4,400 Exposed Rockwell PLCs, 22 in the Exact Cities Hit by the Water Attacks
A Forescout scan counted more than 4,400 internet-exposed Rockwell PLCs worldwide — and 22 of them sit in the exact cities where water utilities were attacked. Here is what the numbers show, what defenders can verify today, and what is still unconfirmed.
Security researchers at Forescout pointed a scanner at the public internet on Aug. 3 and counted 4,407 Rockwell Automation programmable logic controllers (PLCs) — the industrial computers that switch pumps on and off, read tank levels, and hold water pressure — sitting in the open. Then they cross-checked that list against the towns where U.S. water utilities have been attacked this summer. Twenty-two of those exposed controllers turned up in the exact same cities.
Here is the sentence worth carrying out of this story: more than 4,400 Rockwell PLCs are reachable from the open internet, 2,844 of them in the United States, and 22 sit in the precise municipalities already hit in the Iran-linked water-sector campaign. Forescout could not confirm that any of the 22 were breached. The overlap is the point — the same class of device, in the same places, still answering the internet weeks after federal warnings told operators to pull them offline.
What Forescout Counted
The scan, reported by The Hacker News and CyberScoop on Aug. 6 and 7, is a census of exposure, not of compromise. It answers one question: how many Rockwell controllers respond when you knock on them from the open internet? On Aug. 3, the answer was 4,407 worldwide, with the United States holding the largest share at 2,844 devices.
The device mix matters, because it tells you what kind of hardware is sitting outside. Roughly half of the exposed controllers were Allen-Bradley MicroLogix 1400 units — the same compact PLCs used across small water and wastewater systems. CompactLogix 1769 models made up about 22 percent, and the older MicroLogix 1100 and the ControlLogix 5590 each accounted for around 8 percent. These are not exotic devices. They are the everyday automation gear that keeps a municipal pump station running, which is exactly why finding thousands of them on the public internet is a problem rather than a curiosity.
Forescout's framing was deliberately narrow. The firm counted what it could see and declined to claim any of the exposed devices had been tampered with. That restraint is worth respecting: an exposed PLC is a risk, not a breach, and conflating the two is how this beat produces bad headlines. The number that should move a water operator is not "4,407 hacked" — it is "4,407 reachable, and one of them might be yours."
The 22-City Overlap
The finding that turns a routine exposure scan into news is the geography. When Forescout matched its list of internet-facing controllers against the cities where water utilities were attacked this summer, 22 exposed Rockwell PLCs sat inside those same municipalities. Nineteen of the 22 reached the internet over a single mobile-carrier network — the kind of cellular backhaul that small utilities use to connect remote pump stations without running their own fiber.
There is a further wrinkle that explains why exposure here is not academic. Based on firmware versions visible in the scan, 19 of the 22 hosts appeared to be running software old enough to be affected by CVE-2017-16740, a remote-code-execution flaw in the MicroLogix 1400 that was disclosed back in 2017. A device that has been sitting on the internet, unpatched, for the better part of a decade is a device that has had a long time to be found. Forescout did not report that any of these were exploited, and the correlation between the 22 controllers and the attacked cities is not, by itself, proof that these specific devices were the entry points. It is a strong reason to check.
Reporting on the underlying water-sector campaign has tracked its steady expansion — from seven states in the early accounting to at least 12 states, including a disrupted pump station in Georgia's Clayton County. Investigators have attributed the intrusions to Iran-linked actors and described tactics such as altering PLC logic or remotely changing device passwords to lock out legitimate operators. The Forescout data does not add new victims to that ledger. It shows how much of the same attack surface is still hanging open.
"These PLCs Should Not Be Connected to the Internet"
The blunt version of the problem came from someone with standing to say it. Speaking at DEF CON, retired Gen. Paul Nakasone — who led the National Security Agency and U.S. Cyber Command from 2018 to 2024 — told the audience, "These PLCs should not be connected to the internet." The Register distilled his remarks into a headline that reads like a mission statement for the sector: water system controllers don't belong on the internet. Nakasone noted that the United States has roughly 50,000 separate water municipalities, and that about 90 percent of the country's water flows through these systems — a fragmented map that makes uniform security nearly impossible to enforce from the top down.
The uncomfortable part is that operators were already told. As CyberScoop put it, "Despite federal warnings, thousands of US industrial controllers used in water systems remain exposed online." In late July, the Cybersecurity and Infrastructure Security Agency (CISA) urged water and wastewater operators to pull publicly reachable PLCs off the internet and harden their operational-technology networks. The 4,407 figure is, in effect, a measurement of how many devices have not yet acted on that guidance.
What Is Confirmed — and What Isn't
A few things are now on solid footing. The exposure count of more than 4,400 Rockwell PLCs, the 22-city correlation, and the attribution of the scan to Forescout are all in the published reporting. So is the identity of the ex-NSA chief: Paul Nakasone, named in The Register's account of his DEF CON remarks. And the CyberScoop line about thousands of controllers remaining exposed despite federal warnings is a direct quote from its report.
Several details are not settled, and it is worth being explicit about them. Forescout has not published the list of the 22 cities, so the precise locations remain undisclosed. There is no confirmation that CISA is coordinating any takedown of exposed devices, as opposed to issuing guidance. And there is no public record of a Rockwell Automation customer notification tied specifically to this scan. Treat those as open questions rather than facts, and be skeptical of any secondary coverage that fills the gaps with specifics the primary sources do not support.
My Read
My read: the headline number is real, but it is the correlation that should change behavior. Four thousand exposed controllers is an abstraction; 22 of them in the exact towns already under attack is a map. It does not prove those devices were the way in, and Forescout was right not to claim otherwise. What it proves is that the attack surface described in a month of water-sector reporting has not meaningfully shrunk — the same model of PLC, in the same places, is still reachable, and a meaningful slice of it appears to be running firmware old enough to carry a 2017 vulnerability.
The strategic problem Nakasone pointed at is the one that will outlast this incident. When water service is spread across tens of thousands of small municipalities, "just take it off the internet" is technically correct and operationally hard — many of these utilities rent a cellular connection precisely because they cannot staff a network team. The fix is not a single patch or a single agency memo. It is closing the remote path on each of these devices, one utility at a time, and the count of how many have done so is still moving in the wrong direction.
How to Check Your Own Exposure
If you run or advise a water or wastewater system with Rockwell hardware, the useful response to this story is a verification pass, not alarm. Start by searching for your own public IP ranges in Shodan or Censys to see whether any Rockwell or Allen-Bradley controller answers from the open internet. Any device that does should be pulled off the public network — placed behind a firewall or an access-controlled VPN, with no direct inbound path from the internet.
From there, segment operational-technology networks from IT and from the internet so that a controller is never one hop from a public address; inventory the firmware on every MicroLogix and CompactLogix unit and apply Rockwell's hardening and update guidance, with particular attention to older MicroLogix 1400 devices; and review any cellular or third-party remote-access links, since those are how a "private" pump station ends up publicly reachable. None of this requires knowing which 22 cities were on Forescout's list. It requires knowing whether your own devices are on someone else's.