THREAT SUMMARY
Category: Iranian-Affiliated Advanced Persistent Threat Activity
Affected Environment: Operational Technology and Industrial Control Systems
Primary Targets: Government Facilities, Municipalities, Water and Wastewater Systems, and Energy Operations
Affected Products: Internet-Exposed PLCs, including Rockwell Automation and Allen-Bradley, Schneider Electric, and Siemens Devices
Primary Risks: Unauthorized Access, Project-File Theft, Logic Modification, Alarm Suppression, Safety-System Interference, Operational Disruption, and Financial Loss
Attack Vectors: Publicly Exposed PLCs, Misconfigured Remote Access, Industrial Protocol Ports, Third-Party Hosted Infrastructure, and Internet-Connected Modems
Threat Status: Active and Ongoing
Federal Action: Immediate Review of Logs, Project Files, Controller Configurations, Network Exposure, and Published Indicators of Compromise
Federal cybersecurity agencies are urgently warning critical infrastructure operators across the United States that Iranian-affiliated cyber actors are actively targeting internet-connected industrial control equipment used to manage essential physical operations.
The campaign has affected programmable logic controllers across government facilities, local municipalities, water and wastewater systems, and the energy sector. Federal investigators confirmed that some affected organizations experienced operational disruption and financial loss after threat actors accessed industrial devices, extracted project files, altered control logic, and manipulated information displayed to system operators.
The Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency, National Security Agency, Environmental Protection Agency, Department of Energy, U.S. Cyber Command’s Cyber National Mission Force, and Department of the Treasury issued the joint warning.
The advisory was initially published on April 7, 2026, and substantially expanded on July 22. The update confirms observed targeting involving controllers manufactured by Rockwell Automation and Allen-Bradley, Schneider Electric, and Siemens. Federal authorities warned that other manufacturers’ internet-exposed controllers could also be targeted.
The expanded warning reveals that the actors are doing more than scanning industrial networks or attempting to access control panels. Investigators observed the theft of programmable logic controller project files, malicious changes to the logic governing industrial processes, deletion of legitimate instructions, manipulation of operational displays, and interference with safety functions designed to shut down equipment or warn operators when conditions become dangerous.
INDUSTRIAL SYSTEMS CONNECTED TO PHYSICAL OPERATIONS
Programmable logic controllers, commonly known as PLCs, are specialized industrial computers used to control machinery, pumps, valves, motors, sensors, alarms, and other equipment. These controllers are found throughout water-treatment facilities, electrical systems, manufacturing environments, municipal operations, energy installations, and other infrastructure.
Unlike an intrusion confined to an office network, unauthorized access to a PLC can affect a physical process. A malicious change could interfere with the way equipment starts, stops, responds to sensor readings, maintains pressure, controls flow, or enters a safe condition during an emergency.
PLCs often operate alongside human-machine interfaces and supervisory control and data acquisition systems. Human-machine interfaces provide operators with visual information about equipment and processes. SCADA systems allow organizations to monitor and control industrial operations across one or multiple locations.
Manipulating those displays can create a dangerous separation between what the equipment is doing and what an operator sees. A screen may display normal conditions while malicious logic changes how the physical system behaves. It may also show false data designed to confuse personnel responding to an operational problem.
The federal advisory states that the attackers altered data shown on HMI and SCADA displays and disabled critical shutdown and alarm logic. Those changes allowed affected systems to enter unsafe conditions without alerting operators to the developing abnormalities.
MALICIOUS PROJECT FILE DEPLOYED TO U.S. VICTIM
The July update provides new information about an intrusion affecting an unidentified organization in the United States.
According to the FBI, Iranian-affiliated advanced persistent threat actors used configuration software to download a malicious project file to a targeted PLC. The altered file retained the ladder logic needed for downstream functions but added new logic that overrode specific instructions responsible for maintaining safe operating parameters.
Ladder logic is a programming language commonly used to direct industrial controllers. It establishes the conditions under which equipment activates, stops, triggers an alarm, or performs another action.
The malicious file was structured to preserve parts of the industrial process while overriding selected safety instructions. This indicates that the intrusion was not limited to shutting down the controller or deleting its entire program. The actors were capable of modifying specific operational functions while allowing other portions of the system to continue running.
