Iran-linked hackers are now targeting industrial controllers in US infrastructure

TL;DR AI
2 min readKey summary
US agencies warned that an Iran-linked APT has been targeting internet-exposed PLCs since at least March 2026, manipulating devices in government, wastewater, and energy environments.
The campaign has focused on Rockwell Automation and Allen-Bradley controllers, using legitimate industrial software to gain remote access and control.
Rather than relying on zero-day exploits, the attackers are directly interfering with industrial control systems that support critical US services.
FBI, CISA, NSA, DOE, and other agencies say the activity raises operational, safety, and cost risks across critical infrastructure.



