Thousands of industrial controllers—the invisible brains that manage everything from water treatment plants to factory assembly lines—are sitting exposed on the open internet, creating a massive target for Iranian state-sponsored hackers. A joint advisory from multiple U.S. Federal agencies warns that these vulnerabilities have allowed Iranian-affiliated groups to target critical infrastructure, causing operational disruptions and financial losses.
The primary target of these Iranian cyberattacks on US industrial devices has been programmable logic controllers (PLCs) manufactured by Rockwell Automation and its Allen-Bradley line. According to the federal warning, these campaigns have escalated since March 2026, likely as a geopolitical response to ongoing hostilities between Iran, the United States, and Israel.
As a former software engineer, I find the scale of this exposure particularly alarming. PLCs are not designed to be public-facing; they are operational technology (OT) meant to exist within isolated, secure networks. When these devices are connected directly to the internet—often via cellular modems for remote monitoring—they essentially become open doors for anyone with the right tools to find them.
The FBI has already identified instances where this exposure led to the extraction of critical project files and the manipulation of data on Human-Machine Interface (HMI) and Supervisory Control and Data Acquisition (SCADA) displays. In plain English: hackers aren’t just watching the systems; they are potentially changing the numbers operators see on their screens, which could lead to catastrophic physical errors in a real-world industrial environment.
The scale of U.S. Exposure
The sheer volume of vulnerable hardware is staggering. Data from the cybersecurity firm Censys indicates that there are 5,219 internet-exposed hosts globally that respond to EtherNet/IP (EIP) and self-identify as Rockwell Automation/Allen-Bradley devices.
The United States bears the brunt of this risk, accounting for 74.6% of global exposure, or 3,891 individual hosts. A significant portion of these devices are located on cellular carrier autonomous system numbers (ASNs), suggesting they are field-deployed units relying on cellular modems for connectivity rather than secure, hardwired corporate networks.

This “shadow OT” creates a blind spot for many organizations. While a company’s IT department might have a handle on their laptops and servers, the cellular modem attached to a remote pump station or a ventilation system is often overlooked, leaving it completely unprotected from state-backed actors.
A pattern of industrial sabotage
This current campaign is not an isolated event but part of a broader, multi-year strategy by Iranian threat actors to probe and penetrate U.S. Infrastructure. The current focus on Rockwell Automation follows a similar pattern seen nearly three years ago when a group linked to the Islamic Revolutionary Guard Corps (IRGC), known as CyberAv3ngers, targeted Unitronics OT systems.
Between November 2023 and January 2024, the CyberAv3ngers compromised at least 75 Unitronics PLC devices. In a move that highlighted the fragility of essential services, roughly half of those targets were located within water and wastewater systems across the United States.
More recently, the threat has expanded beyond industrial controllers into corporate and medical infrastructure. The Handala hacktivist group, which has been linked to Iran’s Ministry of Intelligence and Security, reportedly wiped approximately 80,000 devices from the network of U.S. Medical giant Stryker. That attack was particularly aggressive, affecting everything from company-managed PCs to employee mobile devices.
| Target/Group | Timeline | Impact/Scale |
|---|---|---|
| Unitronics (CyberAv3ngers) | Nov 2023 – Jan 2024 | 75+ PLCs; focus on water systems |
| Stryker (Handala) | Recent (2025-2026) | ~80,000 devices wiped |
| Rockwell Automation (APT) | Since March 2026 | 3,891+ US hosts exposed |
How to secure exposed controllers
For network defenders and plant managers, the directive is clear: industrial controllers should never be directly reachable via the public internet. The vulnerability isn’t necessarily a “bug” in the software, but a failure in network architecture.
Federal agencies and security experts recommend several immediate steps to mitigate the risk of Iranian cyberattacks on US industrial devices:
- Isolation: Disconnect PLCs from the internet entirely or place them behind a strictly configured industrial firewall.
- Traffic Analysis: Scan logs for suspicious activity, specifically looking for traffic on OT ports originating from overseas hosting providers.
- Access Control: Enforce multifactor authentication (MFA) for any remote access to OT networks.
- Hygiene: Disable all unused services and authentication methods on the PLC and ensure firmware is kept up to date.
The danger of these attacks lies in their potential for “kinetic” impact. While data theft is a corporate headache, the manipulation of a PLC can lead to physical equipment failure, environmental hazards, or the disruption of essential public services.
U.S. Federal agencies are expected to continue updating the joint advisory as more data on the Iranian APT’s tactics, techniques, and procedures (TTPs) becomes available. Organizations are encouraged to monitor official CISA alerts for further indicators of compromise.
Do you function in industrial security or manage OT networks? We want to hear about your challenges in securing legacy hardware. Share your thoughts in the comments or reach out to our newsroom.
Related reading
