CISA: Remove Rockwell PLCs from Internet Now — Iranian OT Attacks Surge

CISA: Remove Rockwell PLCs from Internet Now — Iranian OT Attacks Surge

Why it matters now: The era of casually internet-connected industrial controllers is over. In an updated joint advisory issued July 22, 2026, six U.S. federal agencies — including CISA, the FBI, NSA, and U.S. Cyber Command — delivered an unambiguous directive to critical infrastructure operators: immediately sever direct internet connections to all Rockwell Automation and Allen-Bradley programmable logic controllers. The urgency stems from an active, sustained campaign by Iranian-affiliated APT actors who are systematically hunting for exposed PLCs, exfiltrating project files, and deploying custom malicious ladder logic that persists inside operational technology (OT) environments long after initial compromise.

Analyst Insight: This is not a theoretical vulnerability disclosure. The advisory confirms that Iranian threat actors — aligned with the IRGC Cyber-Electronic Command (IRGC-CEC) — are actively inside U.S. OT networks right now. The replacement of legitimate ladder logic with attacker-controlled code represents one of the most dangerous forms of industrial cyber sabotage, capable of causing physical equipment damage, service disruption, or latent logic-triggered failures weeks after initial access.

The Escalation: From Unitronics to Rockwell — A Broadening Attack Surface

The current wave of attacks traces a direct lineage to the November 2023 "CyberAv3ngers" incidents, in which IRGC-affiliated operatives compromised at least 75 Unitronics PLC/HMI devices across U.S. water and wastewater facilities. Those attacks exploited a depressingly simple vector: default credentials on devices exposed to the public internet via TCP port 20256. The attackers defaced HMIs with politically charged messages, but more critically, they demonstrated the ability to manipulate physical processes at will.

Fast forward to mid-2026, and the playbook has evolved dramatically. The advisory now names Rockwell Automation/Allen-Bradley CompactLogix and Micro850 controllers, along with PLCs from Schneider Electric and Siemens, as confirmed targets. The shift from Unitronics — a niche Israeli manufacturer — to the Rockwell ecosystem signals a major capability escalation. Rockwell controllers dominate North American industrial infrastructure, from water treatment and power generation to discrete manufacturing and government facilities.

Market Trend: The Rockwell Automation installed base accounts for an estimated 40-45% of the North American PLC market across critical infrastructure sectors. A compromise vector targeting Rockwell specifically — rather than smaller OEMs — multiplies the potential victim pool by an order of magnitude. For industrial automation end-users, this advisory effectively rewrites the risk calculus for every internet-facing CompactLogix and Micro850 deployment.

Inside the Attack: Malicious Ladder Logic and Persistent Threats

The most alarming technical detail in the advisory concerns the nature of the compromise itself. Threat actors are not merely scanning or probing exposed PLCs — they are replacing legitimate control logic with custom, attacker-authored ladder logic that persists in the field even after initial detection efforts. This goes far beyond the HMI defacement tactics observed in 2023.

Ladder logic is the graphical programming language that governs how a PLC responds to input signals and controls output devices — pumps, valves, motors, circuit breakers. Replacing this logic means the attacker can redefine how physical equipment behaves. A pump that should activate at a certain tank level can be programmed to remain off. A safety interlock can be silently disabled. And because the malicious logic resides on the PLC itself — not on a connected workstation — it survives reboots and can evade IT-centric detection tools.

How Malicious Ladder Logic Compromises Physical Operations
  • Logic replacement: Attackers overwrite the existing control program with custom rungs that alter device behavior under specific conditions — or unconditionally.
  • Persistence mechanism: Malicious logic executes directly on the PLC CPU; removing it requires a full controller reprogramming and firmware verification.
  • Project file exfiltration: Adversaries download the original project files (including tag databases, I/O configurations, and network maps) to threat-actor-controlled infrastructure, enabling offline analysis and follow-on attack planning.
  • Silent operation: Unlike HMI defacement, altered ladder logic may produce no visible indication on operator screens — the equipment simply behaves abnormally, often attributed to "sensor faults" or "equipment malfunction."
  • Delayed activation: Malicious rungs can be programmed with time-based or event-based triggers, remaining dormant for weeks or months before activating.

The Attribution Picture: IRGC-CEC and the Hacktivist Façade

The joint advisory explicitly ties the current campaign to IRGC-CEC-aligned operations. While the 2023 CyberAv3ngers persona presented itself as a hacktivist collective targeting Israeli-manufactured equipment, U.S. intelligence assessments have consistently attributed the activity to Iranian state-sponsored actors operating under a thin veneer of hacktivism. The updated July 2026 advisory reinforces this assessment, noting that the targeting scope has expanded well beyond Israeli-origin equipment to include American, French, and German-manufactured PLCs.

This evolution from hacktivist-adjacent disruption to systematic, multi-vendor OT exploitation signals a maturing Iranian offensive cyber capability — one that is increasingly focused on positioning itself for strategic leverage against U.S. critical infrastructure during periods of geopolitical tension, particularly following the U.S.-Iran-Israel escalation that began in February 2026.

