All postsCybersecurity

4,400 Rockwell Controllers Exposed

August 8, 2026·industrial control systemswater system securityexposed controllersrockwell automationallen-bradley

The discovery of over 4,000 exposed Rockwell Automation and Allen-Bradley controllers used in U.S. water systems has raised concerns about the vulnerability of these critical infrastructure systems. Despite federal warnings, many of these controllers remain accessible online, potentially allowing malicious actors to disrupt water system operations. The exposure of these controllers has been identified in multiple cities, including some that have recently been targeted by cyberattacks on water systems.

Understanding the Risk of Exposed Industrial Controllers

Industrial control systems (ICS) like those used in water and wastewater operations are designed to manage and monitor critical infrastructure. However, when these systems are exposed to the internet without proper security measures, they can become vulnerable to cyber threats. The exposure of 4,400 Rockwell Automation and Allen-Bradley controllers, including 22 in cities recently targeted by water system attacks, highlights the need for increased awareness and action to protect these systems.

Attack Surface and Vulnerabilities

The fact that many of these controllers are exposing port 44818 (EtherNet/IP) indicates a potential vulnerability that could be exploited by malicious actors. With 65% of the exposed controllers located in the United States, the risk to water system operations is significant. The FBI has warned of malicious cyber actors targeting water and wastewater sector internet-facing programmable logic controllers, causing operational disruptions.

Consequences of Inaction

The consequences of inaction can be severe, with potential disruptions to water system operations affecting public health and safety. The recent coordinated attacks on water systems across at least 12 states demonstrate the real-world impact of these vulnerabilities. It is essential for organizations responsible for water and wastewater operations to take immediate action to address these exposures and protect their systems.

Practical Steps for Protection

To mitigate the risks associated with exposed industrial controllers, organizations should conduct regular vulnerability assessments and implement robust security measures. This includes ensuring that all internet-facing systems are properly configured and secured, using firewalls and intrusion detection systems, and implementing secure remote access protocols. Additionally, organizations should stay informed about potential threats and vulnerabilities, such as those identified by the FBI and other cybersecurity authorities.

What this means for you: if you are responsible for water and wastewater operations, take action now to identify and address any exposed industrial controllers. Conduct a thorough risk assessment, implement robust security measures, and stay informed about potential threats to protect your systems and ensure the continuity of critical water services.