WarBrief Live | October 6, 2026 | Cyber Intelligence
In the spring of 2026, U.S. federal agencies went public with an unusual warning: Iranian-affiliated hackers were actively targeting the industrial controllers that run American water plants, power grids, and municipal services. What made the warning stick was not just the attribution, but the evidence. The Censys Iran cyber attacks data — an internet-wide scan published by the threat intelligence firm Censys — mapped the exact exposed devices these attackers were going after: 5,219 internet-facing programmable logic controllers (PLCs) around the world, most of them in the United States. This article lays out what is confirmed, what is reported but not yet proven, and how scan data is helping defenders find these devices before attackers do.
Key Takeaways
- U.S. agencies confirmed in April 2026 that Iranian-affiliated actors are exploiting internet-exposed PLCs across water, energy, and government sectors — advisory AA26-097A, updated July 22, 2026.
- Censys research identified 5,219 exposed Rockwell/Allen-Bradley PLC hosts globally, 74.6% of them in the United States, most reachable via cellular modems.
- The attackers use legitimate vendor engineering software rather than zero-day exploits — a “living off the land” approach that makes intrusion harder to detect.
- Internet-wide scanning is a defensive tool first: it gives defenders the same visibility attackers already have, so exposed devices can be found and secured.
What are the Iran cyber attacks on critical infrastructure?
Iran-linked cyber operations against critical infrastructure are not new, but 2026 brought them to a new level of visibility. On April 7, 2026, the FBI, CISA, the NSA, the EPA, the Department of Energy, and U.S. Cyber Command jointly disclosed ongoing exploitation of internet-facing Rockwell Automation/Allen-Bradley programmable logic controllers by Iranian-affiliated advanced persistent threat (APT) actors, in an advisory designated AA26-097A.
Programmable logic controllers are the small industrial computers that run physical systems: pumps, valves, power distribution, chemical dosing. The advisory documented Iranian-affiliated activity that disrupted PLCs across multiple U.S. critical infrastructure sectors — water and wastewater systems, energy, and government services and facilities — by downloading malicious project files and manipulating data shown on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays. Several operators lost control of their systems entirely when attackers changed device passwords and IP addresses, or disabled the alarms that would have warned them something was wrong.
On July 22, 2026, the agencies updated the advisory with new detection guidance and a wider manufacturer scope, adding Schneider Electric Modicon and Siemens controllers after observing targeting beyond Rockwell devices. The updated guidance stressed that owners and operators should restrict direct internet access to these devices and treat any internet-facing PLC as a likely target.
CISA has consistently warned critical infrastructure stakeholders that Iranian-affiliated threat actors are conducting a range of targeted cyber activity to include compromise unsecure internet-connected accounts and devices. — CISA Acting Executive Assistant Director for Cybersecurity Chris Butera
The 2026 campaign has a clear predecessor. In December 2023, CISA issued advisory AA23-335A documenting the CyberAv3ngers group — attributed to Iran’s Islamic Revolutionary Guard Corps Cyber Electronic Command (IRGC-CEC) — compromising at least 75 Unitronics Vision Series PLCs between November 2023 and January 2024, 34 of them in U.S. water and wastewater facilities. The targets were internet-exposed devices left on default passwords. Private-sector researchers report the 2026 activity bears the same group’s hallmarks, tracked under aliases including Shahid Kaveh Group, Storm-0784, Bauxite, and UNC5691, though U.S. agencies have not formally attributed the 2026 incidents to a named group.
What does the Censys Iran cyber attacks data tell defenders?
Within a day of the April 7 advisory, Censys published its own research measuring the attack surface the agencies were describing. Using internet-wide scanning — the same technique our explainer on Censys Inspect describes in detail — Censys identified 5,219 internet-exposed hosts globally responding to EtherNet/IP on port 44818 and self-identifying as Rockwell Automation/Allen-Bradley devices.
The geographic distribution was heavily skewed toward the United States, which accounted for 74.6% of global exposure — 3,891 hosts — consistent with Rockwell’s dominant position in North American industrial automation. Spain (110 hosts), Taiwan (78), and Italy (73) showed the next largest concentrations. A disproportionate share of the exposed devices sat on cellular carrier ASNs, indicating field-deployed equipment — pump stations, substations, municipal facilities — whose only internet path is a cellular modem. Some devices were reachable through Starlink satellite terminals, which researchers said makes them even harder to monitor and patch. Nearly half of the global devices were tied to a single U.S. carrier’s wireless network, and most were running outdated software.
