MicroLogix 1400 controller in an open outdoor cabinet, water tower behind

Since July 27, water and wastewater utilities in at least seven US states have reported cyber incidents, enough for the FBI and EPA to issue a joint public service announcement on July 30. The most striking number came a few days later: security firm Forescout counted 4,407 Rockwell controllers reachable from the public internet, 2,844 of them in the United States.

No exploit was needed

The detail worth reading twice, as reported by The Hacker News, is that the attackers did not need a vulnerability. On controllers that were already reachable, they simply changed IP addresses and set passwords. Operators lost visibility, and in some cases control, of their own equipment. One utility only discovered the intrusion after noticing ladder logic discrepancies across several sites.

Half of the exposed devices were MicroLogix 1400 units, answering on EtherNet/IP port 44818: an unauthenticated path that can identify a controller or write settings to it, depending on configuration. A known buffer overflow, CVE-2017-16740, has had a fix available since 2017. Exposure, not patching, was the failure.

The cellular detail

Buried in the analysis is the number that matters most to our customers: of the 22 internet-facing PLCs found in the cities that were attacked, 19 sat on the same mobile carrier network. A cellular modem is a convenient way to reach a remote site, and it is also what places a controller on a public, scannable network. Every SIM card in a pump house is an address the whole internet can try.

You cannot scan a radio path from Shodan

The mitigations in the advisory say it plainly: remove controllers from the public internet, and isolate remote access on a private architecture. That is not a retrofit for a SCADA MASTERS system. It is the starting design.

Our sites talk over a private licensed NXDN radio path. There is no carrier contract, no SIM card and no public IP address anywhere between the sites. A command is a 12-bit burst on a frequency you license, with anti-collision and retransmission logic, and an option for military-grade encryption. A private radio path is not immunity, and we will never sell it as such. But it removes the exposure that made this summer's attacks possible: there is nothing for an internet scan to find.

What we would check this week

If your system reaches its remote sites over cellular modems, three checks are worth an afternoon: inventory which controllers answer from the internet, put strong authentication and logging on every modem that must stay, and keep a current offline copy of your controller logic. That last one is standard practice here: the logic in every unit we ship is readable and documented, and a site's configuration loads back from a USB key in seconds.

If you would rather take the whole question off the table, we will review your sites and spec the radio path that replaces the modems.

Sources

  • The Hacker News, “Over 4,400 Rockwell PLCs Exposed Online”, August 6, 2026.
  • Forescout Research, internet exposure snapshot of Rockwell controllers, August 3, 2026, as reported by The Hacker News.
  • FBI and EPA joint public service announcement on water utility cyber incidents, July 30, 2026.
  • Rockwell Automation advisory for CVE-2017-16740, MicroLogix 1400 Modbus TCP, fixed in firmware 21.003.