6,330 Internet-Exposed ICS Devices Near U.S. Data Centers Put Cooling and Power Systems at Risk

News Repost
MIM liquid cooling plate server data center
gbhackers.com

Published:

6,330 Internet-Exposed ICS Devices Near U.S. Data Centers Put Cooling and Power Systems at Risk / 美国数据中心附近6330台暴露于互联网的ICS设备使冷却与电力系统面临风险

Republished by Newlife - MIM. All rights belong to the original publisher; see Source below.

A newly published internet-exposure analysis has identified more than 6,300 high-confidence industrial control system and building automation devices accessible near 1,063 U.S. data centers. Exposing a largely overlooked attack surface around infrastructure responsible for cooling, power conditioning and environmental monitoring.

The finding underscores a fundamental security gap: hardened server networks do not necessarily extend to the operational technology that keeps those servers alive. The research, conducted using passive Shodan data rather than direct probing or exploitation, identified publicly reachable BACnet controllers, PLC-related interfaces and power-management systems within a one-kilometer radius of documented data-center locations.

Crucially, IP geolocation provides metropolitan proximity not proof that each device sits inside a specific facility so the results should be treated as a substantial regional exposure indicator rather than an attribution list. The risk is operationally significant. Data centers depend on building automation systems to regulate CRAC and CRAH units, chillers, cooling towers, pumps, humidity controls, UPS platforms, generators and power-distribution equipment.

A successful intrusion could enable adversaries to alter temperature setpoints, disrupt monitoring, lock out facilities personnel, manipulate power-management functions or create conditions that trigger protective shutdowns. Unlike a conventional IT compromise, the likely outcome is not merely data loss; it can be a physical availability event. BACnet accounted for 3,664 devices, or 58% of the verified sample, while Fox/Niagara services comprised another 1,453, or 23%.

TrendAI™ Research found that, after filtering 73,847 raw records for honeypots, false positives and non-OT services, researchers retained 6,300 verified devices across 3,991 unique IP addresses. Together, those protocols represented 81% of the exposed environment, showing that building automation not traditional heavy-industrial SCADA is the dominant vector near data-center markets.

The study also found 143 multi-protocol gateways, including 125 systems simultaneously exposing Niagara and BACnet. Such systems can act as high-value aggregation points because they bridge disparate HVAC, environmental and electrical subsystems. When we see over 300 devices at the same coordinates, that is the ISP’s registered location for that IP address block, which typically corresponds to a commercial or industrial district where data centers cluster.

Niagara/Tridium systems represented 28% of identified devices. The platform is widely deployed to integrate building technologies through a central management layer, making it operationally useful but potentially dangerous when exposed without strong authentication, encryption and network isolation.

Researchers also observed devices associated with Vertiv/Liebert, vendors whose products include precision cooling, UPS and power-distribution infrastructure purpose-built for data centers. Their presence raises the possibility that some exposures relate directly to critical facility operations rather than neighboring commercial properties.

In the water sector, Arkansas City, Kansas, switched to manual operations after a September 2024 attack on its treatment facility prompted an FBI investigation. The data challenges the assumption that new infrastructure is inherently better secured. Facilities permitted from 2021 onward showed a 13.1% nearby-exposure rate, compared with 4.9% for pre-2010 sites.

This correlation does not establish causation, but it aligns with a plausible operational reality: AI-era buildouts prioritize rapid deployment, remote manageability and increasingly complex cooling systems, conditions that can leave OT hardening behind schedule. Threat actors do not need exotic zero-days to abuse weakly protected OT.

A joint advisory from CISA, NSA, FBI and DOE warned that actors have developed tools capable of scanning, compromising and controlling ICS devices, including PLCs and OPC UA servers. The agencies recommend isolating ICS from corporate and internet networks, enforcing multifactor authentication for remote access, replacing default credentials, limiting management connections and maintaining offline, integrity-checked backups.

For data-center operators, the takeaway is direct: discover every BAS, EPMS, UPS and cooling interface with internet reachability; eliminate direct exposure; segment OT from IT through tightly controlled conduits; and continuously monitor for abnormal control traffic. In modern facilities, the firewall protecting the compute environment is insufficient if the chiller, generator or UPS controller remains reachable from the public internet.

Source

- gbhackers.com (2026-08-13) - Original article: 6,330 Internet-Exposed ICS Devices Near U.S. Data Centers Put Cooling and Power Systems at Risk

Back to Blog

Have a Part Design? Let's Evaluate It for MIM.

Send us your 2D/3D drawings — our engineers will respond with a feasibility assessment and quotation.