PLC Internet Exposure: The Persistent Industry Blind Spot

Despite nearly a decade of increasingly urgent warnings from CISA, Dragos, Mandiant, and countless ICS-CERT advisories, a staggering number of PLCs remain directly accessible from the public internet. Shodan scans routinely identify thousands of exposed industrial controllers — many with default or weak credentials, and a significant portion running firmware versions with known, unpatched vulnerabilities. The reasons are varied: convenience-driven remote access by system integrators, legacy deployments predating modern security awareness, and the enduring myth that OT networks are "air-gapped" and therefore safe.

Analyst Insight: The air-gap myth is perhaps the single most dangerous misconception in industrial cybersecurity. A PLC connected to the internet — even indirectly through a misconfigured gateway or dual-homed engineering workstation — is not air-gapped. The Iranian campaign exploits precisely this disconnect between operator assumptions and network reality. Organizations that believe their OT assets are isolated often lack the monitoring and detection capabilities to know otherwise.

Key Statistics: PLC Internet Exposure (2024–2026)
  • Over 100,000 industrial control devices discoverable via Shodan as of Q1 2026, with approximately 15-20% attributed to Rockwell Automation/Allen-Bradley protocols (EtherNet/IP, CSPv4).
  • The Water and Wastewater Systems (WWS) sector consistently ranks among the top three most-exposed critical infrastructure verticals, alongside manufacturing and energy.
  • Post-CyberAv3ngers (2024), CISA reported a 40% reduction in exposed Unitronics devices — but exposure of Rockwell, Siemens, and Schneider controllers remained largely unchanged until the July 2026 advisory.
  • Default or easily guessable credentials remain the primary initial access vector in over 60% of OT-targeted intrusions documented by the authoring agencies.

Mitigation Mandate: What CISA Is Demanding Right Now

The advisory does not mince words. Organizations operating Rockwell Automation, Schneider Electric, or Siemens PLCs in U.S. critical infrastructure sectors are directed to take immediate, specific actions. The most emphatic instruction: disconnect all PLCs from direct public internet access — now, not after the next maintenance window.

Immediate Technical Actions

First, implement network segmentation that places all PLCs behind properly configured firewalls with strict access control lists. Direct internet exposure — even through port forwarding or NAT — must be eliminated. Second, enforce strong, unique authentication credentials on every PLC, HMI, and engineering workstation in the OT environment, and disable any remaining default accounts. Third, deploy OT-aware network monitoring to detect unauthorized PLC programming attempts, firmware modifications, or anomalous protocol traffic.

Proactive Threat Hunting Requirements

The agencies go further by requiring organizations to conduct proactive threat hunting for indicators of Iranian APT activity. This means actively searching for evidence of unauthorized ladder logic changes, unexpected project file downloads, and connections to known threat-actor infrastructure — rather than waiting for an alert to fire. The advisory includes specific IOCs and TTPs to guide hunt teams, emphasizing that the absence of alerts does not equal the absence of compromise.

Recommended Mitigation Checklist
  1. Immediate disconnect: Remove all PLCs, HMIs, and engineering workstations from direct public internet access. Use VPN with MFA for any required remote access.
  2. Credential hygiene: Change all default passwords. Implement unique, complex credentials for every device. Consider certificate-based authentication where supported.
  3. Network segmentation: Place OT assets in dedicated VLANs or physical segments isolated from IT and internet traffic by firewalls enforcing deny-by-default policies.
  4. Firmware verification: Compare running PLC firmware and logic against known-good backups. Validate checksums and project file integrity.
  5. Traffic monitoring: Deploy OT-specific network detection (e.g., Dragos, Nozomi, Claroty) to baseline normal PLC communications and alert on programming attempts or firmware writes.
  6. Log review: Audit PLC access logs, engineering workstation event logs, and firewall logs for connections to known IOCs listed in the CISA advisory.
  7. Incident response plan: Ensure OT-specific incident response procedures are documented, tested, and include PLC re-programming and integrity verification steps.

The Broader Implication: OT Security Is Now a Boardroom Issue

The July 2026 advisory lands at a moment when industrial cybersecurity has definitively crossed from the engineering basement to the boardroom. When a joint directive from the FBI, CISA, NSA, EPA, DOE, and U.S. Cyber Command tells you to disconnect devices immediately, the conversation is no longer about whether cybersecurity budget is available — it is about regulatory compliance, operational continuity, and in the case of water and energy utilities, public safety.

For the industrial automation sector, this advisory should trigger a hard reset on how PLC internet exposure is governed. System integrators who deploy controllers with internet-facing interfaces for remote diagnostics must adopt secure-by-design architectures: VPN gateways with multi-factor authentication, jump hosts with session recording, and zero-trust network principles applied to the OT domain. The era of the directly internet-connected PLC is over — not because the technology cannot support it, but because the threat landscape has rendered it indefensible.

Market Trend: Expect accelerated adoption of OT-native zero-trust architectures, secure remote access platforms, and managed OT detection-and-response services in the wake of this advisory. Organizations that treat this as a one-time remediation exercise — rather than a catalyst for operationalizing OT security governance — will remain exposed to the next iteration of this threat, which is almost certainly already under development by the same adversary group.

Related Articles

Back to blog