U.S. Agencies Warn of Increased Cyber Threats to Critical Infrastructure

A new warning from US cybersecurity authorities has placed industrial control systems at the centre of global cybersecurity concerns after Iranian-affiliated threat actors were confirmed targeting programmable logic controllers (PLCs) used in critical infrastructure environments.

Industrial control system cybersecurity engineer monitoring PLC and SCADA systems in a modern factory control room.

The Cybersecurity and Infrastructure Security Agency (CISA), together with the FBI, NSA, Environmental Protection Agency (EPA), Department of Energy and other government partners, updated a joint cybersecurity advisory highlighting ongoing malicious activity against internet-connected operational technology devices. 

The warning is significant because PLCs are not ordinary corporate computers. They are specialised devices that control physical processes inside industrial environments, including systems used in water treatment facilities, energy operations, manufacturing plants and other essential services. A successful compromise of these systems can move a cyberattack beyond data theft and into the physical world.

According to the updated advisory, Iranian-affiliated cyber actors have been targeting PLC environments from multiple manufacturers, expanding beyond previously identified Rockwell Automation and Allen-Bradley devices to include Schneider Electric and Siemens systems. 

The activity highlights a growing concern among defenders: attackers are increasingly focusing on operational technology because these systems often remain exposed to the internet, sometimes with weaker security controls than traditional enterprise networks.

From IT networks to physical infrastructure

Traditional cyberattacks often focus on stealing information, deploying ransomware or gaining access to corporate networks. Attacks against industrial control systems create a different category of risk because the targeted technology is designed to operate real-world processes.

PLCs are commonly used to monitor and control industrial equipment. They communicate with supervisory control and data acquisition (SCADA) systems and human-machine interfaces (HMIs), which allow operators to monitor industrial environments.

The updated advisory states that threat actors have interacted with PLC project files and manipulated information displayed through HMI and SCADA systems, creating the possibility of operators receiving inaccurate information about the state of industrial processes. 

Authorities have previously linked similar activity to Iranian-affiliated groups operating under names including CyberAv3ngers. However, attribution in cyber operations remains complex, and public agencies continue to base their assessments on collected intelligence rather than publicly available evidence alone.

The latest warning does not describe a theoretical risk. Government agencies stated that the activity has already caused operational disruption and financial impact in affected environments. 

Why this matters for organisations worldwide

Although the advisory focuses primarily on US critical infrastructure, the underlying risk extends well beyond one country.

Industrial environments around the world rely on similar technologies from major automation vendors. Many organisations operate equipment that was designed years or decades ago, before internet exposure and remote connectivity became common.

The problem is not limited to a single software flaw that can simply be patched. In many cases, attackers are exploiting insecure configurations, exposed devices and weak network segmentation.

Modern industrial environments increasingly connect operational technology with corporate networks and cloud services. While this improves efficiency and remote management capabilities, it also creates additional pathways for attackers.

Security researchers have repeatedly warned that exposed industrial systems represent an attractive target because disrupting physical operations can create economic pressure and public attention.

The response from cybersecurity authorities

CISA and its partner agencies recommended that organisations operating industrial systems review their exposure, remove unnecessary internet access to PLC devices and strengthen monitoring around OT environments. 

The updated guidance also includes additional detection recommendations related to malicious changes in PLC programming environments and provides organisations with indicators that can help identify suspicious activity. 

The agencies emphasised that organisations should treat internet-exposed operational technology as a priority security concern. Unlike many enterprise systems, industrial devices often directly support essential services, meaning a cybersecurity incident can have consequences beyond the organisation itself.

The challenge of protecting legacy industrial environments

One of the biggest difficulties in securing industrial systems is that many cannot be updated or replaced quickly.

Factories, utilities and infrastructure providers often depend on equipment that must operate continuously. Applying security changes requires careful planning because unexpected changes can affect safety, production and availability.

This creates a difficult balance between cybersecurity and operational reliability.

Security teams increasingly focus on defensive measures such as network segmentation, stronger authentication, continuous monitoring and strict control over remote access.

The latest advisory reinforces the message that industrial cybersecurity cannot be treated as an isolated technology problem. Protecting OT environments requires cooperation between engineers, IT teams, security specialists and government agencies.

A warning sign for the global cybersecurity community

The expansion of this campaign demonstrates how cyber conflict is increasingly moving into environments that directly support everyday life.

For many years, cybersecurity discussions focused primarily on protecting computers, servers and online accounts. The targeting of PLCs and industrial systems shows that attackers are also looking at the technology behind essential services.

The most important lesson from this incident is not only about one threat actor or one group of devices. It is about the changing nature of cyber risk.

As more industrial systems become connected, organisations must assume that operational technology will remain a major target for sophisticated attackers. The ability to detect, isolate and respond to threats before they affect physical operations will become one of the defining challenges of modern cybersecurity.