Iranian hacking groups are stepping up their cyberattacks on critical U.S. infrastructure , using advanced techniques to disrupt PLC and SCADA systems . According to a joint warning issued by six federal agencies, including the FBI , NSA and CISA , the attacks are primarily targeting Rockwell Automation and Allen-Bradley systems that are exposed online. The escalation represents a new phase in cyberwarfare, where states are using increasingly sophisticated tactics to undermine the national security of their adversaries.

Cyberattacks have escalated significantly since the start of the US-Israeli strikes against Iran, with attackers interacting with project files and manipulating data on human-machine interface (HMI) and supervisory control and data acquisition (SCADA) displays.
The targeted sectors include: energy, water supply and sanitation, government services and other critical infrastructure. The choice of these sectors is not accidental, as their disruption can have devastating consequences for the daily lives of citizens and the economic stability of the country.
See also: US: Iranian hackers target critical infrastructure
The joint alert, issued on April 7, 2026 by the FBI, NSA, CISA, EPA, DOE and Cyber Command, reveals that Iranian hackers have already compromised at least 75 devices across U.S. over the past 12 months, causing operational disruptions and financial losses. These attacks preceded the current escalation and demonstrate the ongoing threat posed by Iranian cyber groups. The coordinated response by so many federal agencies underscores the severity of the threat and the need for a unified response strategy.
Attack Techniques and Targeting PLC Systems
The attackers are targeting operational technology (OT) devices that are exposed to the internet, primarily targeting programmable logic controllers (PLCs) from Rockwell Automation and Allen-Bradley. Iranian hackers are exploiting vulnerabilities in key software systems to gain access and maliciously manipulate the project file. The choice of these systems is not accidental, as Rockwell Automation holds a significant market share in American industrial facilities, making its products an attractive target for mass attacks.
The attack methodology involves tampering with data in HMI and SCADA, causing operational disruptions in industrial automation processes. Security researchers attribute the attacks to APT linked to Iran. The attackers appear to have a good understanding of industrial processes, which allows them to cause targeted disruptions that can lead to production downtime or even equipment damage.
It is worth noting that the current attacks resemble the activities of CyberAv3ngers . This is a group affiliated with the IRGC (Islamic Revolutionary Guard Corps). In November 2023 , CyberAv3ngers had compromised and corrupted PLCs of Israeli Unitronics at multiple water treatment facilities in Pennsylvania , shortly after the October 7 Hamas attack on Israel . This historical record shows that Iranian hackers have developed a consistent strategy of targeting critical infrastructure in response to geopolitical developments.
See also: Iranian Prince of Persia hackers target critical infrastructure

Impact
Federal agencies identified the disruptions through collaboration with affected organizations, while Iranian hackers have claimed responsibility for victims including medical technology company Stryker and local governments following the US-Israeli strikes. The attackers’ public claim of responsibility is part of their psychological strategy, aiming to create a climate of insecurity and demonstrate their capabilities.
Recent activity prior to the escalation of the conflict included the deployment of malware via the Telegram, targeting various US entities. These attacks demonstrate the growing capability and willingness of Iranian cyber groups to conduct sophisticated operations against critical infrastructure. The use of social media platforms to deliver malware demonstrates the attackers’ adaptability and ability to exploit new attack vectors.
Advanced Defense and Surveillance Techniques
To counter the sophisticated techniques of Iranian hackers , organizations must adopt a layered security approach . Implementing real-time network monitoring systems can identify anomalous traffic to and from PLC devices . Additionally, implementing network segmentation and zero-trust architecture techniques can limit attackers’ lateral movement within OT networks . Regular firmware updates and implementing strong access control policies are also critical components of a comprehensive defense strategy.
See also: Drift social engineering: Hackers stole $285 million.
Devices should also not be exposed to the internet. Organizations should review available logs for suspicious activity and contact Rockwell Automation if they use Allen-Bradley products and suspect they have been targeted. Implementing VPN connections and using multi-factor authentication for access to critical systems are also key protection measures that should be implemented immediately.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The industry is urged to act immediately, monitor networks and coordinate with federal partners such as the Department of Energy. Experts emphasize that other PLC may also be at risk, making it necessary to widely implement protection measures. The creation of incident response teams (CSIRTs) and regular cybersecurity exercises can significantly improve organizations' preparedness.
The escalation of Iranian cyberattacks reflects geopolitical tension and underscores the need for enhanced cybersecurity for critical infrastructure. As SecurityWeek reports, these attacks are part of a broader strategy aimed at destabilizing American infrastructure through cyberspace. The international community must develop new models of cooperation and information sharing to effectively address these evolving threats, while critical infrastructure organizations must invest in advanced defense technologies and ongoing training for their personnel.
