At least 22 Rockwell Automation programmable logic controllers (PLCs) were found exposed online in cities affected by recent water utility cyberattacks in the US, according to a report by Forescout. The 22 devices were internet-facing, meaning they were accessible from the internet without authentication. This is concerning, as these devices are typically used to control and monitor industrial processes, and their exposure online could have allowed hackers to gain unauthorized access to critical infrastructure.
Forescout's August 3 scan identified 4,407 exposed Rockwell PLCs worldwide, with 2,844 of those found in the United States. Nineteen of the exposed devices used the same mobile carrier network, indicating a potential vulnerability in the network's security.
Rockwell Automation, a leading manufacturer of industrial automation and control systems, has not commented on the findings. However, the company's own documentation suggests that its PLCs can be configured to use a mobile carrier network for communication, which may have contributed to the exposure of these devices.
The discovery of these exposed devices highlights the need for improved cybersecurity measures in the industrial control systems (ICS) sector. As the use of ICS increases, so too does the risk of cyberattacks on these systems, and the consequences of a successful attack can be severe.