Rockwell Automation PLC Cyberattacks 2026: Lessons for Legacy Users
The largest operational technology (OT) security incident of 2026 unfolded over six weeks this spring. Between March and mid-April, Iranian hackers systematically targeted nearly 4,000 internet exposed Rockwell Automation and Allen-Bradley PLCs across US critical infrastructure. The campaign prompted a joint federal advisory from CISA, the FBI, NSA, DOE, EPA, and US Cyber Command on April 7, followed by a Censys exposure report on April 10.
Engineers running legacy Rockwell systems (SLC 500, PLC-5, older MicroLogix) should pay attention. This attack was years in the making.
What Happened: A Timeline of the 2026 Campaign
March 2026. Iranian threat activity against US critical infrastructure escalated sharply. Attackers aligned with two principal groups, the IRGC-linked CyberAv3ngers and the MOIS-linked Handala, began systematic reconnaissance of internet facing industrial control devices. Their target was Rockwell Automation PLCs exposed on port 44818 via EtherNet/IP.
April 7. CISA, the FBI, NSA, DOE, EPA, and US Cyber Command issued a joint advisory confirming attackers had extracted project files from compromised devices, manipulated HMI and SCADA displays, and deployed wiper malware. At least one water facility was forced to manual operation after losing PLC control.
April 10. Censys published exposure data showing 5,219 global hosts responding as Rockwell or Allen-Bradley devices reachable via EtherNet/IP, approximately 3,900 inside the United States. The vast majority were simply connected to the public internet with default settings.
The attackers were not exploiting zero-days. They used Shodan and Censys to find Rockwell-branded PLCs on the public internet, then attempted default credentials and direct EtherNet/IP command exploitation.
Which Devices Were Targeted
Any Rockwell Automation or Allen-Bradley PLC with Ethernet connectivity exposed to the public internet was a viable target. Affected models included ControlLogix (1756 series, the flagship widely deployed in critical infrastructure), CompactLogix (1769, 5370, 5380 series, common in mid-size manufacturing and utilities), MicroLogix (1100, 1400 series, older and widely used in smaller facilities and remote sites), SLC 500 with Ethernet (designed in the 1990s with no meaningful security features), and PLC-5 with Ethernet (a 1980s design still running in oil and gas, water, and heavy industry).
The attackers did not need advanced capabilities. EtherNet/IP implements minimal authentication by design, and many sites had never changed default passwords, disabled unused CIP services, or added a firewall between their PLCs and the carrier network.
Why This Matters for Legacy PLC Users
The 2026 Rockwell campaign exposes a structural vulnerability deferred for two decades. Hundreds, possibly thousands, of SLC 500 and MicroLogix systems remain in active service across American water plants, energy sites, and factories. These controllers were designed before internet-connected PLCs were imagined. They have no cryptographic authentication, no secure boot, no role-based access control, and often no firmware patching mechanism.
You cannot patch a PLC-5. There is no update that retrofits encryption onto a SLC 500's serial-to-Ethernet bridge. The devices are what they are.
This creates a hard deadline. The EU's NIS2 Directive requires compliance by October 2026, with substantial fines, and explicitly covers OT systems. While the US lacks a single equivalent regulation, sector-specific mandates from TSA, DOE, and EPA are moving in the same direction. Facilities running internet exposed legacy PLCs are increasingly in regulatory violation, and that was true before Iranian APT groups started fingerprinting their controllers.
The April 7 joint advisory makes clear that federal agencies now consider these devices an active national security vector.
What to Do If You're Running Legacy Rockwell PLCs
Step 1: Audit every PLC on your network. Use Shodan, Censys, or OT asset discovery tools (Dragos, Nozomi, Claroty) to identify every Rockwell device on your public IP ranges. In the Censys scan, most exposed devices were not intentionally exposed. They sat behind misconfigured firewalls or were connected for remote troubleshooting and never disconnected.
Step 2: Remove PLCs from the public internet. Place every Rockwell PLC reachable on port 44818 behind a properly configured firewall. For remote access, use a cellular modem with VPN, not a direct Ethernet drop. Air-gap critical controllers where possible.
Step 3: Upgrade where feasible. Newer CompactLogix 5380 and 5480 series controllers offer trusted-slot authentication, CIP security extensions, and firmware integrity verification.
Step 4: For truly legacy platforms such as SLC 500 and PLC-5, accept that you cannot patch them. You have three options. Network segmentation with unidirectional gateways uses data diode or unidirectional gateway appliances to allow monitoring traffic out while preventing any inbound commands from reaching the controller. Migration to a current platform uses Rockwell's migration programs for SLC 500 to CompactLogix and PLC-5 to ControlLogix, which are mature but require downtime planning. Hardening in place is possible if migration is not immediate: change all default passwords, disable unused EtherNet/IP services, restrict access via ACLs, and monitor EtherNet/IP traffic for anomalous commands.
None of these are perfect. But any is better than having an Iranian APT group extract your project files and overwrite controller firmware at 2 AM on a Saturday.
The Spare Parts Angle
As facilities scramble to secure or migrate aging Rockwell systems, demand is increasing for spare ControlLogix and CompactLogix modules (1756, 1769 series) for swap-in replacements of potentially compromised units, Ethernet security appliances (bump in the wire devices that add authentication and traffic inspection without controller firmware changes), legacy-to-current migration kits (adapters, chassis, and power supplies for SLC 500 to CompactLogix swaps), and hard to find Allen-Bradley modules for facilities maintaining legacy spares during multi-year migrations.
TZTechio's inventory, from current 5380-series CompactLogix to legacy 1746 and 1771 I/O, covers this range. When a water plant needs a 1756-L73 by Wednesday, availability matters.
Wider Context: OT Attacks Are Accelerating
The 2026 Rockwell campaign did not happen in isolation. It is the latest in a series of OT incidents that have escalated since 2023.
The Unitronics attacks (2023-2024) were Iranian-linked attacks on Israeli-made Unitronics PLCs in US water utilities using the same playbook of Shodan scans, default credentials, and taking control. The Stryker 80,000-device wipe (March 2026) happened weeks before the Rockwell campaign and wiped 80,000 endpoints from medical device infrastructure. It was not an OT incident, but it proved that safety critical fleets are in the crosshairs. The NIS2 deadline (October 2026) has EU member states scrambling to meet requirements for mandatory incident reporting, supply chain security, and OT risk management. US regulatory push will follow in 2027.
Attackers have learned that industrial control systems are the weak point of critical infrastructure. The 2026 Rockwell campaign proves you do not need nation-state resources to compromise most PLCs. You just need a Shodan query and the willingness to try default passwords.
For anyone responsible for a legacy Rockwell system, the time for planning is over. Audit your controllers. Disconnect them from the internet. If you cannot protect them, migrate them, before someone else does it for you.
---
*Sources: CISA/FBI/NSA/DOE/EPA/US Cyber Command Joint Advisory, April 7, 2026; Censys Research Report, April 10, 2026; BleepingComputer; CNN; Defense One. This article is for informational purposes and does not constitute cybersecurity or compliance advice. Consult qualified professionals for your specific environment.*
July 28,2026