Iranian-Affiliated APT Escalates Targeting of US Critical Infrastructure PLCs
FBI, CISA, NSA, EPA, DOE, and US Cyber Command's Cyber National Mission Force issued a joint advisory on May 5 warning of ongoing Iranian-affiliated APT exploitation of internet-exposed Rockwell Automation/Allen-Bradley CompactLogix and Micro850 PLCs across US critical infrastructure. The authoring agencies identified activity dating to at least March 2026 targeting Government Services and Facilities, Water and Wastewater Systems, and Energy sectors, with some victims experiencing operational disruption and financial loss. The actors used leased third-party infrastructure and Rockwell Automation's
The confirmed operational disruption and financial loss, a material escalation from prior threat-warning posture, reflects a coercive signaling campaign below the threshold of irreversible physical destruction, consistent with Tehran's 2023 CyberAv3ngers/Unitronics pattern of demonstrating access rather than executing damage. The escalation timeline correlates to Iran-US-Israel hostilities, suggesting deliberate calibration, though breadth of compromised nodes could equally reflect opportunistic exploitation of a common vulnerability. Six-agency co-authorship including CNMF and DOE signals the IC treats this above routine advisory level. A publicly confirmed destructive incident before August 2026 is