HeadlinesBriefing favicon HeadlinesBriefing.com

Iran‑backed hackers target US industrial controllers

Ars Technica •
×

The FBI, CISA, NSA, EPA, DOE and US Cyber Command issued an urgent advisory Tuesday warning that an Iran‑backed advanced persistent threat group is actively targeting programmable logic controllers across U.S. critical infrastructure. These tiny devices—often the size of a toaster—bridge automation software and physical machinery in factories, water‑treatment plants and oil refineries. Disruption could halt essential services.

Since March 2026 the agencies have traced incidents to PLCs made by Rockwell Automation’s Allen‑Bradley line. A scan by security firm Censys flagged 5,219 Internet‑exposed units, with roughly 75 % residing in the United States, often in remote installations. Attackers appear to use a single multi‑home Windows workstation running the Rockwell toolchain to infiltrate and manipulate the controllers.

Victims report operational downtime and financial losses, underscoring how a compromised PLC can cripple processes from wastewater treatment to power generation. The coordinated warning from six federal bodies reflects growing concern that nation‑state actors can weaponize ordinary industrial hardware. Utilities and manufacturers must now audit exposed controllers and segment control networks to prevent further sabotage.

The advisory also advises organizations to disable unnecessary internet access on PLCs and to apply firmware updates supplied by vendors promptly. Failure to isolate these devices could leave critical services vulnerable to future geopolitical cyber campaigns, reinforcing the need for tighter segmentation in industrial control environments.