Iranian Hackers Are Going After PLCs Inside US Critical Infrastructure
- The Mess: Iranian-affiliated threat actors are actively targeting internet-exposed PLCs used across US critical infrastructure. The attacks have already caused operational disruption and financial losses.
This isn’t another warning about hackers stealing files.
The attackers are going after the machines that control physical processes.
A joint advisory from the FBI, CISA, NSA, EPA, Department of Energy and US Cyber Command says Iranian-affiliated APT actors have targeted programmable logic controllers across the Water and Wastewater, Energy and Government sectors.
The attackers have accessed exposed PLCs, interacted with project files and manipulated data shown to operators through HMI and SCADA systems.
In some cases, that activity caused operational disruption and financial loss.
- The Damage: Attackers don’t need to destroy a PLC to create a dangerous situation. Changing control logic or showing operators false information can affect the physical process while making the control screen look normal.
The advisory describes attackers targeting internet-facing Rockwell Automation/Allen-Bradley PLCs, including CompactLogix and Micro850 devices.
The July update also expanded the observed targeting and added new detection and mitigation guidance.
The bigger problem is exposure.
A PLC connected directly to the Internet is not just another server waiting for a patch.
It controls something.
Water.
Energy.
Industrial processes.
And when attackers can manipulate project files or the information displayed to operators, this stops being a normal IT incident.
It becomes an operational technology problem.
The advisory lists suspicious inbound activity involving OT-related ports including:
44818
2222
102
22
502
The agencies warn that targeting across these protocols may indicate interest in equipment from vendors beyond the initially observed Rockwell Automation/Allen-Bradley devices.
- The Fix: Remove direct Internet exposure from PLCs, restrict engineering access to authorized systems and compare deployed logic against trusted offline copies.
Organizations operating exposed PLCs should immediately review the IOCs and TTPs in the joint advisory.
Network access should be limited to trusted engineering workstations.
Remote access should be tightly controlled.
And operators should not assume that a normal-looking HMI means the underlying process is untouched.
Check the controller logic.
Check the project files.
Check what changed.
And preserve logs before cleaning up anything suspicious.
The US agencies also recommend reviewing manufacturer guidance and implementing vendor-specific OT security controls.
Bugstoday’s Opinion
This is where cybersecurity stops being abstract.
A compromised website is bad.
A compromised PLC can change what happens in the real world.
The most worrying part isn’t some exotic zero-day.
It’s that attackers are finding industrial controllers directly exposed to the Internet.
They don’t always need to break the lock.
Sometimes there isn’t one.
And when an attacker can change the logic while lying to the operator’s screen, the person watching the system may be the last one to know something is wrong.
Today’s Bugs. Tomorrow’s Breaches.
Technical Sources
CISA Joint Cybersecurity Advisory AA26-097A
FBI
NSA
EPA
US Department of Energy
US Cyber Command – Cyber National Mission Force