Censys also improved on the government’s own indicators. Pivoting from the seven 185.82.73.x IP addresses CISA published, Censys researchers found they represented a single multi-homed Windows engineering workstation running the full Rockwell toolchain — and identified four additional operator IPs on the same host that the advisory had missed. This is the defensive value of internet-wide scan data in miniature: faster, wider visibility into both the attack surface and the attackers’ infrastructure than official channels can publish alone. For more on how researchers map exposed infrastructure during conflicts, see Cyber Warfare Research: Using Internet Scan Data (2026).

How do Iranian-affiliated actors get into PLCs?
The surprising answer is that they barely need to “get in” at all. The campaign’s most notable feature is its reliance on legitimate vendor engineering software — Rockwell’s Studio 5000 Logix Designer — used to connect directly to internet-facing PLCs. With no exploit required and no custom malware to detect, the attackers blend into the same workflows that legitimate engineers use. Security researchers describe this as a shift toward “living off the land” techniques in operational technology environments: native tools used for malicious ends, much harder to distinguish from routine maintenance than a malware infection would be.
The entry point is exposure itself. These devices sit directly on the public internet, reachable from anywhere, because they were deployed with cellular modems for remote access and never placed behind a firewall. In many cases, authentication was weak or absent — default credentials, or none at all. Once connected, the attackers manipulate project files and HMI/SCADA display data, change device configurations, and in some cases turn off critical alarms so PLCs fail without notifying operators. The technique mirrors the Unitronics attacks of 2023, where default passwords were the entire attack chain.
This is why the CISA mitigation guidance centers on a simple principle: disconnect PLCs from the internet where possible, or place them behind firewalls with strict access controls. No exotic defense is required — the exposure is the vulnerability.
What happened in the July 2026 water system attacks?
The campaign intensified sharply in the summer of 2026. On July 26 and 27, more than 30 community water systems across Minnesota experienced disruptions in what state officials described as a coordinated cyberattack on industrial control equipment. Operators were locked out of controllers, passwords were changed, and devices were knocked offline. The attacks forced manual operations and precautionary boil-water notices. CISA later disclosed that more than 100 internet-exposed water and wastewater systems were targeted in July alone across at least a dozen states — Minnesota, Michigan, Georgia, South Dakota, and New Jersey among them — predominantly small, rural utilities. It was the first time federal officials quantified the campaign’s monthly scope.
A July 27 incident at a pump station in Clayton County, Georgia, briefly cut water pressure for customers in the area and triggered a boil-water advisory. On July 30, the FBI and EPA warned that hackers were targeting PLCs from Rockwell Automation, Schneider Electric, and Siemens. Private-sector analysts quickly linked the activity to the same Iranian-affiliated campaign documented in AA26-097A.
Attribution for the summer attacks remains officially unconfirmed. Federal investigators examined whether Iranian-linked hackers were involved, and outlets including the New York Times reported that analysts viewed Iranian hackers as the likely source — while emphasizing that the assessment was preliminary and could change as forensic work matured. Third-party researchers corroborated the assessment, saying the techniques and target selection bore the hallmarks of CyberAv3ngers. A July 30 FBI/CISA advisory on PLC targeting did not name a suspected culprit, comparing the activity only to opportunistic disruptions previously associated with the IRGC-affiliated group.
Reporting in early September indicated the campaign had widened beyond water to telecommunications networks and energy providers. And in August, CISA noted attackers were using artificial intelligence to ease their attacks on Siemens equipment — an early sign of AI accelerating an already opportunistic campaign. A separate reported incident — a four-day shutdown at a British power plant attributed by private researchers to Iran-backed hackers — underscores the global reach, though its attribution is also unofficial. One important distinction: the August breach of Kansas PLC maker Micro-Comm, claimed by the profit-motivated ransomware group Barracuda, was confirmed by the FBI and the company but was not part of the Iranian-affiliated campaign.
For context on how this fits into the wider Israel-Iran cyber confrontation, see Israel-Iran Cyber War: What Internet Intelligence Shows, and for the playbook researchers use to investigate such incidents, see How Internet Intelligence Helps Investigate Cyber Attacks.

How defenders can use scan data against exposed infrastructure
The most encouraging lesson from the Censys research is that internet-wide scanning favors the defense. Attackers already map exposed infrastructure this way — scan data simply gives defenders the same picture, faster and cheaper. A utility that can query a current scan index for its own PLCs learns what is exposed in seconds, instead of discovering it during incident response.
