Attackers hit municipal water systems in at least 12 states beginning July 27, 2026, interrupting critical monitoring and control functions at some utilities by changing IP addresses and passwords on internet-facing programmable logic controllers. The FBI reported that at least one victim’s PLC programming was modified. The news about this had little technical detail, so I decided to dig deeper.

Leaving The Door Open For Attacks

Minnesota IT Services reported a coordinated attack against more than 30 water systems in that state on July 28. Two days later, the FBI and EPA identified the affected hardware: MicroLogix 1100 and 1400 series PLCs, sold under the Allen-Bradley brand by Rockwell Automation.

These controllers were reachable from the open internet, and that’s the crux of the problem. Forescout queried Shodan on August 3 and found 4,407 similar devices worldwide exposing EtherNet/IP on port 44818 . A total of 2,844 controllers were in the United States, with more than 70% of the U.S. devices connected via mobile carrier networks behind cellular routers, apparently without a private access point name or a properly configured inbound firewall. EtherNet/IP requires no authentication, so an exposed port on the internet is an open door. Rockwell has consistently told customers not to expose controllers directly to the internet — including in September 2018 , May 2024 and March 2026. Forescout found no confirmation of any common vulnerability or exposure exploit.

My take: Doesn’t anyone read the instructions? After eight years of vendor guidance, thousands of these controllers are still open to anyone who finds them.

Why Industrial Automation Is So Ripe For These Vulnerabilities

The interesting question is not who to blame. It’s why nobody followed the vendor’s clear guidance and fixed the problem. Apparently, it was nobody’s job to do so. Rockwell’s advisories addressed its customers, but in one case, the customer is a town of 1,800 with no IT staff or network engineer. It’s very likely that an integrator specified the connectivity scheme, installed the automation equipment and handed over a working system. I do not know if the integrator or other contractors had an obligation to maintain and update the equipment in perpetuity, but in any case, no one took corrective action.

There is no obvious “throat to choke” here — not because anyone behaved badly, but because most brownfield (old) connectivity schemes like this one have complicated supply chains with weak or unspecified long-term maintenance obligations.

Water utilities are just the latest examples. The problem spans the whole spectrum of industrial automation: legacy controllers, cellular gateways, remote access built by an integrator, no ongoing asset upgrades and an operator with a thin (or nonexistent) technical staff. You’ll find similar situations in factory automation, power generation and distribution, oil and gas, and the building systems that keep hospitals and datacenters alive. Forescout has published similar findings for solar inverters and serial-to-Ethernet converters . These connected systems run continuously and, in many cases, failure causes big problems.

An Expanding Attack Surface For Edge Devices — And What To Do About It

This pattern looks set to scale up. Many (but not all) edge AI and robotics vendors now provide remote fleet management as a headline feature, through similar integrator channels, to operators with thin security staffing. These new edge compute systems are far more capable than PLCs, with a larger attack surface and a similar service lifespan. Companies buying automation systems should nail down who owns each product’s network connections, remote access, security infrastructure and long-term software maintenance over its 10- to 15-year life.

I expect the embedded systems market to answer with platforms rather than consultants and contractors. Identity, security, networking, internet access and system updates belong in an operating system platform with long-term maintenance designed in from the start, supplied by companies large enough to afford the necessary security expertise and financed to support the product across its entire service life. Systems integrators can then move up a level, working with building blocks that are secure by design.

The platform transition is already underway for new equipment, but the massive industrial installed base is a different problem. These brownfield systems with weak security or wide-open ports belong behind solid firewalls with secure, authenticated access. I hope this incident motivates infrastructure owners to take immediate action and move all legacy gear to local networks. This would be costly, but cheaper than the alternative. Let’s start with the wide-open PLCs we already know about.

Moor Insights & Strategy provides or has provided paid services to technology companies, like all tech industry research and analyst firms. These services include research, analysis, advising, consulting, benchmarking, acquisition matchmaking and video and speaking sponsorships. None of the companies mentioned in this article has ever had a paid business relationship with Moor Insights & Strategy.