Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
April 6, 2026 · CISA Cybersecurity Advisories · Severity: CRITICAL
Advisory at a Glance Title Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure Original Publication April 7, 2026 Last Update July 22, 2026 Executive Summary The authoring agencies urgently warn U.S. organizations of ongoing Iranian-affiliated cyber targeting of internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs). These actions disrupted PLCs across several U.S. critical infrastructure sectors through malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss. Last Update Description This update adds new guidance on detecting malicious changes in reusable code modules exploited within Rockwell Automation PLC programs. It also expands scope to include observed targeting of Schneider Electric, Siemens, and potentially other branded/manufactured PLCs, emphasizing the importance of restricting direct internet access and providing best practices for secure deployment. Affected Products Potentially all internet exposed PLCs, including Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and other branded/manufactured PLCs. Key Actions Install PLCs consistent with manufacturers' guidelines and security best practices. Remove PLCs from direct internet exposure via secure gateway and firewall; work with IT/OT team members and/or integrators to perform this action. Query available logs for the provided indicators of compromise (IOCs) and check available logs for suspicious traffic on the ports associated with OT devices, including 44818, 2222, 102, and 502, especially traffic originating from foreign hosting providers. For Rockwell Automation devices, place the physical mode switch on the controller into run position. If you suspect your organization was targeted, including against...
Key Takeaways
- CISA warns of Iranian-affiliated cyber actors exploiting programmable logic controllers across US critical infrastructure.
- Affected organizations should isolate PLCs from the internet and implement network segmentation for OT environments.
- Organizations should monitor for unusual PLC behavior and apply CISA's recommended detection and mitigation measures.