Overview
- Federal agencies said utilities reported intrusions starting the week of July 27 and issued a joint advisory on July 30 urging urgent hardening after attackers locked operators out of water systems.
- A Forescout scan run on August 3 found 4,407 internet‑facing Rockwell Automation PLCs worldwide, with 2,844 in the U.S. and 22 located in cities tied to the recently reported water incidents.
- Forescout and others say attackers often did not need a software zero‑day to cause harm because EtherNet/IP on TCP port 44818 can let unauthenticated users identify controllers or write settings depending on device configuration.
- Researchers found strong carrier clustering: more than 70% of U.S. exposed controllers use large mobile networks and 19 of the 22 devices in affected cities were on the same carrier, pointing to shared modem or integrator templates.
- Recovery is harder for many operators because devices run old or end‑of‑life firmware and Rockwell’s SD1790 factory‑reset process requires a trusted offline project file, so agencies now advise removing PLCs from the public internet, using private APNs or VPNs, enforcing strong modem auth and keeping offline backups.