Forescout’s Vedere Labs research team scanned the internet on August 3, 2026, and found 4,407 Rockwell Automation/Allen-Bradley industrial controllers still directly exposed online via the EtherNet/IP protocol (port 44818). Critically, 22 of those exposed devices were located in the same cities that were actually hit by the recent wave of water utility cyberattacks, showing that exposure and real-world compromise are closely linked rather than theoretical
The breakdown of exposed device types is practically useful for OT teams: MicroLogix 1400 units make up half of all exposed controllers, followed by CompactLogix 1769 (22%) and MicroLogix 1100 (8%) - the exact families named in the FBI/EPA advisory. Most exposure came through cellular/mobile carrier connections rather than traditional corporate networks, which is an important detail for teams focused only on securing wired network perimeters.
The article also includes concrete recovery steps under Advisory SD1790: if a MicroLogix 1100 or 1400 has already been locked by an attacker-changed password, staff can reset the device to factory defaults and redownload a known-good project file - but only if a current offline backup of the controller logic exists. This makes the article as much a checklist ("do we have offline backups of our PLC logic files right now?") as a news item.