Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States, but Forescout could not confirm any were compromised. That figure counts exposed controllers, not water utilities or confirmed victims. Forescout said the publicly described effects could be achieved without a vulnerability exploit: attackers changed IP addresses and set passwords on controllers that were already reachable, causing operators to lose visibility and, in some cases, control of connected equipment. Neither the government alerts nor Forescout's analysis explains how the attackers found, selected, or initially accessed their targets. Water and wastewater utilities in at least seven states have reported incidents since July 27, the FBI and EPA said in a July 30 public service announcement. The Hacker News found on August 6 that Forescout's post says the announcement confirmed at least 12 states, while the FBI page says seven. No agency has attributed the campaign. Whatever the final count, defenders can act now by taking the controllers off the public internet. Exposing EtherNet/IP on port 44818 creates an unauthenticated path that, depending on device configuration, lets an attacker identify a controller or write settings to it, Forescout said. Forescout found more than 70% of the US-based exposed controllers on large mobile carrier networks. The FBI and EPA recommend strong authentication, updates and logging for cellular modems, with remote access isolated through a private APN, VPN or similar architecture. A July 30 Censys snapshot found 4,148 exposed Rockwell/Allen-Bradley EtherNet/IP hosts, with Verizon Business, AT&T Mobility and T-Mobile USA accounting for 59%. The Censys and Forescout snapshots both exceed 4,100 hosts, but different platforms, queries and dates make the figures not