Iranian APT Groups Are Targeting Your PLCs: What U.S. Energy, Water and Wastewater Sectors Need to Know Now
If your organization operates internet-facing programmable logic controllers (PLCs) from Rockwell Automation, Schneider Electric, or Siemens and you haven't reviewed your remote access configurations recently this post is for you.
On April 7, 2026, CISA, the FBI, NSA, EPA, and the Department of Energy issued a joint advisory warning that Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-connected operational technology (OT) devices across U.S. critical infrastructure with the energy and water sectors among the primary targets. The advisory was updated on July 22, 2026 to expand scope and add detection guidance for compromised reusable code modules in PLC programs.
This is not a theoretical risk. Organizations across the energy, water and wastewater, and government sectors have already experienced operational disruption and financial loss as a direct result of this activity.
What the Advisory Says
The Iranian-affiliated actors are targeting PLCs exposed directly to the internet. A configuration that remains alarmingly common across smaller OT operators. Their tactics focus on:
Insecure remote access pathways — VPNs, RDP, and direct internet connections to OT devices that lack proper authentication controls
Credential compromise — default and weak credentials on industrial devices that have never been changed from factory settings
Limited visibility — exploiting gaps in legacy and hybrid IT/OT environments where security monitoring doesn't extend into the operational layer
Once inside, these actors manipulate PLC ladder logic and reusable code modules, the programs that control physical processes, to cause operational disruption or position themselves for future destructive attacks.
Why PLCs Are Such an Attractive Target
PLCs are the workhorses of industrial automation. They control everything from substation switching sequences to pipeline pressure regulation to turbine operations. Unlike IT systems, they were designed for reliability and longevity not security. Many run on firmware that hasn't been updated in years, expose management interfaces directly to the internet for "convenience," and have default credentials that are publicly documented in vendor manuals.
For a threat actor looking to disrupt physical operations rather than just steal data, PLCs are the highest-value targets in the environment.
What PLC Operators Should Do Now
The joint advisory includes specific mitigations. The most critical actions for organizations:
Immediately:
Adhere to CISA Alert - CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs & CISA Joint Advisory AA26-097A (updated July 22, 2026); DOE CESER; FBI; NSA
Audit every PLC and OT device for direct internet exposure and remove it. If remote access is operationally required, place it behind a VPN with MFA.
Change all default credentials on OT devices. Every one.
Review PLC ladder logic and reusable code modules for unauthorized modifications.
Within 30 days:
Implement network segmentation between IT and OT environments. The corporate network and the control network should not be directly connected.
Enable logging on OT devices that support it and route those logs to a SIEM or monitoring platform where someone will actually see alerts.
Review and restrict which vendor and contractor accounts have remote access to OT systems.
Within 90 days:
Conduct a formal OT asset inventory. You cannot protect what you haven't identified.
Develop or update your OT-specific incident response plan. IT incident response procedures don't translate directly to OT environments — the containment and recovery calculus is different when operational continuity is at stake.
Engage with DOE's Energy Threat Analysis Center (ETAC), EPA, or your state public utilities commission for sector-specific threat intelligence.
The Regulatory Angle
For organizations subject to NERC CIP standards, this advisory has direct compliance implications. CIP-005 (Electronic Security Perimeters), CIP-007 (Systems Security Management), and CIP-010 (Configuration Change Management) all speak directly to the vulnerabilities being exploited. FERC has signaled increased enforcement attention on OT security gaps following this advisory.
If you operate Bulk Electric System (BES) assets and haven't mapped this threat to your CIP controls, that gap needs to close.
The Bottom Line
Iranian APT groups are not conducting opportunistic attacks against PLC operators. They are conducting deliberate, targeted campaigns against specific industrial device types with the intent to map physical processes and pre-position for disruption. The threat is active, the advisory is current, and the mitigations are well-defined.
The question for organizations is not whether this threat is real. It's whether your current controls would stop it.
vCISO Pro works with organizations to assess OT/ICS security posture, close gaps identified in federal advisories, and build practical incident response capabilities. Schedule a consultation to discuss where your organization stands.
Sources: CISA Alert -CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs (release date July 30, 2026) & CISA Joint Advisory AA26-097A (updated July 22, 2026); DOE CESER; FBI; NSA
Comments