The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and U.S. government partners have issued a joint cybersecurity advisory about Iranian hackers stepping up attacks on critical infrastructure by targeting programmable logic controllers.
The attackers target water, energy, and other city, municipal, and local government utilities. The FBI, CISA, and partner agencies first issued the advisory “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure” in April 2026.
The July 22, 2026, update warns about Iranian hackers disrupting operations across numerous critical infrastructure sectors through malicious file interactions and manipulation of data on human machine interface (HMI) and SCADA displays, resulting in financial losses. In one attack, Iranian hackers turned off critical alarms to make PLCs fail without notifying operators.
Iranian hackers target more PLCs to compromise critical infrastructure
The authoring agencies stated that Iranian hackers were targeting more devices to compromise critical infrastructure. According to the updated joint cybersecurity advisory, Iranian hackers have expanded the list of targeted devices.
Previously, Iranian hackers had targeted Israel-made Unitronics programmable logic controllers to target critical infrastructure, especially water utilities.
Targeted devices now include Rockwell Automation/Allen-Bradley, Schneider Electric BMX P34/Modicon M340 PLCs, Siemens S7-1200 series PLCs, and other manufacturers. The updated advisory also warns that all internet-exposed industrial control systems may be affected.
“Potentially all internet-exposed PLCs, including Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and other branded/manufactured PLCs,” it stated.
EPA also assessed that hundreds of critical infrastructure systems contain high-severity security vulnerabilities. In 2021, federal agencies had issued an advisory regarding a critical (CVSS v3 9.8) authentication bypass vulnerability, CVE-2021-22681, in Rockwell Automation Studio 5000 Logix Designer and RSLogix 5000.
In November 2023, Iranian hackers CyberAv3ngers compromised an Israeli-made Unitronics PLC at the Pennsylvania Municipal Water Authority of Aliquippa water utility. They displayed a message declaring that any Israeli-made PLCs were legitimate targets.
In June, Iranian hackers Handala also targeted a California water service using a customer’s compromised credentials.
“The biggest issue here is that most of these organizations simply can’t pause operations while an incident is investigated,” said Ross Filipek, CISO at Corsica Technologies. “Water utilities have to keep providing clean water. Energy providers have to maintain power and fuel availability. Local governments still need to support emergency services and public operations. Even a short disruption can force employees into slower manual processes, delay essential services, and create public safety concerns. Recovery costs can also hit smaller operators especially hard since many are limited by small security staffs, older equipment, or outside vendors having control over parts of their environment.”
FBI and CISA issue guidance on protecting critical infrastructure
The agencies published a list of indicators of compromise to help network defenders protect critical infrastructure from Iranian hackers.
The agencies listed indicators of compromise to help network defenders protect critical infrastructure. They include limiting who can access internet-exposed devices. They should also monitor project files for any suspicious activity. In one attack, hackers exploited Dropbear Secure Shell software to compromise an exposed system remotely. Consequently, the agencies advised critical infrastructure operators to check ports associated with operational technology for suspicious traffic.
“Protecting these systems starts with knowing every controller in use and who can access it,” addedFilipek. “IT teams, plant operators, integrators, and security partners need a shared response plan rather than separate assumptions about who owns the problem. Trusted backups of PLC logic are critical, as are tested recovery procedures and experienced responders who can contain an intrusion quickly.”
System administrators and network defenders should also review manufacturer instructions to protect programmable logic controllers. CISA is also working with critical infrastructure organizations to secure their OT networks.
Other recommendations include enabling multi-factor authentication (MFA), changing default passwords, using virtual private networks (VPNs), proxies, firewalls, or gateways to connect remotely to internet-exposed systems. Removing operational technology devices from internet access should also prevent Iranian hackers from compromising critical infrastructure.
Additionally, turning on the physical mode switch in Rockwell Automation devices should prevent hackers from compromising logic controllers.

