logo

Iranian Hackers Target US Critical Infrastructure via Exposed PLCs

ID: 03a38e5c-d18b-5172-abb1-2990de2bebae

STIX ID: report--03a38e5c-d18b-5172-abb1-2990de2bebae

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-04-09

Date Updated: 2026-04-09

...
...

Iranian-affiliated operators are exploiting more than 5,200 internet-exposed Rockwell Automation PLCs—concentrated in the US—to target government and critical infrastructure (energy, water), using legitimate vendor tools to manipulate control systems and causing reported operational disruptions; CISA has warned organizations to disconnect these devices from public networks to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.