Summary

  • Forescout’s 5 August analysis says an August 3 Shodan query found 4,407 controllers exposing EtherNet/IP port 44818 to the internet.
  • The United States accounted for 2,844 results, or 65%; Canada had 513, Spain 146, Italy 109 and Australia 96.
  • More than 70% of US results sat on large mobile-carrier networks, indicating a cellular-routing exposure surface rather than a carrier breach.
  • Forescout found 22 hosts in cities named in the current water-utility campaign, but could not confirm that those hosts were compromised.
  • Nineteen of the 22 appeared susceptible by firmware to CVE-2017-16740; neither required Modbus TCP enablement nor exploitation was confirmed.
  • The FBI reports incidents in at least seven states since July 27, while Forescout says 12; the FBI figure is the authoritative incident count and the discrepancy remains material.

Exposure is the first denominator, not the incident count

The 4,407 figure comes from a search for internet-facing devices with EtherNet/IP port 44818 exposed. It is a count of search results under a defined query at a defined time. It is not a count of water systems, unique organisations, victims or compromised controllers. One organisation may operate several devices, and an exposed host may support a process outside water infrastructure.

That boundary does not make the result harmless. An industrial controller reachable from the public internet offers an attacker a discovery and interaction path that should ordinarily be removed or tightly mediated. But incident analysis becomes less useful when exposure is rhetorically converted into compromise.

Cellular routing is the concentration point

Forescout reported that more than 70% of the US results were on networks of large mobile carriers. Cellular routers are often used to connect remote utility assets where fixed connectivity is costly. The operational convenience can create a public route to equipment that owners assumed was isolated.

The concentration is not evidence that a carrier was breached or owns the controller. It indicates where address assignment, routing, firewall policy and customer configuration intersect. Remediation therefore requires cooperation: asset owners must inventory and isolate systems, while connectivity providers can help identify exposed endpoints and offer private addressing or managed controls.

The device mix points to long-lived equipment

MicroLogix 1400 accounted for 50% of Forescout’s results, CompactLogix 1769 for 22%, MicroLogix 1100 for 8% and ControlLogix 5590 for 8%. The presence of older families illustrates the long operating life of industrial systems. Replacement can require downtime, revalidation and changes to physical processes, so patching is not as simple as updating office software.

Long life makes compensating controls more important. Removing direct internet routes, placing remote access behind authenticated gateways, monitoring protocol activity and maintaining recoverable logic backups can reduce risk even where a controller cannot immediately be replaced.

Twenty-two overlaps do not establish twenty-two compromises

Forescout cross-referenced its scan with cities named in the recent water-utility campaign and found 22 hosts. Nineteen were on the same mobile-carrier network. The overlap is useful for prioritising investigation, but Forescout explicitly could not confirm that those particular devices had been compromised.

Shared geography and a shared carrier can arise from common procurement and network design. They do not establish common ownership, attacker attribution or a single intrusion path. The 22 should be treated as a high-priority review queue, not a victim list.

Firmware susceptibility still requires a missing condition

Nineteen of the 22 hosts appeared, from their firmware, susceptible to CVE-2017-16740. Rockwell’s advisory describes the affected firmware boundary. Forescout also notes that exploitation requires Modbus TCP to be enabled, a condition it could not confirm remotely. No evidence shows that the vulnerability was used in the campaign.

This separates susceptibility from exploitability and exploitation. A firmware version can fall within an affected range while the necessary service is disabled; an exploitable system can remain unattacked. Defenders should still remediate the condition, but reporting should not collapse the stages.

The FBI record defines the confirmed operational effects

The FBI and EPA say utilities in at least seven states reported incidents since July 27. Actors changed controller IP addresses and passwords, causing losses of monitoring or control; reported consequences included pressure loss and flooding, and one victim found its PLC project file modified. The alert does not attribute the activity.

Forescout’s article refers to at least 12 states. Because the FBI page is the authoritative incident notice, seven is the defensible published count unless the agency updates it. The mismatch should be preserved rather than silently blended. It also demonstrates why scan statistics cannot substitute for incident records.

Independent scans are not a clean time series

Censys counted 4,148 Rockwell or Allen-Bradley hosts on July 30 and said Verizon Business, AT&T Mobility and T-Mobile USA represented 59%. Forescout’s Shodan query found 4,407 on August 3. Different engines, query logic, dates and classification can produce different denominators, so the difference should not be called growth.

Within Forescout’s own method, exposed results declined from 7,814 in March 2020 to 4,169 in June 2026 before rising to 4,407 in the August snapshot. That longer view suggests substantial reduction, but also a persistent residue and a recent rebound within the same series.

Sources