00:00Still Answering
highthreats2026-08-04 → 2026-08-103 min read

Still Answering

ByRucka

Somebody scanned on 3 Aug 26 and found 22 controllers still reachable in the same towns that had just been knocked into manual operation. The attacks have reached at least 12 states.

Summary

Somebody scanned the internet on 3 Aug 26 and found 22 industrial controllers still reachable in the same towns that had just been knocked into manual operation. Greg Otto reported it at CyberScoop on 6 Aug 26, working from research by Forescout's Vedere Labs.

Last week this report said getting those controllers off the internet is about a day of work on a small system, and it said to watch whether more states started reporting. They did. The FBI and the Environmental Protection Agency put out a joint advisory confirming attacks at water and wastewater utilities in at least 12 states since 27 Jul 26.

Findings

Forescout's scan turned up more than 4,000 Rockwell Automation and Allen-Bradley controllers answering on the open internet, 2,844 of them on American soil. The MicroLogix 1400 made up half of them and the CompactLogix 1769 another 22 percent.

Then the researchers cross-referenced that list against the cities that had been hit, and 22 devices in those cities were still exposed. Forescout did not say those particular devices were attacked and did not say they belong to the affected utilities, and neither does this report.

19 of the 22 look open to a remote code execution flaw in the MicroLogix 1400 that was disclosed in 2017 and catalogued as CVE-2017-16740. Using it takes Modbus TCP being turned on, and the researchers could not confirm whether it was.

The spread filled in over the week. Michigan had nine systems and South Dakota had one wastewater lift station. In Georgia, the Clayton County Water Authority issued a precautionary boil water advisory and lifted it after testing, and a second authority there reported an incident of its own.

The scan found more than controllers. Expired certificates, and remote-access addresses nobody had renewed in months or years. One abandoned server has served a default Microsoft page since 2019.

Attribution went the other direction this week. Forescout's Sai Molige declined to name anybody and said the evidence supports "opportunistic, at-scale exploitation of a known class of vulnerabilities affecting internet-exposed devices," and that the scale and the speed read more like mass scanning than a long intrusion campaign. Several outlets have pointed at Iran. Both of those are on the record and neither one is settled.

Impact

If this was mass scanning, then the thing that put a town on the list was being reachable. Nobody studied these utilities and chose them. Being small protected nobody, because nothing about the target mattered except that it answered.

Sean Tufts of Claroty told Dark Reading the small systems "are being asked to defend industrial technology with municipal budgets while keeping water running around the clock." Patrick Gillespie of GuidePoint Security put the number of American public drinking water systems above 148,000.

Tufts raised a question nobody has answered yet. More than 30 Minnesota systems went at nearly the same time, and that might mean those utilities share an integrator or a remote-access path. Nobody knows.

The 22 belong to somebody's account. Whoever holds the service contract on that equipment is the one who could have found them, and is the one who still can.

Recommendations

The general version of this ran last week. Here is the narrow one. If you hold a service contract on any of this equipment, pull your site list and check which ones answer from outside. Get those behind a gateway and change the credentials on them.

Then ask the owner two things. Who renews the certificates, and who owns the remote-access address. The scan found plenty of both with nobody home.

Watch whether the count moves past 12 states, and whether anybody attributes this officially.

Works Cited

  1. Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online (CyberScoop)
  2. Cyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidents (The Record)
  3. Water Sector Cyberattacks Reportedly Hit at Least 12 States (SecurityWeek)
  4. Minnesota Water Utility Attacks Expose Sector's Cyber-Risks (Dark Reading)
  5. US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices (SecurityWeek)
#water#ot#plc#ics#exposure#remediation#forescout#attribution
90A LLC

Need CMMC help?

90A LLC works in the CMMC trenches with defense contractors every day. We do readiness assessments, gap analysis, and SSP development for the supply chain.