Iranian Hackers Target U.S. Critical Infrastructure with Advanced PLC Attacks

Iranian Hackers Target U.S. Critical Infrastructure with Advanced PLC Attacks

First seen 23 Jul 2026, 18:34 UTC MbtmagCybersecuritydiveTechtimeswww.rockwellautomation.comclaroty.com+1 87% similarity 80.0

Article Content

Browse articles
ThreatCluster

Iran-affiliated hackers have expanded their attacks on U.S. critical infrastructure, targeting programmable logic controllers (PLCs) from Siemens and Schneider Electric, in addition to Rockwell Automation systems. The Cybersecurity and Infrastructure Security Agency (CISA) and FBI issued an advisory on July 22, 2026, confirming operational disruptions and financial losses across various sectors, including water treatment and energy facilities. Attackers used legitimate software tools to manipulate PLCs, replacing real sensor data with false readings, which poses significant risks to operational safety. The advisory highlights a shift in tactics, with attackers leveraging existing vulnerabilities, including CVE-2021-22681, to gain unauthorized access. The ongoing campaign is linked to Iranian threat groups, including the CyberAv3ngers, and is believed to be part of a broader geopolitical conflict. Organizations are urged to strengthen access controls and validate project files to mitigate risks.

Key Points: • Iran-affiliated hackers are targeting Siemens and Schneider Electric PLCs in addition to Rockwell Automation. • The attacks manipulate sensor readings, posing risks to critical infrastructure operations. • CISA and FBI confirm operational disruptions and financial losses across multiple sectors.

ThreatCluster AI

Timeline

2021-03-03
CVE-2021-22681 published
A critical authentication bypass vulnerability in Rockwell Automation's Studio 5000 software was disclosed.
Mbtmag
2026-03-05
CVE-2021-22681 added to CISA KEV
CISA added CVE-2021-22681 to its Known Exploited Vulnerabilities list due to active exploitation.
Mbtmag
2026-07-22
CISA and FBI issue advisory on Iranian cyber actors
Agencies warn of expanded attacks on PLCs affecting critical infrastructure, confirming operational disruptions.
Techtimes
Recent
Iran-linked hackers exploit PLC vulnerabilities
Hackers are using legitimate software to manipulate PLCs, causing false sensor readings and operational risks.
Cybersecuritydive

Community

Browse all →