Key Findings

  • Recent attacks against internet-facing controllers in U.S. water systems show that exposed operational technology remains a significant concern.
  • There are 4,407 internet-facing controllers exposing port 44818 (EtherNet/IP).
    • 65% are located in the U.S., followed by Canada (12%) and Spain (3%).
    • Exposed controllers decreased 47% from a high of 7,814 devices in March 2020 to a low of 4,169 in June 2026.
    • 70% of U.S.-based controllers are in large mobile network carrier networks, connected via cellular routers.
    • The most common family is MicroLogix 1400 (50%), followed by CompactLogix 1769 (22%), MicroLogix 1100 (8%) and ControlLogix 5590 (8%).
    • 22 hosts in this dataset were present in cities targeted in the current campaign.
  • There is no confirmation of any CVE exploited in this campaign, but exposed controllers are often susceptible to known vulnerabilities.
    • The most prevalent CVE observed in the 22 hosts in the affected cities was CVE-2017-16740. Exploitation would require Modbus TCP to be enabled, which was not confirmed.
  • Beyond controllers, our research found expired certificates, unrenewed remote-access hostnames and abandoned servers that indicate incomplete asset visibility on municipal utilities.

Recommended Mitigation

  • Disconnect PLCs from the public internet
  • Disable unused services
  • Implement secure remote access
  • Plan to replace end-of-life devices

On July 28, Minesota IT Services (MNIT) reported a coordinated cyberattack against more than 30 water systems in the state. No city reported degraded water quality but Plymouth, South St. Paul, Maple Plain, and Braham confirmed operational impacts. Braham reported that threat actors used malware via a wireless connection to shut down water plant controls. Plymouth reported its affected equipment – two water towers and 14 sewer lift stations – were cellular-connected.

Two days later, the FBI and EPA issued a joint advisory confirming that water and wastewater utilities in at least 12 states observed similar incidents since July 27. Michigan,South Dakota, Georgia, have since been named — with nine systems affected in Michigan and one wastewater lift station in South Dakota. The advisory mentions that threat actors targeted Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 programmable logic controllers (PLCs) and that at least one victim organization had its PLC logic modified. In other cases, controllers were remotely accessed and reconfigured by changing IP addresses and passwords, causing loss of monitoring and control. Reported effects include pressure loss and flooding — which could allow untreated groundwater into drinking water pipes.

These attacks have not been attributed to a threat actor, but they were described as being “coordinated” by MNIT. Just four days before the Minnesota incident, CISA updated its advisory on Iranian-affiliated actors exploiting internet-exposed PLCs. Although some of the TTPs and devices mentioned in CISA’s advisory and the recent water sector incidents are similar, there is no confirmed link between the two.

Regardless of attribution, exposed operational technology remains a serious concern, especially in the water sector. Internet-facing controllers, vulnerable industrial cellular gateways, legacy firmware and protocols, and insecure remote access together represent a relevant attack surface independent of this specific campaign.

This research analyzes the current number of internet-facing Rockwell Automation/Allen-Bradley controllers, their historical trends and vulnerabilities, additional evidence of incomplete asset inventories, as well as risk mitigation recommendations for asset owners, including the need for secure remote access (SRA).

Exposure Risks in OT Systems

Both controller families mentioned in the FBI/EPA advisory – MicroLogix 1400 and 1100 – as well as other Rockwell Automation/Allen-Bradley devices use the EtherNet/IP engineering protocol on port 44818.

Exposing EtherNet/IP to the internet creates an unauthenticated path that, depending on device configuration, can allow attackers to obtain information about exposed assets or even write configurations on them. EtherNet/IP is the second most attacked OT protocol we monitor, representing 22% of all OT interactions on our honeypots.

Current Exposure

Querying the Shodan search engine on August 3, 2026 returns 4,407 devices exposing port 44818. The vast majority (65%) are located in the U.S., followed by Canada (12%) and Spain (3%).

More than half of those devices are in the networks of large mobile network carriers, showing that they are often connected via cellular modems – as described in the FBI/EPA’s advisory. If we take only the U.S.-based devices, we see that over 70% of those are in mobile networks.

