A little over a week ago, we wrote about a wave of cyberattacks that disrupted more than thirty water systems across Minnesota — and made the point that “small” does not mean “safe,” and that the attacks hit operations rather than stealing data. A new report has now put a hard number on the exposure sitting underneath that story, and the number is uncomfortable: 4,407. That’s how many industrial control devices made by a single manufacturer were found sitting on the public internet, reachable by anyone, in a scan taken just days ago. Twenty-two of them were in the very cities recently hit by those water attacks.
This is one of those stories where the details matter enormously — where the difference between what was actually found and what a scary headline implies is the whole point. So let’s do this carefully: what the researchers found, what it does and doesn’t prove, how these attacks actually work (it’s not what most people picture), and why the core lesson reaches every small business, not just water utilities. Because it does.
First, what is a PLC — and why should you care?
Let’s not assume. A PLC — programmable logic controller — is a small, rugged industrial computer that controls physical equipment. It’s the device that tells a pump to turn on, a valve to open, a motor to stop. They are the quiet workhorses running the physical machinery of modern life: water treatment plants, manufacturing lines, building systems, elevators, HVAC, food processing. If something in the physical world switches on and off automatically, there’s a decent chance a PLC is behind it.
The specific devices in this report are made by Rockwell Automation, under its well-known Allen-Bradley brand — particularly two models, the MicroLogix 1100 and 1400, that are extremely common in small and mid-sized water utilities. These are not obscure. They are the workhorses of exactly the kind of small municipal operation that keeps a town’s water running.
And here is the thing to understand about all of them: a PLC’s entire job is to do what it’s told, immediately and without argument. It is built for reliability, not suspicion. It generally does not ask “are you sure?” or “who’s asking?” It assumes that anyone able to reach it and give it a command is authorized to do so — because for most of the history of these devices, the only way to reach one was to be standing in the building, physically wired to it. That assumption is the entire root of this story.
What the researchers actually found
The security firm Forescout ran an internet-wide scan on August 3 and published what it saw. Here are the figures, stated precisely, because precision is what keeps this honest:
| 4,407 | Rockwell controllers found reachable on the public internet worldwide |
| 2,844 | Of those, located in the United States |
| 22 | Found in cities that were hit by the recent US water attacks |
| 19 | Of those 22, sharing the same mobile carrier network |
| Over 70% | Share of US exposed controllers reachable via large mobile carrier (cellular) networks |
| ~58% | Of Forescout’s results were MicroLogix 1400 and 1100 models specifically |
| Zero | Devices Forescout could confirm were actually compromised |
A second firm, Censys, ran its own separate scan around the same time and landed in the same neighborhood — more than 4,100 exposed Rockwell devices — which gives us real confidence the number is genuine and not a fluke of one company’s method. When two independent teams counting different ways arrive at the same rough figure, the exposure is real.
Read that last row carefully, because it’s the most important one. Forescout could not confirm that a single one of these devices was actually broken into. This number counts doors that were found unlocked — not doors that were walked through. It’s the count of exposed controllers, not of victims, and not of confirmed hacks. That distinction is everything, and it’s exactly the kind of nuance that gets flattened when a number like “4,407” travels across the internet. We’re going to respect it here.
The part that should genuinely worry you: no “hacking” required
Here’s where most people’s mental model is wrong, and where this story gets its real weight. When you hear “attackers took control of water-system equipment,” you probably picture some elaborate hack — a genius exploiting a hidden flaw, cracking encryption, doing something sophisticated. According to the federal alert describing these incidents, that is not what happened at all.
The FBI and EPA, in a July 30 public service announcement, described the actual technique in plain terms: after remotely reaching internet-facing devices, the attackers simply changed the IP addresses and set passwords on the controllers — causing operators to lose visibility and, in some cases, control of their own equipment. That’s it. No exploited vulnerability was necessary. As the researchers put it, the observed effects could be achieved without any software flaw at all, because the controllers were already reachable and, by design, did what they were told.
Think about what that means with an analogy. This wasn’t a burglar picking a sophisticated lock. This was someone finding a door with no lock at all, walking in, and then installing a lock and keeping the key — locking out the people who actually own the building. The “attack” was possible not because the criminals were brilliant, but because the door was standing open in the first place. The controllers weren’t defeated. They were simply commandeered, because nothing stood between them and the open internet.
The uncomfortable truth about exposure: when a device is directly reachable from the public internet and assumes anyone who reaches it is friendly, there is barely any “hacking” left to do. The exposure is the vulnerability. This is why security professionals treat “is it on the internet at all?” as a more urgent question than “is it fully patched?” A perfectly updated device sitting open on the internet can still be commandeered this way — because the problem was never a bug. It was the open door.
Why are these devices on the internet at all?