A project file contains the controller’s ladder logic and configuration settings. Rockwell Automation uses the .ACD file format for these files. Possession of a stolen project file can provide an attacker with detailed information about how a targeted controller is programmed and how the connected industrial process operates.
Federal investigators confirmed that the actors extracted project files from victim PLCs before modifying or deleting sections of the control logic. The affected logic included Add-On Instructions, which are reusable code modules within Rockwell Automation controller programs. Comparable reusable components are known as function blocks or user-defined function blocks in other industrial platforms.
Unauthorized changes to a reusable instruction can affect every portion of a controller program that relies on that module, making the review of these components a critical part of the investigation and recovery process.
ROCKWELL, SCHNEIDER ELECTRIC AND SIEMENS CONTROLLERS TARGETED
Federal agencies observed the attackers accessing internet-facing PLCs manufactured by several major industrial automation companies.
The specifically identified devices include:
- Rockwell Automation CompactLogix controllers
- Rockwell Automation Micro850 controllers
- Schneider Electric BMX P34 and Modicon M340 controllers
- Siemens S7-1200 series controllers
The advisory does not identify a newly discovered vulnerability affecting all of these products. Federal agencies described the activity as opportunistic targeting of internet-accessible devices that lacked sufficient network protections or secure configuration.
This distinction is important. The campaign is not presented as the exploitation of a single universal software flaw. The actors searched for industrial controllers exposed to the public internet and accessed devices that were insufficiently isolated or hardened.
Potentially exposed equipment extends beyond the named products. Any PLC placed directly on the public internet without adequate access controls, network segmentation, authentication, monitoring, and secure remote-access protections could face similar risks.
ATTACKERS USED LEGITIMATE INDUSTRIAL SOFTWARE
The Iranian-affiliated actors used leased third-party infrastructure and legitimate programming tools to communicate with targeted devices.
The identified software included:
- Rockwell Automation Studio 5000 Logix Designer
- Schneider Electric EcoStruxure Control Expert
- Siemens Totally Integrated Automation Portal
These applications are legitimate engineering tools used to configure, program, and maintain industrial controllers. Their use by threat actors can make the activity more difficult to distinguish from authorized engineering work if an organization lacks strict access controls, complete logging, and a reliable record of approved controller changes.
Federal agencies determined that the attackers used the configuration software from remotely hosted infrastructure to extract project files from PLCs and transfer them to systems under actor control.
In one reported incident, the actors used Dropbear Secure Shell software operating on victim modems to obtain remote access through port 22. The presence of modems within industrial environments introduces another potential path into operational networks, especially when remote-access equipment is connected to the internet without strong authentication or sufficient monitoring.
INDUSTRIAL PORTS UNDER ATTACK
Investigators observed malicious inbound traffic directed at ports commonly associated with industrial control systems and remote access.
The identified ports are:
- Port 44818
- Port 2222
- Port 102
- Port 502
- Port 22 on connected modems
Ports 44818 and 2222 are associated with EtherNet/IP communications used by industrial equipment. Port 102 is commonly associated with Siemens industrial communications. Port 502 is commonly used for Modbus communications. Port 22 is used for Secure Shell connections.
Traffic reaching one of these ports does not automatically prove an intrusion. Owners and operators must examine the source, destination, timing, purpose, authentication records, device configuration, and surrounding network activity before determining whether a connection was malicious.
Federal agencies advised defenders to pay particular attention to unexpected traffic originating from foreign hosting providers. Organizations should also investigate unauthorized attempts to change a controller’s operating mode, download a program, modify logic, or establish remote access.
CAMPAIGN ACTIVE SINCE AT LEAST MARCH 2026
Federal authorities identified the current disruptive activity through engagements with victim organizations and determined that the campaign has been operating since at least March 2026.
The actors targeted government services and facilities, including local municipalities, water and wastewater systems, and energy-sector organizations. PLCs within these sectors control a wide range of industrial automation processes, making the possible consequences dependent on the purpose and configuration of each affected device.
The advisory confirms disruption and financial loss among some victims but does not identify the organizations, locations, affected industrial processes, recovery costs, or complete number of compromised controllers.
It also does not claim that Iranian-affiliated actors have shut down the national electrical grid, disabled the entire American water system, or obtained control of all U.S. industrial infrastructure. The confirmed threat involves successful access to individual internet-exposed industrial devices across several critical sectors, including cases in which attackers altered operational logic and interfered with safety protections.
