A recent report has uncovered 4,407 internet-connected Rockwell Automation/Allen-Bradley controllers that expose port 44818 (EtherNet/IP), with 65% of them located in the United States This article explores cyberattacks starting minnesota. . Following a series of coordinated cyberattacks starting in Minnesota late last month, IT services reported that more than 30 water systems across at least 12 states experienced operational disruptions.

Two days later, the FBI and EPA issued a joint advisory about similar incidents across Michigan, South Dakota, and Georgia, involving nine systems affected in Michigan and one wastewater lift station in South Dakota. Threat actors targeted MicroLogix 1100 and 1400 PLCs, altering controller logic or remotely changing IP addresses and passwords, resulting in loss of monitoring and control, pressure issues, and potential flooding risks that could contaminate drinking water pipes.

Among the 22 hosts identified in affected cities, 86% shared a single mobile carrier network, with 15 devices in Eagan, Minnesota showing matching network addresses, firmware, and GPS coordinates indicating a common fleet. Beyond controllers, researchers found expired certificates, abandoned remote-access hostnames, and forgotten servers tied to municipal utilities, including one certificate that has served only a default IIS page since 2019. Mitigations Forescout recommends blocking direct internet access to engineering protocols, restricting port 44818 and Modbus TCP via allowlists, and moving cellular gateways to private APNs or VPNs.