US Agencies Update Advisory on Iranian Cyber Campaign Targeting Internet-Connected PLCs
A joint advisory from US cybersecurity and intelligence agencies warns that Iranian-affiliated cyber actors are actively exploiting internet-exposed programmable logic controllers (PLCs). The campaign targets critical infrastructure sectors — including water and wastewater systems, energy, and healthcare — and relies on weak security postures such as default credentials and unsecured remote access to compromise operational technology (OT) devices.
- Scope: Internet-connected PLCs in critical infrastructure environments.
- Targeted sectors: Water and wastewater, energy, healthcare, and other critical operations.
- Techniques: Exploitation of default passwords, poor network segmentation, and generally weak device hardening.
- Risk: Unauthorized access to control systems that could disrupt safety, availability, and operational integrity of industrial processes.
Recommended Actions for Defenders
- Immediately identify and inventory internet-exposed PLCs and other OT devices.
- Disable or restrict remote internet access to OT devices; use secure remote access solutions and VPNs where needed.
- Change default credentials and enforce strong password policies; apply multi-factor authentication where feasible.
- Harden devices by applying vendor patches and firmware updates; follow vendor-recommended security configurations.
- Implement network segmentation and monitoring to isolate OT environments and detect anomalous activity.
- Coordinate with national and sector-specific cybersecurity authorities for threat intelligence and mitigation guidance.