CyberDefenseMagazine

FBI and CISA Warn of Escalating Iranian Cyber Attacks


Escalating Threats to Critical Infrastructure

On July 22, 2026, federal agencies led by the FBI, CISA, and NSA released an updated joint alert warning that cyberattackers with ties to Iran are actively attacking vital U.S. infrastructure. The revised notice shows a more comprehensive threat landscape: attackers are now aggressively compromising internet-exposed Programmable Logic Controllers (PLCs) from other prominent manufacturers, such as Siemens and Schneider Electric, whereas early campaigns only targeted Rockwell Automation equipment. These threat actors use publicly available controls to obtain initial access while operating in vital areas including government facilities, electricity, and water management.  Once inside, they alter project file logic and manipulate data feeds on HMI and SCADA control panels, causing severe operational disruption and financial damage. 

Security teams must prioritize isolating all industrial control systems from direct internet exposure behind stringent firewalls and protected access gateways in order to combat these persistent assaults. System logs should be examined by network managers for anomalous traffic that hits important operating ports like 44818, 2222, 102, and 502. Special attention needs to be brought to connections coming from foreign hosting services. For physical hardware defenses, operators running compatible PLCs should manually switch controller key toggles into “RUN” position, effectively locking down the unit’s memory and preventing unauthorized remote updates to the underlying ladder logic.

Author Notes

Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency, National Security Agency, Environmental Protection Agency, Department of Energy, U.S. Cyber Command, & Department of the Treasury. (2026, July 22). Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure (Advisory No. AA26-097A). https://www.ic3.gov/CSA/2026/260722.pdf 

About the Author

Carmen Estela is a Cybersecurity Research Analyst at Cyber Defense Magazine and a Women in Cybersecurity Award Candidate. She recently graduated with a Master’s of Science degree from the University of Central Florida and holds a Bachelor’s degree in Criminology from the University of Florida with certifications in Data Analytics and AI Fundamentals. She frequently speaks and volunteers at well-known industry gatherings, such as BSides Orlando and BSides Jax, where she offers her perspectives on emerging cyber trends. Carmen is committed to advancing the standards of governance, risk, and compliance within cybersecurity. She has also served as an adult protective investigator, police dispatcher, and legal intern, applying investigative skills across law enforcement, academic, and public service settings. 

Reach her online at [email protected].



Source link