logo

Iran-Linked Actors Breach Are Targeting US Water and Energy Control Systems

ID: b289c8cc-7d72-56a7-86f0-6674efb714b1

STIX ID: report--b289c8cc-7d72-56a7-86f0-6674efb714b1

Feed Name: Security Affairs

Threat Score
92/100

Date Published: 2026-07-25

Date Updated: 2026-07-26

Author: Pierluigi Paganini

...
...

U.S. agencies warn that Iran-linked APT actors have been intruding into internet-exposed PLCs and OT devices (including Rockwell, Schneider Electric, and Siemens controllers), exfiltrating and modifying project files via vendor engineering tools and common OT ports, manipulating HMI/SCADA displays and disabling shutdowns/alarms—causing operational disruption and financial loss across water, energy, and other critical infrastructure sectors; agencies recommend removing direct internet access to PLCs, enforcing vendor best practices, and monitoring OT ports and logs for indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.