Cyber Operations — 2026-04-11

FBI, CISA, NSA and Cyber Command Issue Joint Advisory on Iranian IRGC-CEC Exploitation of U.S. Critical Infrastructure PLCs

Six federal agencies including FBI, CISA, NSA, EPA, DOE, and U.S. Cyber Command jointly warned that Iranian-affiliated actors linked to IRGC Cyber Electronic Command, operating as CyberAv3ngers, have actively exploited internet-exposed Rockwell Automation PLCs across U.S. government facilities, water and wastewater systems, and energy infrastructure since March 2026. The attacks disrupted PLC function through malicious interactions with software configurations and manipulated SCADA displays, causing operational disruption and financial loss. NERC confirmed it is actively monitoring the grid following the alert. The advisory assesses the activity is geopolitically motivated retaliation.

Analysis
The six-agency attribution to IRGC Cyber Electronic Command (CyberAv3ngers/Shahid Kaveh Group) is the most specific U.S. government link between Iran's military command structure and active critical infrastructure disruption. NERC's confirmation of active grid monitoring suggests the energy sector attack surface is broader than the advisory's disclosed victims.
2 sources
  1. Iranian Attackers Are Targeting U.S. Energy, Water Systems, Federal Agencies Say - Security Boulevard
  2. EPA, FBI, CISA, NSA Issue Joint Cybersecurity Advisory to Water System Regarding Iranian-Affiliated Cyber Attacks - U.S. EPA

View in full brief →

UNCLASSIFIED // OPEN SOURCE