CISA, FBI, EPA, and US Government Partners Update Warning of Iran-Affiliated Threat Actors Targeting PLCs in Critical Infrastructure

Author photo: Chantal Polsonetti
ByChantal Polsonetti
Category:
Industry Trends

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Environmental Protection Agency (EPA), and other US government partners published an update to a joint Cybersecurity Advisory originally published in April 2026: Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers (PLCs) Across U.S. Critical Infrastructure. The advisory warns U.S. organizations of ongoing Iranian-affiliated cyber activity targeting internet-connected operational technology (OT) devices, provides indicators of compromise and detection guidance, and recommends mitigations to protect against this activity and strengthen resilience.

The update provides new guidance to detect malicious changes in reusable code modules used within Rockwell Automation PLC programs and adds more recommended mitigations. It also expands the manufacturer scope to include observed targeting of Schneider Electric, Siemens, and possibly other PLC manufacturers. The targeting of additional manufacturers emphasizes the importance of OT owners and operators restricting direct internet access and ensuring secure PLC deployment.

The Iranian-affiliated activity outlined in this advisory has disrupted PLCs across several US critical infrastructure sectors by attempting to download malicious project files and manipulate data on human-machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss for affected organizations. The group of Iranian-affiliated actors targeted devices across multiple US critical infrastructure sectors, including water and wastewater systems, energy, government services and facilities, and local municipalities.

Recommended mitigations are based on the activity described in the advisory and are intended to help organizations reduce the risk of compromise. The updated mitigations include:

  • Review PLC manufacturers’ previously issued guidance to ensure the security of OT deployments.

  • Strictly control network access to PLC devices.

  • Validate project files running on PLCs for unauthorized changes.

  • Ensure service providers are informed of active threats targeting internet-connected PLC devices.

For more information on nation-state cybersecurity advisories, visit Nation-State Cyber Threats.

Learn more about industrial cybersecurity challenges and solutions.

Engage with ARC Advisory Group

Representative End User Clients
Representative Automation Clients
Representative Software Clients