Iranian APT Actors Exploit Internet-Exposed PLCs in U.S. Critical Infrastructure
Iranian-affiliated threat actors are actively exploiting internet-exposed programmable logic controllers (PLCs) across U.S. critical infrastructure sectors, including government facilities, water systems, and energy plants. A joint advisory from CISA, the FBI, NSA, DOE, EPA, Treasury, and U.S. Cyber Command warns that attackers are manipulating industrial control systems in real time, causing operational disruptions and financial losses.
What Happened: Iranian APT Actors Exploit PLCs in U.S. Critical Infrastructure
Iranian-linked advanced persistent threat (APT) actors are targeting operational technology (OT) environments by exploiting misconfigured, internet-facing PLCs from major industrial vendors. The campaign impacts multiple U.S. sectors, including government facilities, water and wastewater systems, and energy infrastructure.
Investigations reveal that threat actors are interacting directly with PLC project files and altering data displayed on human-machine interfaces (HMI) and supervisory control and data acquisition (SCADA) systems. In several confirmed cases, these manipulations resulted in operational disruption and financial losses.
Authorities attribute the activity to Iranian-affiliated actors, potentially linked to the IRGC Cyber Electronic Command. This is consistent with previously tracked groups such as CyberAv3ngers (also known as APT Iran, UNC5691, and Shahid Kaveh Group). Similar tactics were observed in earlier campaigns, including the 2023 compromise of Unitronics PLCs, where attackers deployed malicious ladder logic to override legitimate control processes.
Technical Details of the PLC Exploitation Campaign
The attackers are exploiting exposed PLC services using vendor-specific programming software, including Rockwell Studio 5000 Logix Designer, Schneider EcoStruxure, and Siemens TIA Portal. They are accessing internet-facing PLCs and modifying control logic to manipulate industrial processes.
CISA updated advisory AA26-097A on July 22, 2026, to expand the scope of affected vendors and provide new detection guidance. The update includes specific guidance around malicious modifications in reusable code modules within Rockwell PLC environments.
Attack Vectors and Methods
- Exploitation of internet-exposed PLC programming ports and services
- Direct modification of PLC project files and control logic
- Manipulation of HMI and SCADA display data to hide unauthorized changes
- Use of vendor-specific programming tools to maintain persistence
- Deployment of malicious ladder logic to override legitimate processes
Affected Vendors and Systems
- Rockwell Automation — Studio 5000 Logix Designer, ControlLogix, CompactLogix PLCs
- Schneider Electric — EcoStruxure platform, Modicon PLCs
- Siemens — TIA Portal, S7 series PLCs
Business and Operational Impact
The exploitation of PLCs in critical infrastructure carries severe consequences for public safety, national security, and economic stability. Operational disruptions can affect water treatment, energy distribution, and government operations.
- Operational Disruption: Manipulated control logic can alter industrial processes, causing equipment failure or service outages
- Financial Losses: Confirmed cases have resulted in direct financial impact to affected organizations
- Public Safety Risk: Water and wastewater system disruptions pose health and safety risks to communities
- National Security: Energy infrastructure targeting threatens grid stability and national security
- Trust Erosion: Successful attacks undermine confidence in critical infrastructure resilience
Mitigation and Recommendations
Organizations operating industrial control systems must take immediate action to reduce exposure and detect unauthorized modifications. The joint advisory provides specific technical guidance for each affected vendor.
Immediate Actions for Defenders
- Remove PLC internet exposure: Disconnect PLCs from the public internet immediately. Place all OT devices behind properly configured firewalls with strict access controls
- Audit control logic: Review PLC project files for unauthorized modifications, especially in reusable code modules and ladder logic segments
- Monitor HMI/SCADA displays: Implement integrity checks to detect discrepancies between displayed data and actual PLC states
- Restrict programming tool access: Limit use of vendor-specific programming software to authorized personnel only
- Enable logging and alerting: Configure PLC and network logs to capture programming access, logic changes, and anomalous connections
- Segment OT networks: Isolate industrial control networks from corporate IT networks to limit lateral movement
- Apply vendor patches: Follow vendor-specific guidance for securing PLC programming interfaces and firmware
Detection Guidance
CISA’s updated advisory includes detection signatures for identifying malicious modifications in Rockwell PLC environments. Security teams should:
- Monitor for unauthorized PLC programming sessions
- Compare current PLC logic against known-good baselines
- Alert on unexpected file transfers to PLC devices
- Review network traffic for anomalous connections to OT devices
Bottom line: Internet-exposed PLCs are being actively exploited by Iranian-linked threat actors right now. Organizations must remove OT devices from the public internet, audit control logic for unauthorized changes, and implement strict network segmentation to protect critical infrastructure.
Incident Summary
| Campaign: | Iranian APT PLC Exploitation Campaign (AA26-097A) |
| Threat Actor: | Iranian-affiliated APT (CyberAv3ngers / IRGC Cyber Electronic Command) |
| Affected Systems: | Rockwell Automation, Schneider Electric, Siemens PLCs; HMI/SCADA systems |
| Target Sectors: | Government facilities, water/wastewater, energy infrastructure |
| Disclosure Date: | Advisory updated July 22, 2026 |
| Patch Status: | Vendor-specific mitigations available; network segmentation critical |
| Severity: | Critical — active exploitation confirmed |
References
- CISA, FBI, NSA, DOE, EPA, Treasury, and U.S. Cyber Command, “Joint Cybersecurity Advisory AA26-097A: Iranian Affiliated APT Actors Exploit PLCs,” July 22, 2026, https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a, accessed August 3, 2026.
- GBHackers, “Iranian Hackers Exploit Rockwell, Schneider and Siemens PLCs Across U.S. Critical Infrastructure,” July 27, 2026, https://gbhackers.com/iranian-hackers-exploit-rockwell/, accessed August 3, 2026.
- Cybersecurity News, “CISA Warns of Coordinated PLC Attacks on U.S. Water Utilities: 30+ Systems Disrupted,” July 2026, https://cybersecuritynews.com/, accessed August 3, 2026.