Thousands of Industrial Control Systems Exposed Near U.S. Data Centers, Raising Physical Security Risks
A recent internet-exposure analysis has uncovered over 6,300 high-confidence industrial control system (ICS) and building automation devices accessible near 1,063 U.S. data centers, revealing a critical but often overlooked attack surface. The research, conducted by TrendAI Research using passive Shodan data, identified publicly reachable devices including BACnet controllers, Niagara Framework instances, PLC interfaces, and power-management systems within a one-kilometer radius of documented data center locations.
The findings highlight a fundamental security gap: while server networks may be hardened, the operational technology (OT) infrastructure responsible for cooling, power conditioning, and environmental monitoring often remains exposed. These systems regulate CRAC/CRAH units, chillers, UPS platforms, generators, and humidity controls, meaning a successful intrusion could allow adversaries to alter temperature setpoints, disrupt monitoring, lock out personnel, or trigger protective shutdowns leading to physical availability disruptions rather than just data loss.
Key vulnerabilities identified:
- BACnet devices accounted for 58% (3,664) of the exposed systems, while Niagara/Tridium systems made up 23% (1,453).
- 143 multi-protocol gateways (including 125 exposing both Niagara and BACnet) were found, acting as high-value aggregation points bridging HVAC, environmental, and electrical subsystems.
- Vertiv/Liebert devices, commonly used in data center cooling and power infrastructure, were also detected, suggesting some exposures may directly impact critical facility operations.
Geolocation data revealed clusters of exposed devices near hyperscale data centers in Silicon Valley, though IP-based proximity does not confirm exact physical locations. The study also challenged assumptions about newer infrastructure, finding that facilities permitted since 2021 had a 13.1% exposure rate nearly triple that of pre-2010 sites potentially due to rapid deployment and complex cooling demands outpacing OT security hardening.
The risks are not theoretical. Recent incidents, such as the 2024 attack on Arkansas City, Kansas’ water treatment facility, demonstrate how exposed ICS devices can lead to operational disruptions. U.S. agencies (CISA, NSA, FBI, and DOE) have warned that threat actors are actively developing tools to scan, compromise, and control ICS devices, including PLCs and OPC UA servers, often exploiting weak authentication and default credentials.
While the research did not involve direct probing, the findings underscore the need for data center operators to identify and secure all internet-reachable OT systems, enforce strict network segmentation, and monitor for abnormal control traffic. The exposure of these devices even if not directly inside data centers poses a regional risk, as adversaries could exploit them to disrupt critical infrastructure.
Source: https://gbhackers.com/6330-internet-exposed-ics-devices/
Tridium cybersecurity rating report: https://www.rankiteo.com/company/tridium
Vertiv cybersecurity rating report: https://www.rankiteo.com/company/vertiv
"id": "TRIVER1786618728",
"linkid": "tridium, vertiv",
"type": "Vulnerability",
"date": "9/2024",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Technology, Critical Infrastructure',
'location': 'United States (clusters near hyperscale '
'data centers in Silicon Valley)',
'type': 'Data centers'}],
'attack_vector': 'Internet-exposed ICS/OT devices',
'description': 'A recent internet-exposure analysis uncovered over 6,300 '
'high-confidence industrial control system (ICS) and building '
'automation devices accessible near 1,063 U.S. data centers. '
'The exposed devices include BACnet controllers, Niagara '
'Framework instances, PLC interfaces, and power-management '
'systems, which regulate critical infrastructure such as '
'cooling, power conditioning, and environmental monitoring. '
'Successful intrusion could lead to physical availability '
'disruptions.',
'impact': {'downtime': 'Potential physical availability disruptions',
'operational_impact': 'Alteration of temperature setpoints, '
'disruption of monitoring, lockout of '
'personnel, protective shutdowns',
'systems_affected': 'Industrial control systems (ICS), building '
'automation systems, power-management systems'},
'lessons_learned': 'Data center operators must secure all internet-reachable '
'OT systems, enforce strict network segmentation, and '
'monitor for abnormal control traffic to mitigate regional '
'risks.',
'post_incident_analysis': {'corrective_actions': 'Secure internet-reachable '
'OT systems, enforce network '
'segmentation, monitor for '
'abnormal control traffic',
'root_causes': 'Rapid deployment of OT '
'infrastructure outpacing security '
'hardening, weak authentication, '
'default credentials, lack of '
'network segmentation'},
'recommendations': ['Identify and secure all internet-reachable OT systems',
'Enforce strict network segmentation',
'Monitor for abnormal control traffic'],
'references': [{'source': 'TrendAI Research'},
{'source': 'Shodan'},
{'source': 'CISA, NSA, FBI, and DOE warnings'}],
'response': {'enhanced_monitoring': 'Recommended',
'network_segmentation': 'Recommended',
'remediation_measures': 'Identify and secure internet-reachable '
'OT systems, enforce network '
'segmentation, monitor for abnormal '
'control traffic'},
'title': 'Thousands of Industrial Control Systems Exposed Near U.S. Data '
'Centers, Raising Physical Security Risks',
'type': 'Exposure of Critical Infrastructure',
'vulnerability_exploited': 'Weak authentication, default credentials, lack of '
'network segmentation'}