The United States’ leading cybersecurity and intelligence agencies—the Federal Bureau of Investigation (FBI), National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA) and the U.S. Department of Energy—have issued a joint cybersecurity advisory warning that Iranian state-backed hackers are actively targeting America’s critical infrastructure. According to the advisory, industrial control systems (ICS) used in the water supply and energy sectors are among the primary targets, and virtually all internet-exposed industrial control devices could be vulnerable to cyberattacks.
The advisory states that the attackers are specifically targeting Programmable Logic Controllers (PLCs), which are specialized computers used to control industrial machinery, valves, pumps, switches and other critical equipment. Investigators say the hackers are manipulating display data and programming logic to push control systems into unsafe operating conditions while preventing operators from immediately detecting the changes.
According to the warning, the attackers have also tampered with data displayed on Human Machine Interface (HMI) and Supervisory Control and Data Acquisition (SCADA) systems. These actions have disrupted industrial operations and caused financial losses for affected organizations. The agencies emphasized that such attacks extend beyond digital networks and have the potential to impact essential services, including electricity generation, water supply and other critical infrastructure.
The updated advisory further notes that the threat actors are exploiting reusable code modules to alter industrial control systems. Investigators have observed attempts to target PLC devices manufactured by Rockwell Automation, Schneider Electric, Siemens, and potentially other vendors. However, the agencies cautioned that any PLC directly connected to the public internet could be at risk, regardless of its manufacturer.
The U.S. agencies have urged all critical infrastructure operators to conduct immediate security assessments, disconnect industrial control systems from direct internet access, and deploy secure gateways and firewalls. They also recommended enforcing multi-factor authentication, reviewing system logs regularly and closely monitoring suspicious network activity. Special attention has been advised for unusual traffic involving operational technology (OT) ports 44818, 2222, 102 and 502, which are commonly associated with industrial control devices.
The advisory also recommends that organizations immediately contact both the equipment manufacturer and the relevant federal agencies if they detect suspicious modifications to PLCs or suspect a cyber intrusion. For Rockwell Automation controllers, operators have been advised to keep the physical mode switch in the secure Run position to reduce the risk of unauthorized changes.
According to a Researcher at Algoritha Security, cyberattacks targeting industrial control systems are significantly more dangerous than conventional data breaches because they can directly disrupt essential services such as electricity generation, water distribution, manufacturing and public safety. The researcher noted that organizations should isolate IT and OT networks, apply security updates promptly, minimize internet exposure and maintain continuous security monitoring to reduce cyber risks.
The FBI, NSA, CISA and the U.S. Department of Energy have urged all critical infrastructure operators to immediately assess the security of their industrial systems, address any identified vulnerabilities and promptly report suspicious cyber activity to the appropriate authorities to help prevent large-scale operational disruptions.