Practical steps flow directly from the data. First, inventory exposed OT devices using scan data and confirm which ones are truly reachable from the public internet. Second, disconnect or firewall them: the Censys findings show most exposed PLCs sit on cellular or satellite paths that were never meant to be directly internet-facing, so placing them behind a firewall or VPN closes the main entry point. Third, patch and change default credentials — the 2023 Unitronics attacks needed nothing more than factory passwords. Fourth, monitor logs and OT ports for suspicious traffic, especially from overseas hosting providers, and check HMI/SCADA displays and PLC project files against known-good baselines, since the attackers manipulate both.
Our earlier coverage of internet scanning and exposed infrastructure in conflict zones explains the broader methodology, and Censys and Critical Infrastructure: Finding Exposed Systems covers the critical infrastructure exposure problem in depth. Researchers tracing adversary tooling, meanwhile, will find Tracking Adversary Infrastructure With Censys Data relevant.
Frequently asked questions
Did Censys participate in the Iran cyber attacks?
No. Censys is a threat intelligence company whose research measured the exposed devices that attackers targeted. It published the 5,219-device figure and pivoting analysis as defensive research, and urged operators to secure or disconnect their PLCs. There is no evidence or claim that Censys participated in any attack.
Which countries were targeted by the Iranian-affiliated PLC campaign?
U.S. agencies documented targeting of American critical infrastructure — water and wastewater systems, energy, and government services — in advisory AA26-097A. Censys data showed exposed Rockwell PLCs worldwide, including Spain, Taiwan, and Italy, but exposure is not the same as targeting. Private researchers have also linked Iran-backed actors to incidents such as a UK power plant shutdown, though that attribution is unofficial.
How can I tell if my organization’s PLCs are exposed?
Search internet-wide scan datasets for your organization’s IP ranges and look for industrial protocols such as EtherNet/IP (port 44818), Modbus, or Siemens S7 services reachable from the public internet. Check whether devices sit on cellular modems with direct internet access rather than behind a firewall or VPN, and verify that default credentials have been changed.
Has the U.S. formally attributed the 2026 water attacks to Iran?
As of this writing, no U.S. agency has formally attributed the July 2026 water-system incidents to a named group. Federal advisories describe the actors as “Iranian-affiliated,” and private-sector researchers assess the activity as bearing the hallmarks of CyberAv3ngers, an IRGC-CEC-linked group. Federal investigators have examined Iranian links, but attribution statements from officials remain qualified as preliminary.
What should utilities do first to defend against this campaign?
Remove direct internet access to PLCs — disconnect them or put them behind a firewall with strict access controls. Then change all default credentials, patch outdated firmware, scan logs for indicators of compromise, and verify HMI/SCADA displays and project files against known-good baselines. Follow the mitigation guidance in the updated AA26-097A advisory.
Conclusion
The 2026 PLC campaign is a case study in how modern cyber conflict works: not through sophisticated zero-day weapons, but through the mundane exposure of everyday industrial equipment on the public internet. Iranian-affiliated actors understood this, and for months they worked through exposed controllers with vendor software and default credentials — confirmed by U.S. agencies across AA26-097A and its July update.
Censys’s research did not stop the attacks, but it did something nearly as important: it measured the battlefield. With 5,219 exposed devices mapped and attacker infrastructure pivoted from the official indicators, defenders got a clear inventory of what needed fixing. The tools that found the exposure are the same ones that can close it. For operators of critical infrastructure, the message is simple and urgent: find your internet-facing PLCs and get them behind a firewall before someone else finds them for you.
Sources and Further Reading
- CISA — “CISA, FBI, EPA and U.S. Government Partners Update Warning of Iran-Affiliated Threat Actors Targeting Critical Infrastructure Programmable Logic Controllers” — cisa.gov
- Censys — “Iranian-Affiliated APT Targeting of Rockwell/Allen-Bradley PLCs” — censys.com
- Reuters — “Hack of water sector supplier draws FBI scrutiny as Iran-linked cyber concerns grow” (Aug 26, 2026) — reuters.com
- Cybersecurity Dive — “Nearly 4K industrial control devices vulnerable to Iran-linked hacking campaign” — cybersecuritydive.com
- Industrial Cyber — “US agencies update advisory on Iranian cyber campaign targeting internet-connected PLCs” — industrialcyber.co
- Kharon — “Iran’s Attacks on U.S. Water Systems Look Less Like a New Terror Front and More Like a Psyop” — kharon.com
- Cybersecurity News — “Censys Warns 5,219 Rockwell/Allen-Bradley PLCs Are Exposed Amid Iranian APT Activity” — cybersecuritynews.com