# Twenty-Two Exposed PLCs, One Carrier, and the Water Utility Deployment Problem Nobody Wants to Fix


When Forescout researchers ran a scan of internet-facing Rockwell Automation programmable logic controllers on August 3rd, they found 4,407 of them worldwide — 2,844 sitting exposed in the United States alone. That number is alarming enough. Then they cross-referenced the results against cities that have experienced recent cyberattacks on water utilities.


They found 22 matches. Nineteen of those 22 were running through the same mobile carrier network.


That detail — the carrier overlap — is the part that matters most, and it's getting buried in the headline count.


## What "Exposed" Actually Means Here


A PLC isn't a web server. It doesn't need to be reachable from the internet to do its job. A Rockwell Automation controller managing a pump station or chemical dosing system should be air-gapped, or at minimum sitting behind a purpose-built industrial firewall with authenticated remote access. Finding one with a public IP isn't a configuration edge case. It's a failure of basic operational security.


Forescout was careful to note it could not confirm any of the 4,407 exposed controllers were actively compromised. That's the responsible caveat. But "not confirmed compromised" is not the same as "safe." Reconnaissance precedes intrusion. Shodan has indexed ICS devices for over a decade, and threat actors have known how to find them that much longer.


The 22 systems in attack-targeted cities represent something more specific: exposure in places where adversaries have already demonstrated intent and operational capability. That's a different threat calculus than the baseline exposure figure.


## The Carrier Fingerprint


Nineteen of the 22 exposed PLCs using the same mobile carrier isn't a coincidence — it's a pattern. The most plausible explanation is a shared deployment methodology: a single engineering firm or systems integrator that configured remote access for multiple utility clients using cellular modems on the same carrier, and either didn't lock down the exposure or explicitly chose cellular-over-internet as the remote access path.


This is exactly how vendor-introduced risk propagates through critical infrastructure. A contractor builds a repeatable deployment template. It's efficient, it works, it gets the SCADA system up and the client is happy. Whether that template exposes the PLC to the open internet is an afterthought, if it's a thought at all. Across dozens of client sites over years, one bad template becomes dozens of exposure points — all carrying the same carrier fingerprint.


This also means that if an attacker wanted to find more targets in the same cohort, they'd already have a methodology: scan for Rockwell controllers on that carrier's IP ranges, narrow by geography, cross-reference with utility service areas. That's not sophisticated threat intelligence. That's an afternoon with Shodan and some basic OSINT.


## The Regulatory Vacuum Underneath This


US water utilities have no enforceable federal cybersecurity standards. The EPA attempted to require cybersecurity assessments as part of existing sanitary survey requirements in 2023. A federal court vacated that rule the same year after challenges from Missouri, Arkansas, and Iowa — a coalition that argued the agency had overstepped its authority.


What's left is a patchwork: voluntary guidance from CISA, sector-specific information sharing through WaterISAC, and whatever individual utilities choose to do with limited budgets. Many water systems serving small municipalities operate on thin margins with IT staff who are also responsible for physical plant maintenance. "Hire an ICS security engineer" isn't a realistic line item.


The Aliquippa, Pennsylvania attack in late 2023 — where an Iranian-linked group called Cyber Av3ngers hit a UNITRONICS controller at a municipal water authority — demonstrated that these aren't hypothetical risks. The attackers took over a booster pump station's controller and displayed their own message on the operator panel. Water service wasn't disrupted, but that was luck, not design.


The Forescout findings show that even after Aliquippa, even after years of CISA advisories, even after repeated FBI and NSA bulletins about ICS exposure, thousands of PLCs remain directly reachable from the internet — including in the exact municipalities that have already been targeted.


## What Defenders Can Do Right Now


The fix for an internet-exposed PLC is not a patch. It's network architecture.


For utilities that may be in the Forescout cohort:

  • Conduct an immediate asset inventory of all internet-facing OT devices — this includes cellular-connected RTUs and PLCs that may have been deployed by third-party contractors
  • Demand documentation from every integrator who has touched your network: what IP addresses were assigned, what ports are open, what carrier is being used
  • Isolate OT networks from internet-routable addresses using proper DMZ architecture and jump servers with MFA
  • If cellular modems are required for remote telemetry, they should route to a private APN, not the public internet

  • For water sector CISOs and IT leads:

  • WaterISAC membership is free for drinking water and wastewater utilities. The threat intelligence sharing alone is worth it.
  • CISA's free vulnerability scanning program covers ICS/OT environments. Take them up on it.
  • Treat your integrators as a supply chain risk. Audit what they deployed, not just what they told you they deployed.

  • The 4,407 number will shrink only when utilities — and the contractors who serve them — start treating internet-facing ICS as the emergency it is.


    ---


    ## HackWire Analysis


    The carrier overlap is the thread this story should pull harder on. Nineteen out of 22 exposed PLCs in water-attack cities running through the same mobile network is not background noise — it's a signature. It points directly at a systemic integrator or vendor problem, and it suggests the remaining exposed Rockwell controllers in Forescout's 4,407-device dataset may cluster in similar ways: same carrier, same firmware version, same deployment template.


    This story fits a pattern that critical infrastructure security researchers have been screaming about since at least 2016, when Dragos and others began cataloguing ICS exposure at scale. The problem isn't awareness at this point — CISA publishes advisory after advisory. The problem is structural: there's no enforcement mechanism, there's no liability attached to leaving a PLC on the internet, and the utilities most at risk are the smallest ones with the least capacity to fix it.


    What's missing from most coverage of this finding is the contractor angle. When you see clusters of exposed devices on a single carrier, that's not 19 different utilities making 19 independent mistakes. That's one bad playbook replicated across 19 clients. The person who wrote that playbook — and the firm that kept using it — bear real responsibility here. The utilities are victims of vendor practice as much as they are architects of their own exposure.


    The timing also deserves scrutiny. Forescout's scan ran August 3rd. Recent attacks on US water utilities have elevated the threat landscape. Publishing exposure data while simultaneously noting it can't confirm compromise is responsible disclosure — but it also means adversaries with the same scan data have a prioritized target list. The window between "publicly known exposed" and "actively probed" is not long.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)