Focusing on the specific product lines mentioned in the FBI/EPA advisory, we see that MicroLogix 1400 is much more common than MicroLogix 1100, with 50% of the exposed assets being in the former family and only 8% in the latter. Other relevant product lines seen exposed include CompactLogix 1769 (22%) and ControlLogix 5590 (8%).

Shodan Query Total Results Top Countries
“Vendor
ID: Rockwell Automation/Allen-Bradley”
4,407 US: 2,844 (65%)

Canada: 513 (12%)

Spain: 146 (3%)

Italy: 109 (2%)

Australia: 96 (2%)

“Product name:
1766”
(MicroLogix 1400)
2,224 United States: 1,706

Canada: 121

Italy: 83

New Zealand: 65

Australia: 64

“Product name:
1763”
(MicroLogix 1100)
349 United States: 168

Spain: 62

Iceland: 33

Denmark: 20

Mexico: 18

 

Within that dataset of thousands of internet-facing assets, we identified 22 located in cities targeted in the current campaign. Although we cannot confirm these particular assets were compromised in this campaign, they had some interesting characteristics:

  • 19 of the 22 hosts (86%) were on the same mobile carrier network, connected via cellular routers.
  • Two hosts exposed web management interfaces of cellular routers. One of them exposed Sierra Wireless AirLink’s ACEmanager interface on port 9191, which we have previously researched on Sierra:21.
  • Fifteen hosts in Eagan shared adjacent network addresses, similar serial numbers, largely uniform firmware, and one identical GPS coordinate pair. Eagan’s own water utility runs SCADA across two treatment facilities and two well fields, with 20 wells and 6 reservoirs or towers, a plausible fit for a 15-device fleet, but no banner data confirms the cluster belongs to that utility.

Historical Trends in Industrial Controller Exposure

In 2026, it should not be news to any asset owner that industrial controllers are not supposed to be exposed directly on the internet. Our past research has summarized work going back to 2011 showing the dangers of this practice.

Over the years, Rockwell Automation – as well as other OT vendors – have published several advisories instructing their customers not to expose controllers directly on the internet, including in September 2018, May 2024 and March 2026.

Fortunately, even if we continue to see these devices online, their numbers are decreasing. The figure below – using results from Shodan – shows that the number of controllers with exposed port 44818 decreased 47% from a high of 7,814 devices in March 2020 to a low of 4,169 in June 2026.

Vulnerabilities

Only one vulnerability affecting Rockwell Automation/Allen-Bradley controllers is known to be exploited: CVE-2021-22681. That CVE was added to CISA KEV on March 5, 2026 – a month before the original publication of CISA’s alert about Iranian actors exploiting PLCs.

CVE-2021-22681 does not affect the MicroLogix controllers mentioned in the FBI/EPA advisory. However, many other vulnerabilities affect them and we see internet-facing controllers that are susceptible to these issues. We cannot confirm that any of these vulnerabilities was part of the current campaign, since the impacts described publicly could be achieved without exploiting these issues.

Device Model Observed CVEs
MicroLogix 1400 CVE-2017-16740: denial of
service via Modbus TCPCVE-2016-5645: unauthorized
configuration changes via hardcoded SNMP read-write community strings.
MicroLogix 1400 and

MicroLogix 1100

CVE-2016-9334: sensitive
information transmitted in clear text between the browser and the controller’s embedded web server.CVE-2016-9338: authenticated
administrators can remove all administrative users from the web service.CVE-2015-6490: remote attackers can
execute arbitrary code via unspecified vectorsCVE-2015-6491:remote attackers can
upload arbitrary files into FRAME elements.

CVE-2015-6492: denial of service via
HTTP.

CVE-2017-7898: attackers can try
incorrect passwords without restrictions

CVE-2017-7899: credentials transmitted
in clear text via HTTP GET

CVE-2017-7901: insufficiently random
TCP initial sequence numbers

CVE-2017-7903: small maximum character
size for numeric passwords.

Three points are relevant to mention here:

  • These matches were based on observed firmware versions, but exploitability depends on specific services being exposed, such as SNMP, HTTP or Modbus.
  • The most prevalent vulnerability we observed was CVE-2017-16740. Approximately 86% (19 of 22) hosts observed in the affected cities were susceptible to this CVE based on firmware versions. Exploitation would require Modbus TCP to be enabled, which was not confirmed.
  • Rockwell discontinued the MicroLogix 1100 on April 30, 2022, so there are no further patches expected for that product family.