That documented activity is serious without overstating the known scope.
CONNECTION TO EARLIER CYBERAV3NGERS ATTACKS
The federal government previously documented similar activity involving CyberAv3ngers, also known as the Shahid Kaveh Group, which authorities identified as affiliated with the Islamic Revolutionary Guard Corps Cyber Electronic Command.
Beginning in November 2023, CyberAv3ngers targeted Unitronics PLCs and human-machine interfaces used across multiple critical infrastructure sectors, including water and wastewater systems.
At least 75 devices were compromised during that earlier campaign. The attackers developed and deployed malicious ladder logic that replaced the legitimate programs operating on targeted controllers. Federal agencies reported that the malicious code from that campaign continues to be observed.
The current advisory does not state that every intrusion described in the 2026 campaign was conducted by CyberAv3ngers. It identifies the activity as the work of an Iranian-affiliated advanced persistent threat group and cites the earlier IRGC-linked campaign as a documented example of similar targeting.
The authoring agencies assess that the current actors are conducting the activity to create disruptive effects inside the United States. The advisory also states that Iranian-affiliated targeting of American critical infrastructure has escalated in connection with hostilities involving Iran, the United States, and Israel.
FEDERAL INDICATORS OF COMPROMISE
The FBI identified a series of internet addresses used by the threat actors to communicate with PLCs in the United States. The July 22 update added addresses connected to activity observed from September 2025 through July 2026.
The newly released indicators are:
- 185.82.73[.]175
- 141.11.164[.]153
- 175.110.121[.]42
- 175.110.121[.]39
- 175.110.121[.]41
- 175.110.121[.]107
- 192.142.54[.]79
- 84.200.205[.]165
- 185.225.17[.]225
- 79.133.46[.]209
- 88.80.150[.]199
- 88.80.150[.]200
- 88.80.150[.]202
Previously released indicators include:
- 185.82.73[.]162
- 185.82.73[.]164
- 185.82.73[.]165
- 185.82.73[.]167
- 185.82.73[.]168
- 185.82.73[.]170
- 185.82.73[.]171
- 135.136.1[.]133
The FBI stated that the addresses were associated with the actors during specific periods. Organizations are advised to investigate and validate any identified connections before blocking an address or treating it as definitive proof of compromise.
An address may change ownership, host multiple customers, or serve a legitimate purpose outside the period covered by the advisory. Historical traffic involving one of the indicators requires investigation within the complete context of the affected network.
MITRE ATT&CK TECHNIQUES
The advisory maps the observed conduct to several MITRE ATT&CK techniques:
- T0883 — Internet Accessible Device
- T0885 — Commonly Used Port
- T1219 — Remote Access Tools
- T1041 — Exfiltration Over Command-and-Control Channel
- T1565 — Data Manipulation
The activity began with access to publicly exposed PLCs. The actors communicated through ports associated with industrial protocols, used remote-access capabilities, transferred project files from victim environments, and manipulated the data and logic controlling industrial operations.
This sequence demonstrates why organizations cannot rely exclusively on endpoint protections designed for office computers. Operational technology requires visibility into industrial protocols, controller programming activity, engineering workstations, remote-access equipment, cellular modems, and changes occurring directly within PLC project files.
IMMEDIATE DEFENSIVE ACTIONS
Federal agencies urged owners and operators to remove PLCs from direct public internet exposure. Remote connectivity should be placed behind a controlled gateway, firewall, virtual private network, jump host, or another monitored security layer.
Organizations should work with their information technology personnel, operational technology specialists, system integrators, and equipment manufacturers before making changes to active industrial systems. An improperly planned defensive action can interrupt a physical process or create new operational risks.
Federal recommendations include:
- Remove direct inbound internet exposure from PLCs.
- Restrict communications to authorized devices and addresses.
- Review firewall rules and access-control lists.
- Secure cellular modems with strong authentication.
- Enable and preserve modem connection logs.
- Inspect traffic involving ports 44818, 2222, 102, 502, and 22.
- Review PLC project files for unauthorized changes.
- Compare active programs with verified, known-good copies.
- Examine reusable instructions and input-output configurations.
- Change default passwords to complex, unique credentials.
- Implement multifactor authentication for external access to operational networks.
