Critical Infrastructure Security
,
Governance & Risk Management
,
Operational Technology (OT)
Internet-Exposed Programmable Logic Controllers ‘An Easy Target’

Thousands of vulnerable industrial devices, accessible from the public internet, are being targeted by Iran-linked hackers, U.S. authorities said this week.
See Also: How Cyberattacks Can Turn Battery Farms Into Grid Blackouts
“Iranian-affiliated threat actors are conducting a range of targeted cyber activity to include compromise [of] unsecure internet-connected … devices,” the Cybersecurity and Infrastructure Security Agency said in a statement Wednesday.
The warning was an update to an advisory CISA originally published in April. The revision is because a broader range of device brands are under attack, CISA said. The original advisory mentioned devices made by Rockwell Automation. The update this week expands that to include “observed targeting of Schneider Electric, Siemens and possibly other … manufacturers.”
Successful attacks have struck organizations across several U.S. critical infrastructure sectors, including water and wastewater, energy and local government facilities, CISA stated, “resulting in operational disruption and financial loss for affected organizations.”
The devices, known as programmable logic controllers, are used to automatically control machinery like valves – opening and closing them in response to pre-programmed signals from sensors. A valve might be programmed to open when the water level in a tank reaches a certain level, so that it doesn’t overflow. Because they’re designed to be deployed on a closed network, rather than on the internet, many PLCs don’t require any login or authentication and could be reprogrammed by hackers, explained Patrick Gillespie, the practice director for operational technology at GuidePoint Security.
“They’re an easy target,” he said.
Using specialized search tools like Shodan, anyone can locate PLCs exposed on the internet. Even those that can’t be reprogrammed by a hacker because of the settings on the physical device can still be subject to a denial of service attack. “That can cause production issues because if it takes a PLC 30 seconds to reset, there’s that 30 second window when the system is not going to run as intended,” he said.
As of today, Gillespie added, Shodan was showing 4,278 Rockwell devices globally exposed to the internet, almost two thirds of them in the United States. Conversely, of the 2,577 Schneider Electric devices exposed, only 8% were in the U.S.
“Rockwell has a heavy presence in the U.S. market and these threat actors are of course targeting the U.S., so it’s statistically more likely that they’re going to hit a Rockwell device because there are more of those here,” Gillespie explained.
“That’s why I believe that Rockwell was listed in the first advisory,” he said, not because other manufacturers’ devices weren’t being targeted, but because the Rockwell attacks were “being seen first from an incident response perspective.” With the benefit of three months more data, it was now clear the attackers were “seeing more [PLCs from different manufacturers] to target in the U.S.”
PLCs should always be deployed behind a firewall or other security gateway, which would make them invisible to Shodan, Gillespie continued, “Right now there are probably millions of Rockwell devices in the U.S. and 99% of them are probably behind a firewall.”
The fact that some of the owners and operators of exposed PLCs could be identified by their IP addresses has led some to call for the government to do more.
No one appears to be individually warning the owners and operators to protect themselves, said Marc Sachs, of the Center for Internet Security, a non-profit that works with state and local governments and operates the Multi-State Information Sharing and Analysis Center.
“Who has the duty to tell them that they’re exposed? I would say certainly our own federal government, through CISA, has some of that responsibility,” he said.
CISA should be resourced better to do more, he added. Issuing advisories was necessary and helpful to those larger organizations with a security team and budget. But who would be reading them at a small town water utility that lacks security personnel? “Shouldn’t they be sending out notifications directly to the asset owners,” if they can be identified, Sachs asked.
With nearly 3,000 devices exposed from just two manufacturers, scale is a problem, Sachs acknowledged, “Where are the resources coming from?”
Moreover, because of the nature of many of the internet connections, made using cellular modems, the IP addresses in many cases only reveal the name of the network operator.
“Half of those exposed Rockwell devices in the U.S., the IP address belongs to Verizon,” said Gillespie, “So you’d have to have a subpoena, or you’d have to work with Verizon to try to figure out who the end user [of the PLC] is.”
Even then, the Verizon customer might be a product vendor or a third-party service provider who installed the PLC. “It still doesn’t tell you who the end user is. That’s the challenge of trying to track them down and actually get a firewall in front of them because the true asset owner that runs that water or waste water facility maybe doesn’t even know” that their devices are connected.
A CISA spokesperson told ISMG that it “works regularly to identify vulnerable internet-facing devices that support critical infrastructure. Whenever possible, we notify the owner or operator of these devices and encourage them to take steps to secure their systems.”
