Internet-Exposed PLCs: A Clear and Present Danger to Water Utilities
On July 30, 2026, CISA issued an alert about threat actors actively targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) sector. The alert details a disturbing trend: attackers are modifying PLC passwords to lock out operators and changing device IP addresses to disconnect them, forcing utilities into manual operations and boil-water notices. CISA specifically named Rockwell Automation/Allen-Bradley, Siemens, and Schneider Electric equipment as targets, and flagged cellular modems as a common blind spot in attack-surface scans.
Censys, a leading internet-wide scanning platform, has released a report characterizing the current exposure of these devices. As of the 2026-07-30 snapshot, Censys ARC identified:
- 4,148 internet-exposed Rockwell Automation/Allen-Bradley EtherNet/IP hosts
- 4,117 internet-exposed Siemens SIMATIC S7-1200 hosts
- 2,072 internet-exposed Schneider Electric hosts (vendor-wide, not PLC-scoped)
These numbers are stark. But the deeper story lies in the network distribution: a significant portion of these devices are connected via cellular networks, which often escape traditional perimeter defenses and are frequently undocumented.
Rockwell/Allen-Bradley: US Dominates, Cellular Carriers Abound
Censys found that 71.0% (2,945 hosts) of exposed Rockwell/Allen-Bradley EtherNet/IP devices are located in the United States, with Canada a distant second at 11.5% (476 hosts).
More striking is the network breakdown: combined cellular carriers (Verizon Business, AT&T Mobility, T-Mobile USA) account for 59.0% of all exposed hosts. This confirms CISA's warning that cellular modems are a major blind spot. These connections are often installed by operators or integrators for remote monitoring, but they bypass traditional firewalls and are rarely included in routine attack-surface scans.
Siemens SIMATIC S7-1200: Europe's Mobile-First Exposure
Siemens SIMATIC S7-1200 exposure is heavily concentrated in southern and central Europe. Greece, Spain, Italy, and Austria together account for 86.0% of the total. Each country's exposure is dominated by that country's leading mobile carrier, not fixed-line or hosting providers. This pattern strongly suggests that cellular modems are the primary connection method for these PLCs, making them accessible from anywhere with a signal.
Schneider Electric: A Broader View
The 2,072 exposed Schneider Electric hosts are vendor-wide, not specifically PLCs. Turkey and Australia account for 55.5% of the total combined. Without a protocol filter, this number includes other Schneider products, but the exposure is still significant and warrants attention.
Censys Queries: How to Find Exposed Devices
Censys provides the exact queries used to identify these devices. Security teams can use these to audit their own attack surface:
Rockwell/Allen-Bradley:
(host.services.protocol=EIP) and host.services.eip.identity.vendor_name="Rockwell Automation/Allen-Bradley"
Siemens SIMATIC S7-1200:
host.hardware.vendor: "siemens" and host.hardware.product: "simatic_s7-1200"
Schneider Electric:
host.hardware.vendor = "schneider-electric"
Run these against your own IP ranges to see if you have exposed OT devices. If you do, treat it as a critical finding.
CISA's Recommended Mitigations
CISA's guidance is clear and actionable:
- Disconnect the PLC from the internet. Route remote access through a VPN or gateway device, not directly to the PLC.
- Enable password protection and change default passwords.
- Allowlist IPs to permit remote access only from known engineering laptops or other critical OT assets.
These steps are not optional. The threat actors are actively exploiting exposed PLCs, and the consequences—boil-water notices, manual operations—are immediate and severe.
Why This Matters for Developers
You might not work in the water sector, but the lessons apply broadly. Internet-exposed industrial control systems are a ticking time bomb. The same principles apply to any IoT device, embedded system, or legacy hardware you manage.
Cellular modems are a blind spot. When you deploy a device, do you know every network path it can be reached from? If a technician added a cellular modem for convenience, you might be exposing critical infrastructure without knowing it.
Visibility is the first step. Censys's data shows that these devices are findable by anyone with an internet connection. If you have OT devices, you need to know what's exposed. Use the same scanning techniques to audit your own environment.
Default passwords are a death sentence. CISA specifically mentions password changes. If you have a device with a default password, it's only a matter of time before someone logs in.
Next Steps for Your Organization
- Audit your attack surface. Use Censys queries or similar tools to find any internet-exposed OT devices in your IP ranges.
- Immediately remove direct internet access from any PLC. Replace it with a VPN or bastion host.
- Change all default passwords and implement role-based access control.
- Document all remote access paths, including cellular modems. If you don't know about a modem, you can't secure it.
- Monitor for anomalous activity. Watch for password changes or IP address modifications on your OT devices.
The CISA alert is not a drill. The exposure is real, and the attackers are active. Take action now before your utility becomes the next headline.



