Iranian APT Groups Exploit Internet-Exposed PLCs at Scale
Federal agencies warn that state-sponsored attackers have compromised thousands of industrial controllers from Siemens, Schneider Electric, and Rockwell Automation across U.S. critical infrastructure.

Federal Warning on Industrial Control System Attacks
In July 2026, a coalition of U.S. federal agencies—including the FBI, CISA, NSA, and U.S. Cyber Command—issued a joint advisory detailing an active campaign by Iranian state-sponsored threat actors targeting industrial control systems. The attackers have focused on internet-exposed programmable logic controllers (PLCs) and remote terminal units (RTUs) manufactured by Siemens, Schneider Electric, and Rockwell Automation, causing operational disruptions and financial damage across water, wastewater, energy, and government sectors.
The threat actors behind this campaign include CyberAv3ngers, linked to Iran's Islamic Revolutionary Guard Corps, the pro-Palestinian hacktivist group Handala, and elements associated with Iran's Ministry of Intelligence and Security. These groups have a documented history of targeting operational technology environments, particularly infrastructure aligned with U.S. and Israeli interests.
Why it matters
This campaign exposes a fundamental vulnerability in how critical infrastructure operators deploy industrial control systems. With over 5,200 Rockwell Automation controllers alone identified as internet-exposed—nearly 3,900 of them in the United States—the attack surface is substantial. The ability of adversaries to manipulate operational parameters, wipe firmware, and disrupt essential services like water treatment and energy distribution poses direct risks to public safety and national security. Organizations that assumed obscurity would protect their OT environments now face adversaries conducting mass scanning and exploitation at scale.
Attack Methods and Exploitation
The Iranian groups employ a multi-stage methodology beginning with scanning for exposed devices via cellular modems, satellite uplinks including Starlink, and misconfigured firewalls. Attackers exploit industrial protocols such as EtherNet/IP (port 44818), Modbus (port 502), and Siemens S7 (port 102), along with remote access services including VNC, FTP, HTTP, and Telnet.
Credential-based attacks dominate the initial access phase, with adversaries leveraging default or weak passwords to gain administrative control. Once inside, attackers download project files, manipulate human-machine interface displays, extract configuration data, and in severe cases, overwrite or wipe device firmware entirely. Command and control operations run through encrypted channels, notably Telegram, and attackers deploy lightweight SSH servers like Dropbear on compromised modems to maintain persistence.
Confirmed incidents include the compromise of at least 75 Unitronics PLCs in late 2023 and early 2024, resulting in water system disruptions. In March 2026, the Handala group claimed responsibility for wiping approximately 80,000 devices at medical device manufacturer Stryker. Security researchers at Censys identified the scope of exposure in April 2026, revealing thousands of vulnerable controllers deployed in remote or unmanned facilities with minimal network segmentation.
Immediate Mitigation Steps
Organizations must immediately audit their ICS environments for internet exposure. All PLCs and RTUs from the targeted vendors should be disconnected from the public internet or routed through secure, monitored gateways with multi-factor authentication enforced for all remote access. Remote access services including VNC, Telnet, and FTP must be disabled or strictly firewalled.
Firmware updates should be applied to all devices, with unsupported hardware replaced. For Rockwell Automation devices, placing the physical mode switch in run position prevents remote modification. Siemens devices should have programming protection enabled via TIA Portal. Continuous monitoring for unauthorized project file downloads, unexpected HMI changes, and anomalous remote access sessions is essential.
These details were first reported by Rescana in a comprehensive threat advisory, drawing on federal agency warnings and security research from Censys and other sources.
This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.
Want systems like this working for your business?
Book a Call