ctipilot.ch
← Back to the live brief
NOTABLEupdateNATOB2threat

UPDATE — the water-campaign exposure gets counted: 4,407 internet-facing Rockwell controllers, and 19 of the 22 in already-attacked cities sat on the same mobile carrier network

discovered 2026-08-10 04:56 UTCrun 2026-08-10T0411Z-intel2 sourcesmulti-source

UPDATE · originally covered Water-utility PLC lockouts reach at least twelve US states, and Clayton County publicly confirms a distribution-side consequence as its own (2026-08-06)

the water-sector controller-lockout campaign has been tracked here through its growth to at least twelve US states and the FBI's naming of the targeted controller families. What was missing was a measurement of the exposed estate. Forescout has now published one (Forescout, 2026-08-05).

"Querying the Shodan search engine on August 3, 2026 returns 4,407 devices exposing port 44818" — the EtherNet/IP engineering protocol used by the Rockwell Automation and Allen-Bradley families the joint federal advisory named. "The vast majority (65%) are located in the U.S., followed by Canada (12%) and Spain (3%)." Forescout also notes the exposed population has fallen substantially from its 2020 peak, so the trend is downward even as the absolute number stays material.

The finding worth carrying into a European estate is not the headline count but what Forescout found inside it. Of the devices located in cities the campaign targeted, "Although we cannot confirm these particular assets were compromised in this campaign, they had some interesting characteristics" — and the first of those is that "19 of the 22 hosts (86%) were on the same mobile carrier network, connected via cellular routers." That is a connectivity path, not an IT-network path: controllers reachable through a mobile carrier do not appear in a scan of an organisation's own address space, do not sit behind its perimeter, and are frequently owned operationally by an integrator rather than by the utility. Separately, and confusingly sharing the same ratio, "Approximately 86% (19 of 22) hosts observed in the affected cities were susceptible to this CVE based on firmware versions" — referring to CVE-2017-16740, which Forescout names but does not describe further. These are two different observations about the same 22 devices and should not be read as one.

Forescout is careful about what that CVE means here, and the care is worth preserving: "Exploitation would require Modbus TCP to be enabled, which was not confirmed", and "There is no confirmation of any CVE exploited in this campaign". The vulnerability is a patch-currency signal on devices that were already exposed and already targeted — the point being that controllers left on the public internet in attacked cities were also running eight-year-old firmware. The exposure itself needs no vulnerability at all: "Exposing EtherNet/IP to the internet creates an unauthenticated path that, depending on device configuration, can allow attackers to obtain information about exposed assets or even write configurations on them."

CISA's acting director, interviewed on the sidelines of Black Hat, described what the agency keeps finding: "We're seeing things like [programmable logic controllers] that are open and accessible on the internet with either no password set or default password set" (Nextgov/FCW, 2026-08-06). Asked about attribution he was equally direct — "For us, we're not doing anything with attribution right now" — with the agency's focus on assisting affected operators instead.

Querying the Shodan search engine on August 3, 2026 returns 4,407 devices exposing port 44818.

Although we cannot confirm these particular assets were compromised in this campaign, they had some interesting characteristics

19 of the 22 hosts (86%) were on the same mobile carrier network, connected via cellular routers

Exposing EtherNet/IP to the internet creates an unauthenticated path that, depending on device configuration, can allow attackers to obtain information about exposed assets or even write configurations on them.

Forescout 2026-08-05

We're seeing things like [programmable logic controllers] that are open and accessible on the internet with either no password set or default password set

For us, we're not doing anything with attribution right now

Nextgov/FCW 2026-08-06

ATT&CK mapping

1 technique mapped from the cited reporting · MITRE ATT&CK v19.2

Initial Access TA0001
T1078.001Valid Accounts: Default Accounts

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

overlap matrix · ATT&CK page ↗

Persistence TA0003
T1078.001Valid Accounts: Default Accounts

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

overlap matrix · ATT&CK page ↗

Privilege Escalation TA0004
T1078.001Valid Accounts: Default Accounts

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

overlap matrix · ATT&CK page ↗

Stealth TA0005
T1078.001Valid Accounts: Default Accounts

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.