Skip to main content

Share story

Security Policy

Iran-Linked Hackers Target US Critical Infrastructure, Government Agencies Warn

Flag of Iran on binary code. Image: Primary
Federal agencies are warning that hackers working on behalf of the Iranian government are actively disrupting operations at multiple US critical infrastructure sites. Six government agencies issued an urgent advisory on Tuesday identifying the threat to industrial control systems. The FBI, Cybersecurity and Infrastructure Security Agency, National Security Agency, Environmental Protection Agency, Department of Energy, and US Cyber Command jointly reported that an Iranian-affiliated advanced persistent threat group has been compromising programmable logic controllers since at least March 2026. The targeted PLCs, manufactured by Rockwell Automation and Allen-Bradley, control physical machinery in factories, water treatment centers, oil refineries, and other industrial settings. Victims have experienced operational disruption and financial losses, according to the advisory. Security firm Censys identified 5,219 internet-exposed Rockwell devices, with 75 percent located in the United States. The attackers are using legitimate vendor software including Rockwell Studio 5000 Logix Designer to manipulate project files and control system displays without requiring zero-day exploits. The cyberattacks come amid ongoing military conflict between the US and Iran. The advisory notes that pro-Iranian proxy groups have also conducted DDoS attacks against major platforms and government portals. Federal agencies have published IP addresses and infrastructure identifiers associated with the threat actors along with security guidance for affected organizations.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Ars Technica and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security
Security

Dell urges System Update patch for flaw enabling root access

Dell urged customers to update its System Update tool after identifying a critical vulnerability that could let an unauthenticated remote attacker execute code with root privileges on vulnerable PowerEdge servers. SecurityAffairs ...

AI Policy
AI Policy

Pentagon says it has ended use of Anthropic products

The Pentagon has completed its phase-out of Anthropic products, the BBC reported, citing the US Department of Defense. The removal followed a dispute over Anthropic's insistence on contractual restrictions against mass surveillanc...

Security
Security

ClickFix attackers hide executable scripts in browser cache

Microsoft Threat Intelligence has identified a ClickFix attack that stages a malicious script in a browser's cache disguised as a PNG image. Compromised websites then persuade users to run a command that executes the cached conten...

Policy Security
Policy Security

OpenAI and Anthropic support mandatory AI breach reporting in Australia

OpenAI and Anthropic told an Australian parliamentary inquiry they would support laws requiring AI developers to disclose breaches involving their systems, EconoTimes reported. The comments follow criticism of OpenAI for waiting t...

Security Products
Security Products

Texas disclosure puts Oracle healthcare breach at nearly 20 million people

Information released by the Texas attorney general puts the scope of last year's cybersecurity breach at Oracle's healthcare unit at nearly 20 million people, Bloomberg reported. The breach compromised personal information belongi...