A joint U.S. government advisory said Iranian-affiliated cyber actors are actively exploiting internet-facing operational technology devices across multiple U.S. critical infrastructure sectors, with a particular focus on Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs). The activity has affected organizations in Government Services and Facilities, Water and Wastewater Systems, and Energy, where attackers maliciously interacted with project files and manipulated data displayed on HMI and SCADA systems, causing operational disruption and financial losses for some victims.
The campaign has been observed since at least March 2026 and shows similarities to prior CyberAv3ngers activity linked to the IRGC Cyber Electronic Command. According to the advisory, the actors used overseas IP infrastructure, Rockwell Studio 5000 Logix Designer, OT-related ports including 44818, 2222, 102, 22, and 502, and Dropbear SSH for remote access. U.S. authorities urged operators to remove PLCs from direct internet exposure, harden remote access, enable logging, place controllers in run mode where appropriate, and review published indicators of compromise and ATT&CK-mapped TTPs alongside Rockwell Automation security guidance.

See the actors and campaigns active against you right now.
5 events from the most recent confirmed update back to the earliest known activity.
U.S. federal agencies expanded their earlier warning on Iranian regime-affiliated attacks against internet-facing OT environments, broadening the scope beyond Rockwell Automation and Allen-Bradley PLCs to include Schneider Electric, Siemens, and possibly other PLC manufacturers. The revised advisory said the activity caused operational disruption and financial loss and warned that pressure from Iran-affiliated attackers is expected to continue.
On April 7, 2026, CISA and partner agencies warned that Iranian-affiliated actors were actively exploiting internet-facing PLCs, disrupting operations by manipulating project files and altering data shown on HMI and SCADA displays. The advisory also shared technical details, observed ports and tooling, indicators of compromise, and mitigation guidance for defenders.
Rockwell Automation published security advisory SD1771 addressing the PLC-focused threat activity referenced in later government reporting. The advisory was released on March 20, 2026.
Since at least March 2026, Iranian-affiliated cyber actors have targeted internet-exposed operational technology devices across multiple U.S. critical infrastructure sectors, especially Rockwell Automation/Allen-Bradley PLCs. The activity affected sectors including Government Services and Facilities, Water and Wastewater Systems, and Energy.
In 2026, suspected Iran-linked intrusions affected 30 to 36 Minnesota water utilities, and several utilities shifted to manual operations. The report says no confirmed water contamination occurred and formal U.S. government attribution remains pending.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 93 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
35 references tracked. Mallory keeps watching after this page renders.
lares.com
Open sourcewaterisac.org
Open sourcetherecord.media
Open sourceblog.polyswarm.io
Open sourcerockwellautomation.com
Open sourceinfosec.pub
Open sourceic3.gov
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.