Iranian Cyberattacks Target Nearly 4,000 US Industrial Devices, Disrupt Operations
Nearly 4,000 industrial control devices in the United States, primarily Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), have been exposed to Iranian state-backed cyberattacks since March 2026. These attacks have led to operational disruptions, forced manual operations at affected sites, and financial losses. The threat actors, linked to Iranian advanced persistent threat groups affiliated with the Islamic Revolutionary Guard Corps and the Ministry of Intelligence and Security, exploited internet-exposed PLCs to extract project files, manipulate Human-Machine Interface and Supervisory Control and Data Acquisition displays, and attempt destructive actions using malware known as 'wipers.' The sectors most affected include oil and gas, water and wastewater, energy, and government services. Multiple U.S. federal agencies have issued joint advisories urging immediate defensive actions, including disconnecting PLCs from the internet, enforcing multifactor authentication, and monitoring fo...