United States
U.S. Critical Infrastructure PLCs
U.S. agencies, including the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA), have issued a warning to U.S. organizations that Iranian-affiliated threat actors are exploiting internet-connected programmable logic controllers (PLCs) across U.S. critical infrastructure.
The agencies warned of ongoing cyber exploitation targeting operational technology (OT) devices, including Rockwell Automation and Allen-Bradley PLCs, across multiple critical infrastructure sectors. These activities have already led to disruptions impacting organizations in affected industries.
The threat actors are reportedly focusing primarily on government services and facilities, including local municipalities, as well as water, wastewater and energy systems.
How it could affect your business
Due to the widespread use of these PLCs and the risk of attackers expanding to other OT devices, organizations should urgently review the tactics, techniques and indicators of compromise (IoCs) outlined in this advisory for signs of current or past activity. Applying recommended security measures can help reduce exposure and strengthen defenses across critical infrastructure environments.