← Back
Hackers target infrastructure

Iranian Hackers Target More PLCs in Critical Infrastructure

U.S. agencies issued a new advisory on July 22, 2026, warning that Iranian hackers are expanding their list of targeted programmable logic controllers (PLCs).
By
Cisco office interior features suspended blue bird sculptures and large windows.
Foto: Symbolbild | hdnux.com · Symbolbild (Bildsuche: CISO headquarters building) - nicht das Originalfoto der Quelle.
The essentials
  • The FBI and CISA released an updated cybersecurity advisory on July 22, 2026, about increased threats to critical infrastructure.
  • Iranian hackers have expanded their targeting to include Rockwell Automation, Schneider Electric, and Siemens PLCs.
  • CyberAv3ngers and Handala groups have compromised water utilities in Pennsylvania and California.

government partners have issued a joint cybersecurity advisory highlighting a significant increase in cyberattacks by Iranian hackers targeting critical infrastructure. The advisory underscores the expanding threat, especially to water, energy, and local government utilities. These attacks specifically focus on manipulating programmable logic controllers, known as PLCs. These devices play a crucial role in managing operations within infrastructure systems.

A notable example of this threat occurred on November 23, 2023, when Iranian hackers from the group CyberAv3ngers breached a Unitronics PLC at the Pennsylvania Municipal Water Authority of Aliquippa. Once inside the system, the hackers displayed a message explicitly stating that any Israeli-made PLCs are legitimate targets for further attacks. In another case in June 2026, the hacker group Handala infiltrated a California water service by exploiting stolen customer credentials. These incidents demonstrate that Iranian hackers are employing a range of tactics to gain unauthorized access to critical systems.

Expanded Target Scope

The updated advisory, originally issued in April 2026 and later revised on July 22, 2026, states that Iranian hackers are now targeting a broader range of PLC devices. Initially, their focus was primarily on Israel-made Unitronics PLCs. However, the hackers have expanded their scope to include other brands and models. This indicates a growing and more sophisticated threat as the hackers diversify their attack strategies.

The agencies have issued a warning that all internet-exposed industrial control systems are at risk of being compromised. One notable example is the critical authentication bypass vulnerability discovered in Rockwell Automation Studio 5000 Logix Designer and RSLogix 5000 in 2021. This high score underscores the urgent need for organizations to address and resolve such security issues promptly.

Industry Challenges and Responses

Ross Filipek, Chief Information Security Officer at Corsica Technologies, has outlined the challenges these attacks pose for organizations in critical sectors. He noted that most organizations, particularly those in essential industries, cannot afford to halt operations during a cyberattack. For example, water utilities must continue to supply clean water, energy providers must maintain power availability, and local governments need to support emergency services and public operations. Recovery costs can be especially challenging for smaller operators due to limited staff, outdated equipment, and the reliance on external vendors.

To combat this threat, the FBI and CISA have provided a list of indicators of compromise that network defenders can use to detect and respond to potential attacks. The guidelines recommend limiting internet access to devices to prevent unauthorized entry and monitoring project files for any suspicious activity. Using virtual private networks (VPNs) is another recommended step, as these tools help prevent unauthorized access to systems. These proactive measures can significantly reduce the likelihood of successful cyber intrusions.

The advisory also emphasizes the importance of system administrators enabling multi-factor authentication (MFA) and changing default passwords. Reviewing manufacturer instructions is another critical step, as this ensures that devices are configured securely. For Rockwell Automation devices, using the physical mode switch can add an extra layer of protection. These measures collectively help mitigate the risk posed by Iranian hackers.

CISA is actively collaborating with critical infrastructure organizations to enhance the security of their operational technology (OT) networks. The agencies strongly recommend removing OT devices from internet access, a key step in preventing Iranian hackers from exploiting potential vulnerabilities. By following these recommendations, organizations can better protect their systems and reduce the chances of a successful cyberattack. Strengthening security practices across all levels of infrastructure management is essential in countering the evolving cyber threats from Iranian cyber actors.

“The biggest issue here is that most of these organizations simply can’t pause operations while an incident is investigated.”

Frequently asked questions

What are the latest Iranian cyberattack targets?

Iranian hackers have expanded their list of targeted programmable logic controllers to include Rockwell Automation, Schneider Electric, and Siemens PLCs.

What vulnerabilities are being exploited?

The agencies warn of vulnerabilities in internet-exposed industrial control systems, including a critical vulnerability in Rockwell Automation products in 2021.

What are recommended actions for protection?

The FBI and CISA recommend limiting internet access to devices, enabling multi-factor authentication, and reviewing manufacturer instructions for PLC security.

Based on reporting by CPO Magazine, compiled by the Tradingbird newsroom. Published 04 Aug 2026, 00:37.
Topics: Cyber · Diplo · Politics

Related

Takaichi's Hiroshima speech leaves nuclear policy open · Geopolitics ·

China retaliates with 6 US entities banned · Geopolitics ·

Sudan's war leaves 8M children out of school, UN warns · Geopolitics ·

NRC commissioners reshaped in 2025 amid nuclear rulemaking surge · Geopolitics ·

Riyadh seeks Iraq talks after deadly strikes · Geopolitics ·

Read this in: English · Arabiy · Deutsch · Espanol · Italiano · Portugues · Russkij · Turkce