In May 2023, SecurityWeek reported that U.S. departments were examining whether Rockwell Automation’s China operations posed a cybersecurity risk to critical infrastructure. The reported concern centered on access to software code, customer-support work, and vulnerability patches at the company’s Dalian facility—not on a disclosed exploit or confirmed breach. Later Rockwell disclosures and a separate 2026 FBI/EPA alert provide useful security context, but they do not establish that the 2023 allegations were substantiated.
What was reported about the 2023 inquiry?
SecurityWeek reported on May 11, 2023, that several U.S. departments were examining whether Rockwell Automation’s Chinese operations created a cybersecurity risk to U.S. critical infrastructure. The reported focus was the company’s Dalian facility, where employees were said to work on code, customer support, and vulnerability patches.
The concern described in the report was that access to information or systems used in development and support could potentially be abused in ways that affected customer environments. SecurityWeek characterized the inquiry as being at an early stage and reported that Rockwell had not been notified. It did not identify a specific vulnerability.
Why did the Dalian work raise security questions?
Rockwell Automation products are used in settings including manufacturing, energy, government, and military environments. Industrial control software and programmable logic controllers (PLCs) can help monitor or control physical processes, so a security failure may affect operations as well as data.
#1 Best Overall
The reported risk scenario was a supply-chain or insider-access pathway: personnel with development or support privileges could, in principle, encounter sensitive information or weaknesses that might affect customers. That is a description of a potential risk, not evidence that Dalian employees accessed customer systems or inserted malicious code.
The 2023 report also described a customer-contract dispute involving requests for breach reporting, third-party assessments, and restrictions on support from countries such as China. Rockwell reportedly said code written in China was checked for vulnerabilities by U.S. employees.
Rank #2
What does Rockwell say about product and supply-chain risk?
Rockwell Automation’s fiscal 2025 annual report describes cybersecurity as a risk across products, services, and supply chains. It says products and services may be exposed to information theft, tampering, sabotage, or cyberattacks, and notes that customer security depends substantially on how systems are designed, configured, updated, and monitored. The filing also recognizes that software and hardware supply chains can introduce vulnerabilities.
The company says its Secure Development Lifecycle is audited annually by third-party firms and that its Third-Party Risk Program is intended to manage supplier risk. It also cautions that these controls cannot remove all risk: “We believe these measures reduce, but cannot eliminate, the risk of a cybersecurity incident internally or externally.”
Rank #3
What did the 2026 FBI/EPA alert say about Rockwell PLCs?
A July 30, 2026, public service announcement from the FBI and Environmental Protection Agency described attacks against internet-facing Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs. Since July 27, 2026, water and wastewater utilities in at least seven states had reported incidents. Some activity degraded water operations.
According to the agencies, attackers changed IP addresses and passwords, causing organizations to lose monitoring and control. One organization reported modified PLC project files; reported effects included loss of pressure and flooding. The alert shows the operational consequences that can follow when exposed controllers or their configurations are compromised. It does not connect those incidents to China, Dalian, or the 2023 inquiry.
Rank #4
How should operators reduce exposure?
The FBI and EPA recommended that utilities:
- Remove PLCs from direct internet exposure, using secure gateways or jump hosts for remote access.
- Use strong, unique passwords for the devices.
- Apply firewall or access-control-list rules so only authorized devices can communicate with controllers.
For organizations managing industrial systems, the broader controls should also address how vendors and other third parties receive access, how code and patches are reviewed, and how support activity is governed. Remote access should be mediated and limited to what is needed; customers should understand whether the vendor or the customer administers systems and credentials. Contract terms can clarify breach reporting, independent assessments, and support-location restrictions. These controls address different parts of the risk and do not substitute for keeping controllers off the open internet.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What is established—and what remains unresolved?
The available reporting establishes that U.S. departments were reported to be examining potential risks associated with Rockwell’s China operations in 2023. It does not establish a public final disposition of that inquiry, a named vulnerability tied to Dalian, or a confirmed breach through the facility. The 2026 FBI/EPA alert documents a distinct threat to internet-facing PLCs, not confirmation of the earlier allegations.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

