US federal agencies issued a joint advisory warning that an Iranian-affiliated threat group has been breaking into internet-connected programmable logic controllers, or PLCs, across American critical infrastructure since at least March 2026 — reaching into the same class of equipment that runs factory floors, water treatment plants and energy facilities. The advisory, published April 8 and authored jointly by CISA, the FBI, the NSA, the EPA, the Department of Energy and US Cyber Command's Cyber National Mission Force, ties the activity to a group previously identified as CyberAv3ngers, affiliated with Iran's Islamic Revolutionary Guard Corps Cyber Electronic Command.

Investigators say the campaign is likely connected to broader hostilities involving Iran, the US and Israel, and represents a continuation of a tactic security researchers have watched for several years: using low-cost, low-sophistication access to industrial equipment as a form of geopolitical signaling rather than pure financial extortion.

What's actually being targeted

The advisory names specific equipment: Rockwell Automation's CompactLogix and Micro850 PLCs, and Siemens S7-series controllers, alongside the human-machine interface and SCADA displays operators use to monitor them. Attackers gained unauthorized remote access through leased, third-party infrastructure originating overseas, then used configuration tools — including Rockwell's own Studio 5000 Logix Designer software — to interact directly with PLC project files and manipulate what HMI and SCADA screens display to operators. In several cases, attackers deployed Dropbear SSH software on compromised endpoints to maintain persistent access, targeting inbound ports including 44818, 2222, 102, 22 and 502 — the standard communication ports for industrial protocols.

Affected sectors span government facilities, water and wastewater systems, and energy operators, with officials warning the same exposure pattern applies broadly across manufacturing environments that run internet-facing OT equipment without adequate network segmentation.

Why exposed PLCs keep being an easy target

"Cyber attacks are key components now in all war and kinetic attacks," said Joe Saunders, CEO of RunSafe Security, in comments on the advisory. "Cyber attacks are one way to break down physical barriers and can be executed at a time and place of a nation-state's choosing." Steve Povolny, a vice president at Exabeam, noted that facilities like water treatment plants and pipeline operations are "uniquely asymmetric targets" that let adversaries create disruption without triggering a traditional military response.

The agencies' guidance to defenders is blunt: disconnect PLCs from public-facing networks entirely, route any remote access through monitored gateways, secure cellular modems with strong authentication, and enforce multifactor authentication everywhere. For device manufacturers, the ask is structural — eliminate insecure default settings, build in phishing-resistant multifactor authentication, and design products to be secure by default rather than relying on operators to configure security correctly after the fact. That last recommendation points at the uncomfortable truth underlying the entire advisory: much of this exposure exists not because attackers found a novel flaw, but because industrial equipment shipped — and was deployed — with the assumption that nobody would go looking for it on the open internet.