Iran-Linked Hackers Target US Critical Infrastructure via Exposed PLCs
ID: ed85b8ae-9d11-513f-ba14-f0eba4547042
STIX ID: report--ed85b8ae-9d11-513f-ba14-f0eba4547042
Feed Name: ThreatCluster
Threat Score
Iran-linked threat actors are actively targeting internet-exposed Rockwell Automation/Allen-Bradley PLCs—over 5,200 devices (approx. 3,900 in the US) are exposed—with attacks using legitimate engineering software to manipulate PLC and SCADA data; federal agencies (CISA, FBI) have issued advisories warning of potential operational disruptions across energy, water, and government sectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
