
Thousands of Exposed PLCs Found in Critical Water Systems Amid Cyberattack Concerns
Threatscritical infrastructureEPAFBIForescoutRockwell AutomationShodan
A scan of internet-connected industrial equipment identified 4,400 exposed programmable logic controllers (PLCs), including 22 located in U.S. cities recently targeted by water system cyberattacks. The exposed devices are associated with critical infrastructure, specifically water systems, despite prior federal warnings from agencies such as the Environmental Protection Agency (EPA) and the Federal Bureau of Investigation (FBI). The discovery was made using tools like Shodan, highlighting persistent vulnerabilities in operational technology (OT) environments. No specific dates, CVE IDs, or technical attack vectors were detailed in the report. The findings underscore ongoing risks to public utilities from unsecured industrial controllers.