Internet-Exposed Programmable Logic Controllers Present an Easy Target for Hackers
In a troubling revelation this week, U.S. authorities disclosed that thousands of vulnerable industrial devices, specifically programmable logic controllers (PLCs), are being targeted by hackers with links to Iran. The Cybersecurity and Infrastructure Security Agency (CISA) issued a statement highlighting the alarming rise in cyber activities directed at these unsecure internet-connected devices.
This warning serves as an update to an advisory previously published by CISA in April. The revision indicates a broadening of the scope regarding which brands are under attack. Initially, the advisory focused on devices manufactured by Rockwell Automation; however, the updated guidance now includes other major players, such as Schneider Electric and Siemens, among potentially more manufacturers.
CISA specified that successful breaches have affected a variety of critical infrastructure sectors within the United States, including water and wastewater treatment facilities, energy production, and even local governmental entities. The impacts of these attacks have led to operational disruptions and financial losses for the organizations involved, underscoring a significant risk to national security.
Programmable logic controllers automate the control of machinery and processes, acting as the backbone of many industrial systems. For instance, these devices can manage the opening and closing of valves based on sensor signals, preventing overflow in tanks. Many PLCs are designed to operate within closed networks—meaning they shouldn’t be connected to the internet—resulting in many lacking any form of login or authentication requirements. This inherent vulnerability makes them attractive targets for cybercriminals.
Patrick Gillespie, the practice director for operational technology at GuidePoint Security, stated that these systems are "an easy target" for hackers. With specialized search tools like Shodan, anyone can discover PLCs that are exposed to the internet. Even if a hacker cannot reprogram a specific PLC due to device settings, they can still execute denial-of-service (DoS) attacks. Gillespie elaborated that during a DoS attack, production halts momentarily while the PLC resets, which could lead to significant delays in operations.
As of now, Shodan reports nearly 4,300 Rockwell devices exposed globally, with approximately two-thirds located within the United States. In contrast, out of 2,577 Schneider Electric devices identified, only about 8% are in the U.S. Gillespie pointed out that Rockwell has a dominant presence in the U.S. market, making these devices more appealing targets for threat actors focused on American interests.
The initial emphasis on Rockwell devices in the first advisory could be attributed to the significant number of incidents observed thus far. Recent data has clarified that attackers are increasingly targeting PLCs from various manufacturers, prompting CISA’s updated warning.
For optimal security, Gillespie advocated for PLCs to be deployed behind firewalls or other security gateways. This would render them invisible to tools like Shodan, effectively reducing their vulnerability. “Right now, there are probably millions of Rockwell devices in the U.S., and 99% of them are likely behind a firewall,” he added.
The identification of exposed PLCs by their IP addresses has led some cybersecurity experts to urge greater government interventions. Marc Sachs from the Center for Internet Security emphasized that it’s vital for the federal government to take responsibility, particularly through CISA, to inform potentially vulnerable entities about their exposure.
Sachs pointed out that while advisories might be beneficial for larger organizations with dedicated security teams, smaller utilities, like local water utilities, often lack the personnel to engage with such warnings. He raised a crucial question regarding whether CISA should reach out directly to asset owners, especially if they can be identified.
However, the scale of the issue complicates matters. With nearly 3,000 devices exposed from just two manufacturers, the resources available to mitigate these risks are limited. Besides, many of these devices are connected via cellular modems, which obscures the identity of the end user. According to Gillespie, many IP addresses linked to exposed Rockwell devices belong to major network operators, revealing little about the actual users.
Even when an effort is made to track down end users, the complexity of ownership complicates the situation further. The true asset owner operating a water treatment facility might not even be aware of their devices’ internet connectivity, making it increasingly challenging for authorities to enforce security measures.
In light of the growing threats to critical infrastructure driven by unprotected programmable logic controllers, CISA’s engagement efforts continue. An agency spokesperson indicated that CISA regularly identifies vulnerable devices within critical infrastructure sectors and strives to notify owners when possible, encouraging them to secure their systems proactively.
As cyber threats evolve, the call for enhanced protection measures becomes increasingly urgent. The responsibility lies not only with device manufacturers and operators but also extends to governmental agencies that have the capacity to safeguard essential industries from the looming specters of cyberattacks. The future of America’s critical infrastructure may very well hinge on how effectively these vulnerabilities can be addressed in an ever-expanding digital landscape.

