Iran-Linked Hackers Breach U.S. Industrial Systems, Trigger Disruptions
ID: 56a94e66-ae74-5acc-831d-ad7fc91ad507
STIX ID: report--56a94e66-ae74-5acc-831d-ad7fc91ad507
Feed Name: The Cyber Express
U.S. agencies (FBI, CISA, NSA and partners) issued an advisory that Iranian‑affiliated APTs are actively exploiting internet-exposed PLCs (e.g., CompactLogix, Micro850) to modify controller logic and HMI/SCADA displays, causing operational disruptions and financial losses across government, water/wastewater, and energy sectors; attackers use legitimate engineering tools (Studio 5000), common OT ports (44818, 2222, 102, 22, 502), Dropbear SSH for persistence, overseas IPs and leased infrastructure, and the campaign has been observed from Jan 2025 through Mar 2026—organizations are urged to remove PLCs from direct internet exposure, improve segmentation and authentication, and monitor OT logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
