INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Rockwell PLCs Exposed Online in Water Attack Cities Across US
| 2026-08-06 19:10 HIGH HIGH CRITICAL INFRASTRUCTURE & OT
Executive Summary
AI-generated
A scan of internet-connected industrial equipment found over 4,000 Rockwell Automation and Allen-Bradley controllers exposed online, including 22 in cities impacted by cyberattacks on US water systems. The affected states include Michigan, South Dakota, and Georgia, with at least nine systems hit in Michigan and one wastewater lift station hit in South Dakota. Since July 27, attacks have been reported at water and wastewater utilities in at least 12 states. The attackers targeted programmable logic controllers (PLCs) made by Rockwell Automation under its Allen-Bradley brand, specifically the MicroLogix 1100 and 1400 models, which are vulnerable to a remote code execution flaw disclosed in 2017 that impacts MicroLogix 1400 devices. The attack works by exploiting this vulnerability, allowing attackers to remotely change settings or write new configurations on exposed controllers. As of now, no further information is available regarding the current status of the affected systems and whether they have been restored to normal operation.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2017-16740 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2017-16740CVE-2017-16740
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
energyenergy
governmentgovernment
manufacturingmanufacturing
telecommunicationstelecommunications
Incident Timeline
2026/08/06
Threat actors used a Modbus TCP buffer overflow vulnerability in MicroLogix 1400 Series B and C devices to target US water systems.
Click on any entity below to view its context and source!
infrastructure
4,148 exposed Allen Bradley IP hosts
A July 30 Censys snapshot
found 4,148 exposed Rockwell/Allen-Bradley EtherNet/IP hosts, with Verizon Business, AT&T Mobility and T-Mobile USA accounting for 59%.
infrastructure
22 hosts
The research also found that 19 of the 22 hosts in affected cities appeared, based on firmware versions, to be open to CVE-2017-16740, a remote code execution flaw disclosed in 2017 that impacts MicroLogix 1400 devices.
Forescout cross-referenced those machines against the recently targeted cities and municipalities and found 22 devices still exposed to the internet.
infrastructure
1400 devices
The research also found that 19 of the 22 hosts in affected cities appeared, based on firmware versions, to be open to CVE-2017-16740, a remote code execution flaw disclosed in 2017 that impacts MicroLogix 1400 devices.
MicroLogix 1400 devices made up 50% of Forescout's results and MicroLogix 1100 devices 8%.
infrastructure
5590 devices
MicroLogix 1100 and ControlLogix 5590 devices each accounted for about 8%.
infrastructure
21.002
The flaw is a Modbus TCP buffer overflow affecting MicroLogix 1400 Series B and C running firmware 21.002 and earlier; Rockwell fixed it in revision 21.003.
infrastructure
21.003
The flaw is a Modbus TCP buffer overflow affecting MicroLogix 1400 Series B and C running firmware 21.002 and earlier; Rockwell fixed it in revision 21.003.
infrastructure
4,100 hosts
The Censys and Forescout snapshots both exceed 4,100 hosts, but different platforms, queries and dates make the figures not directly comparable.
Tactical Metrics
Metrics
infrastructure
22
Hosts
Click for context!
The research also found that 19 of the 22 hosts in affected cities appeared, based on firmware versions, to be open to CVE-2017-16740, a remote code execution flaw disclosed in 2017 that impacts MicroLogix 1400 devices.
Forescout cross-referenced those machines against the recently targeted cities and municipalities and found 22 devices still exposed to the internet.
Metrics
infrastructure
1,400
Devices
The research also found that 19 of the 22 hosts in affected cities appeared, based on firmware versions, to be open to CVE-2017-16740, a remote code execution flaw disclosed in 2017 that impacts MicroLogix 1400 devices.
MicroLogix 1400 devices made up 50% of Forescout's results and MicroLogix 1100 devices 8%.
Metrics
infrastructure
5,590
Devices
MicroLogix 1100 and ControlLogix 5590 devices each accounted for about 8%.
Metrics
infrastructure
4,148
Exposed Allen Bradley Ip Hosts
A July 30 Censys snapshot
found 4,148 exposed Rockwell/Allen-Bradley EtherNet/IP hosts, with Verizon Business, AT&T Mobility and T-Mobile USA accounting for 59%.
Metrics
infrastructure
21.002
Software Version
The flaw is a Modbus TCP buffer overflow affecting MicroLogix 1400 Series B and C running firmware 21.002 and earlier; Rockwell fixed it in revision 21.003.
Metrics
infrastructure
21.003
Software Version
The flaw is a Modbus TCP buffer overflow affecting MicroLogix 1400 Series B and C running firmware 21.002 and earlier; Rockwell fixed it in revision 21.003.
Metrics
infrastructure
4,100
Hosts
The Censys and Forescout snapshots both exceed 4,100 hosts, but different platforms, queries and dates make the figures not directly comparable.
Intelligence Sources
CyberScoop
2026-08-06
The Hacker News
2026-08-06
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T12:19
Comprehensive Tactical Telemetry
Highly Correlated Entities
22x
organisation
Identified Entity
Shodan
entity
15x
timeline
Temporal Reference
2026/07/30
date
7x
attribution
Attributing Entity
FBI
authority
6x
general metric
%
65
%
2x
target region
Target Country
United States
country
2x
tactic
Cyber Operation Type
Remote Code Execution
tactic
2x
infrastructure
Hosts
22
hosts
2x
infrastructure
Devices
1,400
devices
2x
general metric
Micrologix
1,100
micrologix
2x
infrastructure
Software Version
21.002
version
Contextual Telemetry
Context Block
15 METRICS
general metric
Monday
2,844
monday
general metric
States
12
states
vulnerability
Exploited CVE
CVE-2017-16740
cve
general metric
Research
19
research
general metric
Rockwell Automation
4,000
rockwell automation
general metric
Controllers
22
controllers
source region
Origin Country
Iran, Islamic Republic of
country
general metric
Compactlogix
1,769
compactlogix
general metric
Khandelwal Aug
6
khandelwal aug
general metric
Scan
4,407
scan
infrastructure
Exposed Allen Bradley Ip Hosts
4,148
exposed allen bradley ip hosts
industry
Targeted Sector
Government
sector
general metric
Score
9
score
general metric
Rockwell Plcs
4,400
rockwell plcs
tactic
MITRE ATT&CK Technique
T1592.003 - Firmware
technique
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.