This is the natural question, and the answer is deeply human — and directly relevant to every small business. Almost nobody sat down and decided to put a water-treatment controller on the open internet. It happened by accident, through convenience, one reasonable-seeming step at a time.
The single biggest culprit in this report is telling: over 70% of the exposed US devices were reachable through cellular modems — the little wireless boxes that let a small utility check on a remote pump station without driving out to it. A staffer needs to monitor equipment from home or from a truck. Someone adds a cellular modem for convenient remote access. It works beautifully. But unless it was very carefully configured, that modem quietly made the equipment reachable from anywhere on Earth — not just from the staffer’s phone. The convenience was visible and immediate. The exposure was invisible and permanent.
Notice that this is not a story about negligent, careless operators. It’s a story about small teams solving practical problems with limited time and budget, and one convenient decision having an enormous unintended consequence that nobody was in a position to notice. That exact pattern — convenient remote access quietly becoming public exposure — is one of the most common serious problems we find, and it is absolutely not limited to water utilities.
Two more wrinkles worth knowing
A couple of additional details from the research sharpen the picture:
- Many of these devices are past their prime. Researchers noted that a large share of the exposed MicroLogix 1400 controllers are running “end-of-sale” firmware — older versions with limited ongoing security support. One of the two models, the MicroLogix 1100, was formally discontinued back in 2022. This is the same end-of-life problem we keep running into: equipment that still works perfectly, and is therefore never replaced, quietly accumulating risk because it’s no longer actively supported.
- The devices announce themselves. By design, these controllers openly broadcast their model and firmware version to anyone who queries them — no password needed just to ask. That means an attacker scanning the internet can effortlessly build a shopping list, sorting exposed devices by exactly which ones are oldest and least defended. Exposure isn’t just an open door; for these devices, it’s an open door with the make and model helpfully posted on it.
There’s a genuinely reassuring flip side, though, and it deserves equal billing. Because the problem is exposure rather than some unpatchable flaw, the fix is largely within reach. The manufacturer, the FBI, the EPA, and the researchers all converge on the same core remedy: get these devices off the public internet. Route remote access through a protected private channel instead of leaving the equipment directly reachable. On many of these controllers there’s even a physical switch that, set to “run,” blocks the exact remote changes seen in these attacks and cannot be overridden from afar. This is a solvable problem. That’s the good news buried in the alarming number.
Why this matters if you don’t run a water plant
You might be reading this thinking it’s a fascinating story about critical infrastructure that has nothing to do with your accounting firm, your dental practice, or your retail shop. But the core lesson is universal, and it’s one of the most important ideas in all of security: you cannot protect what you don’t know is exposed.
Those 4,407 controllers didn’t get onto the internet through a decision. They got there through convenience, drift, and the simple fact that nobody was watching the perimeter with fresh eyes. And that same quiet drift happens at businesses of every kind. The remote-access tool someone set up to work from home. The security camera system reachable from an app. The old server still humming in a closet. The “temporary” remote-desktop connection that’s been on for three years. The smart device plugged in and forgotten. Every one of these can be the equivalent of an exposed PLC — a door to your business standing open on the internet that nobody remembers opening.
The questions this story should prompt for your own business: What of yours is reachable from the public internet right now — and did anyone actually decide that, or did it just happen? * Is there remote access into your network (a modem, a camera system, a remote-desktop tool) that was set up for convenience and never security-reviewed? * Are you running any equipment or software that’s past its support life, still working, and quietly exposed? * And if a door to your business were standing open online, is there anyone whose job it is to notice?
That last question is the one that matters most, because the lesson of the 4,407 is not “water utilities are careless.” It’s that exposure is silent. Nobody gets an alert that says “your equipment is now reachable by the entire internet.” It simply becomes true, and stays true, until someone looks — or until someone finds it for you. Finding those open doors before anyone else does is precisely what our environment review is built to do: we look at your business exactly the way an internet scanner would, find what’s exposed, and help you close it — the modem, the forgotten server, the remote-access tool, the end-of-life device. The water utilities in this story didn’t have a hacking problem. They had a visibility problem. Almost every business has some version of the same one. The only real question is whether you find your open doors, or someone else does.
Sources: Forescout research (internet scan dated August 3, 2026); FBI and EPA joint Public Service Announcement (July 30, 2026); CISA guidance to water and wastewater utilities (July 30, 2026); Censys internet-exposure analysis; Rockwell Automation advisory SD1790 (device recovery guidance); The Hacker News; BleepingComputer; Industrial Cyber, July-August 2026. Exposure figures count internet-reachable controllers, not confirmed compromises or affected utilities. No agency has attributed the late-July water incidents to a specific actor; this article follows that official position and takes no view on attribution.