- Maintain tested offline backups of PLC logic and configurations.
- Patch industrial devices through established maintenance procedures.
- Disable unnecessary services and remote-access methods.
- Review connected HMIs, modems, and engineering workstations for signs of lateral movement.
- Notify service providers responsible for remote monitoring or maintenance about the active threat.
Organizations restoring a controller from backup must first confirm that the backup does not contain malicious logic. Restoring an altered project file can return the attacker’s changes to the device after other portions of the incident have been contained.
If investigators determine that the actors accessed connected modems, HMIs, workstations, or other equipment, the advisory recommends reviewing those systems for additional modifications and reimaging them when necessary.
CONTROLLER MODE PROTECTIONS
For controllers equipped with a physical operating-mode switch, federal agencies recommend placing the switch in the run position after validating the project file.
The run position can prevent remote programming changes. A controller should remain in program or remote mode only when authorized personnel are performing approved updates or downloading software. It should be returned to run mode when that work is complete.
Operators must validate the active project file before changing the mode. Moving a compromised controller into run mode without inspecting its program could lock the malicious file into operation.
For devices that support software-based key switching, the agencies recommend enabling programming protections within the controller’s configuration software. Siemens operators can use protections available through the TIA Portal to restrict remote modifications.
RESPONSIBILITY ALSO EXTENDS TO MANUFACTURERS
The joint advisory places part of the responsibility for industrial cybersecurity on device manufacturers.
Federal agencies urged manufacturers to prevent administrative interfaces from being exposed to the internet by default, provide essential security protections without additional fees, and support multifactor authentication, including phishing-resistant methods.
Industrial equipment should be secure when deployed under its standard configuration. Owners and operators should not be forced to purchase additional products or perform extensive configuration changes to obtain basic security functions needed to protect essential systems.
Secure design cannot eliminate every threat, but it can reduce the number of industrial devices that become exposed because of weak defaults, unnecessary services, limited authentication, or unclear deployment requirements.
INCIDENT REPORTING
Organizations that identify suspicious activity connected to this campaign are encouraged to contact the FBI, CISA, and the appropriate equipment manufacturer.
Reports to the FBI may be filed through the Internet Crime Complaint Center or a local FBI field office. CISA’s 24-hour Operations Center can be reached at contact@cisa.dhs.gov or 1-844-SAY-CISA.
Reports should include the date, time, and location of the activity; the type of activity observed; the number of people or systems affected; the equipment involved; the reporting organization’s name; and a designated point of contact.
Energy-sector entities subject to Department of Energy reporting requirements should follow their established procedures. Operators can also contact the security response teams maintained by Rockwell Automation, Schneider Electric, and Siemens.
TRJ VERDICT
The July 22 federal update now provides the detailed confirmation that was not publicly available when TRJ examined this threat on July 19. At that time, the available evidence confirmed exploitation and disruption involving operational technology but did not establish the full scope of the Iranian-affiliated activity. The expanded advisory now documents successful operational intrusions affecting industrial control systems across several sectors of American critical infrastructure.
Iranian-affiliated cyber actors accessed internet-exposed PLCs, extracted controller project files, altered industrial logic, manipulated information displayed to operators, and disabled functions responsible for alarms and emergency shutdowns. Some affected organizations experienced operational disruption and financial loss.
The new findings do not establish that Iran controls the national electrical grid or America’s entire water infrastructure. They confirm that individual industrial systems have been compromised and that the actors possess the access and technical capabilities needed to interfere with physical operations at affected facilities.
The immediate danger comes from controllers that remain directly accessible from the public internet, weakly protected remote connections, insufficient monitoring, unverified project files, and industrial systems operating without strong separation between external networks and physical processes.
Critical infrastructure operators must determine which devices are exposed, remove unnecessary internet access, inspect active control logic, validate offline backups, secure remote-maintenance pathways, and report confirmed activity. Federal investigators have now documented the successful manipulation of systems responsible for controlling real-world infrastructure, transforming a broadly recognized threat into a confirmed record of operational interference.
Joint Cybersecurity Advisory AA26-097A, issued by the Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency, National Security Agency, Environmental Protection Agency, Department of Energy, U.S. Cyber Command–Cyber National Mission Force, and Department of the Treasury. Originally published April 7, 2026; updated July 22, 2026. (Free Download)
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



