Skip to content
23 July 2026

U.S. Warns of Iranian Cyber Attacks on Industrial Control Systems

Iranian cyber actors are exploiting programmable logic controllers across U.S. critical infrastructure, causing operational disruptions and financial losses

U.S. Warns of Iranian Cyber Attacks on Industrial Control Systems

The United States is facing a significant cyber threat from Iranian-affiliated actors targeting programmable logic controllers (PLCs) across critical infrastructure sectors. This ongoing campaign has resulted in operational disruptions and financial losses, highlighting the urgent need for robust cybersecurity measures.

The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and other authoring agencies have issued urgent warnings about the exploitation of internet-connected operational technology (OT) devices. These devices, including PLCs from Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens are being targeted to manipulate data and cause disruptions.

Iranian Cyber Actors Exploit PLCs

The Iranian-affiliated advanced persistent threat (APT) actors are conducting these attacks to cause disruptive effects within the United States. The targeted sectors include Government Services and Facilities, Water and Wastewater Systems (WWS), and Energy Sectors. The actors have been observed using malicious project files and manipulating data displayed on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays.

The authoring agencies have identified that the actors are using leased, third-party hosted infrastructure and manufacturers’ PLC programming software to connect to misconfigured victim PLCs. The targeted devices include Rockwell Automation CompactLogix and Micro850 PLCs, Schneider Electric BMX P34/Modicon M340 PLCs, and Siemens S7-1200 series PLCs.

Technical Details of the Cyber Attacks

The actors have been observed using several foreign-based IP addresses to access internet-facing PLCs. They have targeted ports associated with OT vendors’ protocols, including 44818, 2222, 102, and 502 as well as targeting modems on port 22. The actors have also utilized Dropbear Secure Shell (SSH) software on victim modems to gain remote access.

After extracting device project files, the actors have modified and deleted project file logic, including Add-On Instructions (AOIs) and manipulated data on HMI and SCADA displays. These changes have disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators.

The authoring agencies recommend that organizations implement the following mitigations to improve their cybersecurity posture:

  • Install PLCs consistent with manufacturers’ guidelines and security best practices.
  • Remove PLCs from direct internet exposure via secure gateway and firewall; work with IT/OT team members and/or integrators to perform this action.
  • Query available logs for the provided indicators of compromise (IOCs) and check available logs for suspicious traffic on the ports associated with OT devices.
  • For Rockwell Automation devices place the physical mode switch on the controller into run position.

Organizations are urged to review the tactics, techniques, and procedures (TTPs) and IOCs in the advisory for indications of current or historical activity on their networks. If owners and operators discover an affected internet-accessible device in their environment, additional technical measures may be necessary to evaluate the risk of compromise.

For more information on Iranian malicious cyber activity, see CISA’s Iran Threat Overview and Advisories webpage and the FBI’s Iran Threat and Iran Cyber Threat Overview webpages.

Author

Sophie Donovan

Sophie Donovan, Manchester-born and classically elegant, once turned down a commission to chase a long-form piece on Salford’s textile heritage, filing instead from the mill where her grandmother worked. Advocates patient, context-rich features and brings a taste for quiet narrative detail and theatre aficionadoship.