Skip to Content
Add Network with Us — Join Membership


FBI, NSA, CISA Warn of Iranian Cyber Threat Targeting U.S. Critical Infrastructure

July 25, 2026 by
FBI, NSA, CISA Warn of Iranian Cyber Threat Targeting U.S. Critical Infrastructure
Administrator

Joint Advisory Says State-Backed Hackers Are Targeting Industrial Control Systems in Energy and Water Sectors

The Federal Bureau of Investigation (FBI), National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and the U.S. Department of Energy have issued a joint cybersecurity advisory warning that Iranian state-backed cyber actors are actively targeting U.S. critical infrastructure, particularly industrial control systems used in the energy and water sectors.

According to the advisory, internet-exposed Industrial Control Systems (ICS), including Programmable Logic Controllers (PLCs), are at heightened risk of cyberattacks that could disrupt essential services such as electricity generation and water distribution.

The advisory urges critical infrastructure operators to strengthen cybersecurity measures immediately to reduce operational risks.

Industrial Control Systems Under Threat

According to the joint advisory, threat actors are focusing on Programmable Logic Controllers (PLCs)—specialized computers that control industrial equipment such as:

  • Pumps
  • Valves
  • Switches
  • Industrial machinery
  • Automated process controls

The agencies state that attackers are attempting to manipulate PLC programming logic and alter display information, potentially placing industrial systems into unsafe operating conditions while making the changes difficult for operators to detect.

HMI and SCADA Systems Also Targeted

The advisory notes that attackers have also tampered with data displayed on:

  • Human Machine Interface (HMI) systems
  • Supervisory Control and Data Acquisition (SCADA) systems

According to the agencies, such actions have disrupted industrial operations and caused financial losses for affected organisations.

Officials warn that attacks on operational technology (OT) environments can extend beyond information systems and directly affect essential public services.

Multiple PLC Vendors Potentially Affected

Investigators observed attempts targeting PLCs manufactured by:

  • Rockwell Automation
  • Schneider Electric
  • Siemens

The advisory cautions, however, that any PLC directly connected to the public internet may be vulnerable, regardless of manufacturer.

Agencies Recommend Immediate Security Measures

The advisory urges operators of critical infrastructure to:

  • Disconnect industrial control systems from direct internet access where possible.
  • Deploy secure gateways and firewalls.
  • Enable multi-factor authentication (MFA).
  • Regularly review system logs.
  • Continuously monitor network activity.
  • Conduct immediate cybersecurity assessments.

The agencies also recommend monitoring unusual activity involving common operational technology ports, including:

  • TCP 44818
  • TCP 2222
  • TCP 102
  • TCP 502

Report Suspicious Activity Promptly

The advisory recommends that organisations immediately contact both the equipment manufacturer and the appropriate federal authorities if they detect:

  • Unauthorised PLC modifications
  • Suspicious programming changes
  • Indicators of cyber intrusion

For certain Rockwell Automation controllers, operators are advised to keep the physical mode switch in the secure Run position to reduce the risk of unauthorised programming changes.

Experts Stress IT–OT Network Segmentation

According to a researcher at Algoritha Security, attacks on industrial control systems are particularly dangerous because they can directly affect physical infrastructure rather than simply compromise data.

The researcher recommends:

  • Segregating IT and operational technology (OT) networks.
  • Applying security patches promptly.
  • Minimising internet exposure.
  • Maintaining continuous monitoring and incident detection capabilities.

Cybersecurity Agencies Urge Vigilance

The FBI, NSA, CISA, and the U.S. Department of Energy have called on operators of critical infrastructure to assess their industrial environments, address identified vulnerabilities, and report suspicious cyber activity promptly to help prevent large-scale operational disruptions.

in News
Share this post
Archive