CISA Warns Iran-Linked Hackers Exploit Rockwell PLCs to Disrupt U.S. Critical Infrastructure
ID: eefef403-f3b6-5ecc-a480-5d9939601331
STIX ID: report--eefef403-f3b6-5ecc-a480-5d9939601331
Feed Name: cybersecurityNews.com
**Executive summary:** An Iran-linked APT campaign since at least March 2026 has targeted internet-exposed PLCs (Rockwell CompactLogix/Micro850, Schneider BMX P34/Modicon M340, Siemens S7-1200) across U.S. government, water, wastewater, and energy facilities, using legitimate engineering software and rented infrastructure to download and modify project files (including .ACD and Add-On Instructions), alter HMI/SCADA displays, disable alarms/shutdowns, and produce operational disruption; CISA/FBI published IoCs and urge removing direct internet access, enforcing MFA, securing modems, validating running project files, and reviewing logs and backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
