Breaking: Iranian Hackers Actively Disrupting US Water and Energy ICS — 24 July 2026
Iranian State Hackers Actively Disrupting US Water and Energy Industrial Control Systems
The FBI, NSA, CISA, and the Department of Energy issued an updated joint advisory (AA26-097A) this week confirming that Iranian state-backed hackers are actively breaching and manipulating industrial control systems at US water and energy providers, with disruptive effects already achieved in the field. This is not a theoretical warning. The agencies state the attackers have already broken into at least one critical infrastructure provider and altered controller programming logic to disable shutdown and alarm processes, allowing systems to enter unsafe operating conditions without notifying operators.
The campaign targets programmable logic controllers (PLCs) on internet-connected operational technology networks. Initial reporting earlier this year identified Rockwell Automation/Allen-Bradley controllers as the primary target. The updated advisory expands the scope significantly, confirming exploitation now extends to Schneider Electric and Siemens PLCs as well, with the agencies warning that "potentially all internet exposed" PLCs across US critical infrastructure sectors may be vulnerable.
The attackers are manipulating data shown on human-machine interface (HMI) and SCADA displays while simultaneously altering the underlying control logic, so operators see normal readings while the physical process drifts into an unsafe state. Indicators of compromise include traffic on ports 44818, 2222, 102, and 502 originating from foreign hosting providers, and malicious modifications to reusable code modules within controller programs.
CISA attributes the motive to ongoing hostilities between Iran and the US/Israel, describing the activity as intended "to cause disruptive effects within the United States." This fits a broader pattern this year of escalating Iranian offensive cyber activity, including the Handala group's wipe of tens of thousands of employee devices at medical device maker Stryker, a claimed (though unconfirmed) attempt to disrupt California's Cal Water supply, and the leak of FBI Director Kash Patel's personal email contents.
While the confirmed victims sit in the US, the technique is vendor-based rather than geography-based. Any organisation running internet-exposed Rockwell, Schneider Electric, or Siemens PLCs anywhere, including in Europe, is within the stated blast radius. European utilities and manufacturers using the same controller families should treat this as directly relevant, not a US-only problem.
So What / Action
Audit every PLC and OT device for direct internet exposure today, not this quarter. If you cannot immediately verify a controller is isolated behind a secure gateway or firewall, assume it is exposed and remediate now. For Rockwell Automation devices specifically, CISA recommends physically setting the controller's mode switch to RUN to block remote logic changes. Review logs for connections on ports 44818, 2222, 102, and 502 from unfamiliar or foreign-hosted IP ranges, and compare current controller program logic against known-good backups to detect unauthorised changes to shutdown and alarm routines. Enforce strict multi-factor authentication on any remote engineering access, and brief OT operations teams that HMI/SCADA display readings cannot currently be trusted as ground truth on affected networks; physical verification of safety-critical states may be necessary until systems are confirmed clean. This is an active, ongoing campaign with confirmed disruptive impact, not a patch-and-move-on advisory.

