Published Monday, August 24, 2026 at 11:01 AM PT

BLUF: Iranian-linked threat actors are actively compromising programmable logic controllers (PLCs) across US water and energy infrastructure. FBI confirms targeting of Rockwell Automation and Allen-Bradley devices. Critical infrastructure operators must immediately audit and isolate internet-exposed OT devices. This is an ongoing campaign.
DETAILS:
- FBI issued formal warning against Iranian cyberattacks targeting operational technology (OT) devices, specifically PLCs manufactured by Rockwell Automation and Allen-Bradley platforms
- Threat actors are exploiting internet-exposed PLCs in US water supply systems (documented incidents in New Jersey, Alabama, and Minnesota) and energy control systems
- Iran-linked actor CyberAv3ngers linked to Minnesota water system compromise; broader campaign uses modular C&C framework for device control
- Attack vector: direct internet exposure of PLCs without network segmentation or authentication hardening
- Intrusions enable remote manipulation of industrial control systems with potential to disrupt service delivery or cause physical damage
IMPACT:
- Scope: US critical infrastructure — water treatment/distribution systems and energy control grids (exact number of compromised sites unconfirmed; incidents confirmed in multiple states)
- Affected systems: Rockwell Automation ControlLogix, CompactLogix, and Allen-Bradley PLC families; any internet-exposed OT device running these platforms
- Risk level: CRITICAL — compromised PLCs can be remotely manipulated to alter water chemistry, redirect flows, or disrupt power distribution without operator visibility
- Attribution: Iran-linked state actors; coordination with US indictment activity against 17 Iranian nationals over cyber espionage (2024–present)
RECOMMENDED ACTIONS:
- Immediate (24 hours): Audit all PLCs for internet exposure via port scans and network telemetry; prioritize Rockwell/Allen-Bradley devices
- Emergency: Isolate any internet-exposed PLCs from external networks; migrate to air-gapped or VPN-protected access only
- Baseline authentication: Enforce strong credentials (no defaults), disable remote access protocols (Ethernet/IP, Modbus TCP) unless production-critical; require multi-factor authentication
- Indicators: Monitor for unauthorized C&C communication, unexpected firmware changes, or configuration modifications on OT devices
- Report: File incident reports with CISA (central@cisa.dhs.gov) and FBI (IC3.gov) if compromise suspected
SOURCES:
- FBI cybersecurity advisory — Rockwell Automation/Allen-Bradley targeting
- TrueSec threat report — Iranian OT infrastructure attacks
- SecurityAffairs, SecurityWeek — Iran-linked actor campaigns vs. US water/energy systems
- The Register — CyberAv3ngers attribution (Minnesota water systems)
- US Department of Justice indictment (17 Iranian nationals, cyber espionage)
STATUS: Ongoing active campaign. CISA and FBI monitoring. No patch availability stated; mitigation is network isolation and access control.
Recent high-severity events at publish time:

