Iranian Cyberattacks Target Nearly 4,000 US Industrial Devices, Causing Operational Disruptions
Nearly 4,000 industrial control devices in the United States, primarily Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), have been targeted by Iranian state-backed cyberattacks since March 2026. These attacks have led to operational disruptions, forced manual operations, and financial losses. The attackers, linked to Iranian advanced persistent threat (APT) groups, exploited internet-exposed PLCs to extract project files, manipulate Human-Machine Interface (HMI) and Supervisory Control and Data Acquisition (SCADA) displays, and attempt destructive actions using malware known as 'wipers.' The sectors most affected include oil and gas, water and wastewater, energy, and government services. Multiple U.S. federal agencies have issued joint advisories urging immediate defensive actions, including disconnecting PLCs from the internet, enforcing multifactor authentication, and monitoring for suspicious activity.