Published Monday, August 24, 2026 at 11:01 AM PT

<strong>BREAKING: Iranian State Actors Exploiting Internet-Exposed PLCs in US Critical Infrastructure</strong>

BLUF: Iranian-linked threat actors are actively compromising programmable logic controllers (PLCs) across US water and energy infrastructure. FBI confirms targeting of Rockwell Automation and Allen-Bradley devices. Critical infrastructure operators must immediately audit and isolate internet-exposed OT devices. This is an ongoing campaign.

DETAILS:

  • FBI issued formal warning against Iranian cyberattacks targeting operational technology (OT) devices, specifically PLCs manufactured by Rockwell Automation and Allen-Bradley platforms
  • Threat actors are exploiting internet-exposed PLCs in US water supply systems (documented incidents in New Jersey, Alabama, and Minnesota) and energy control systems
  • Iran-linked actor CyberAv3ngers linked to Minnesota water system compromise; broader campaign uses modular C&C framework for device control
  • Attack vector: direct internet exposure of PLCs without network segmentation or authentication hardening
  • Intrusions enable remote manipulation of industrial control systems with potential to disrupt service delivery or cause physical damage

IMPACT:

  • Scope: US critical infrastructure — water treatment/distribution systems and energy control grids (exact number of compromised sites unconfirmed; incidents confirmed in multiple states)
  • Affected systems: Rockwell Automation ControlLogix, CompactLogix, and Allen-Bradley PLC families; any internet-exposed OT device running these platforms
  • Risk level: CRITICAL — compromised PLCs can be remotely manipulated to alter water chemistry, redirect flows, or disrupt power distribution without operator visibility
  • Attribution: Iran-linked state actors; coordination with US indictment activity against 17 Iranian nationals over cyber espionage (2024–present)

RECOMMENDED ACTIONS:

  1. Immediate (24 hours): Audit all PLCs for internet exposure via port scans and network telemetry; prioritize Rockwell/Allen-Bradley devices
  2. Emergency: Isolate any internet-exposed PLCs from external networks; migrate to air-gapped or VPN-protected access only
  3. Baseline authentication: Enforce strong credentials (no defaults), disable remote access protocols (Ethernet/IP, Modbus TCP) unless production-critical; require multi-factor authentication
  4. Indicators: Monitor for unauthorized C&C communication, unexpected firmware changes, or configuration modifications on OT devices
  5. Report: File incident reports with CISA (central@cisa.dhs.gov) and FBI (IC3.gov) if compromise suspected

SOURCES:

  • FBI cybersecurity advisory — Rockwell Automation/Allen-Bradley targeting
  • TrueSec threat report — Iranian OT infrastructure attacks
  • SecurityAffairs, SecurityWeek — Iran-linked actor campaigns vs. US water/energy systems
  • The Register — CyberAv3ngers attribution (Minnesota water systems)
  • US Department of Justice indictment (17 Iranian nationals, cyber espionage)

STATUS: Ongoing active campaign. CISA and FBI monitoring. No patch availability stated; mitigation is network isolation and access control.


Recent high-severity events at publish time:

Recent high-severity events