The FBI, CISA, NSA, EPA, Department of Energy, and US Cyber Command issued a joint advisory warning of intensified cyberattacks by Iranian-affiliated hackers on programmable logic controllers (PLCs) in US critical infrastructure. Attacks since at least March 2026 have caused operational disruptions and financial losses in government facilities, wastewater, water, energy, and municipal systems, amid escalating tensions in the US-Israel war with Iran.
The advisory, published on Tuesday, highlights an Iranian advanced persistent threat group targeting internet-exposed operational technology devices, including PLCs that interface between automation computers and physical machinery in factories, water treatment centers, oil refineries, and other facilities. Victims across multiple sectors reported diminished PLC functionality, data manipulation, operational disruptions, and financial losses. The advisory stated: “These PLCs were deployed across multiple US critical infrastructure sectors... Some of the victims experienced operational disruption and financial loss.” The FBI noted these developments on X, underscoring the escalation.