Beyond PLC Controllers

Focusing on the cities known to be impacted by the current campaign, we went beyond internet-facing controllers to identify other risky exposure patterns.

Certificate transparency research found a pattern of water- and utility-named remote-access services abandoned for months or years, alongside examples of the same class of service being actively maintained.

One example was a currently valid certificate used to serve only the default Microsoft IIS 10.0 page since April 15, 2019, on a server provisioned for ASP.NET.

Expired certificates, unrenewed remote-access hostnames, wildcard coverage that hides live services, and abandoned servers together indicate incomplete asset visibility on municipal utilities.

Recommended Mitigation

Firmware updates can address specific vulnerabilities, but they do not make direct public exposure of PLCs acceptable. Internet-accessible port 44818 remains a significant risk even without explicitly exploitable CVEs.

Weak or absent protocol authentication makes network isolation the primary practical control. One way to achieve this isolation while allowing for remote access operations is via Secure Remote Access (SRA). SRA gateways can mediate each interaction between a user and an OT asset. Users do not communicate directly with PLCs, HMIs, or engineering workstations. Instead, the gateway isolates sessions and renders them as secure, browser-delivered image streams. The user sees pixels, not protocols, which reduces exposure of fragile protocols.

Beyond SRA, multiple advisories published on July 30 share relevant guidance related to the current campaign:

Some of the common recommendations in the advisories above and others based on our additional research include:

  • Block direct internet reachability to engineering protocols.
  • Restrict port 44818 and Modbus TCP with explicit allowlists.
  • Move cellular gateways to private carrier APNs or a protected VPN path. Disable public gateway administration.
  • Require individual accounts and MFA for all remote access.
  • Upgrade MicroLogix 1400 firmware where testing permits. Plan replacement for end-of-life MicroLogix 1100.
  • Disable unused SNMP and management services.
  • Segment enterprise, engineering, vendor, SCADA, and controller networks.
  • Monitor controller writes, mode changes, faults, and program transfers.
  • Maintain approved offline copies of controller programs for comparison and restore.
  • Audit shared managed-service provider configurations across every client site for repeated vulnerable setups.
  • Test manual operation under loss of SCADA/cellular communications.
  • Audit every VPN, wildcard certificate, and remote-service hostname for current ownership. Remove abandoned DNS records, servers, certificates, and firewall rules.
  • Preserve gateway, carrier, VPN, and OT logs for incident reconstruction.

Beyond proactive risk mitigation, we recommend organizations consider the following assets for threat hunt and detection.

Hunt Review Hunt For:
Industrial network traffic Firewall/flow/router/OT logs for ports 44818, 502, 2222, 8443, 9191, 9999, 6000, 6002 New external sources, repeated scanning, off-hours access
Controller sessions EtherNet/IP and Modbus sessions New engineering sources, unexpected writes, stop commands
Controller state Mode, fault, restart, program history Mode changes, online edits, unexpected faults, logic discrepancies across sites
Engineering workstations Auth, software execution, project files, outbound connections New tools, unknown sources, off-hours project changes
Cellular gateways Cradlepoint/Sierra Wireless/carrier management logs New admins, failed logins, config exports, firmware changes
VPN / remote access Sessions, source addresses, device identity, auth records Shared accounts, impossible travel, new devices
Third-party / vendor access Managed service provider network configurations across client sites Shared setups repeated across multiple victims, per FBI advisory
Process historian Pump, valve, pressure, tank, alarm data Unexplained state changes, missing telemetry, alarm suppression
DNS / certificates New hostnames, wildcard use, renewal failures New remote-access names, unexplained issuance, long-dead services still resolving
Asset inventory Compare internal records to passive exposure data Unknown addresses, unowned controllers, unsupported firmware, MicroLogix 1100 units
missed by PLC-only filters

Preserve configurations, logs, controller programs, firmware versions, accounts, and routes before rebooting anything – where operational safety allows. Search for connections from unfamiliar external addresses.

Stay on top of the latest threats. Sign up for the Vedere Labs Threat Feed and get the full context in our monthly newsletter.