Iranian APTs Target 5,219 Exposed Rockwell PLCs in U.S. Critical Infrastructure

Iranian APTs Target 5,219 Exposed Rockwell PLCs in U.S. Critical Infrastructure

First seen 11 Apr 2026, 21:14 UTC GbhackersSecurityaffairs.CoFacilitiesdivewww.cybersecuritydive.comcensys.com 87% similarity 78.0

Article Content

Browse articles
ThreatCluster

Censys researchers identified 5,219 Rockwell Automation PLCs exposed to the internet, primarily located in the U.S. These devices are being targeted by Iranian-affiliated advanced persistent threat (APT) actors, as warned by U.S. agencies including the FBI, CISA, and NSA on April 7, 2026. The threat actors are exploiting vulnerabilities in internet-connected operational technology (OT) systems across various critical infrastructure sectors. This follows a previous campaign in November 2023 that compromised at least 75 Unitronics PLCs in U.S. water and wastewater facilities. Security experts are urging immediate action to secure or disconnect these vulnerable devices to mitigate potential attacks. The ongoing threat highlights the increasing risk to critical infrastructure from state-sponsored cyber operations.

Key Points: • 5,219 Rockwell PLCs are exposed online and vulnerable to Iranian APT attacks. • U.S. agencies issued a warning on April 7, 2026, regarding the exploitation of these devices. • Previous attacks linked to the same APT actors targeted U.S. water facilities in late 2023.

ThreatCluster AI How this analysis works

Timeline

2023-11-01
Iranian APTs compromised 75 Unitronics PLCs in U.S. water facilities.
2026-04-07
U.S. agencies warn of Iranian APTs targeting exposed Rockwell PLCs.
2026-04-11
Censys reports 5,219 exposed Rockwell PLCs online.

Community

Browse all →

Tracked Entities in This Story