Back to all lessons
Awareness Lessons
last week

4,400+ Rockwell PLCs Exposed to the Internet, Including Water Utility Infrastructure

Over 4,400 Rockwell Automation PLCs were found directly accessible on the public internet, with 22 located in US water utilities that had already been targeted by cyberattacks. Industrial control systems like PLCs were never designed to be internet-facing, and exposing EtherNet/IP on port 44818 opens a direct path for attackers to manipulate physical processes — such as water treatment — without needing to breach a traditional IT network first. Attackers could have changed device IP addresses or set unauthorized passwords, effectively locking out legitimate operators and causing loss of visibility and control over critical infrastructure. This is especially alarming given the life-safety implications of compromised water systems. The presence of these devices on mobile carrier networks further complicates detection and remediation efforts.

Tactical Insight

Immediate actions

  • Audit all OT/ICS assets and immediately take any internet-facing PLCs offline or place them behind a firewall.
  • Block public access to EtherNet/IP port 44818 at the network perimeter for all industrial control devices.
  • Change default credentials and set strong, unique passwords on all exposed PLCs.

Long-term improvements

  • Implement strict network segmentation by isolating OT/ICS networks from both IT networks and the public internet using DMZs and industrial firewalls.
  • Maintain a continuously updated asset inventory of all OT/ICS devices, including those connected via mobile carrier networks.
  • Enforce a formal policy prohibiting direct internet connectivity for any industrial control system without compensating controls.

Detection measures

  • Deploy continuous monitoring and anomaly detection tools specific to OT/ICS environments (e.g., Claroty, Dragos, or Nozomi) to detect unauthorized configuration changes.
  • Configure alerting for any unexpected changes to PLC IP addresses, access credentials, or firmware.
  • Subscribe to ICS-CERT advisories and threat intelligence feeds relevant to Rockwell Automation and EtherNet/IP vulnerabilities.