-
The FBI says Iran-affiliated cyber actors continue targeting PLCs used across U.S. critical infrastructure.
-
The updated warning now covers equipment from Rockwell Automation, Schneider Electric, Siemens, and other makers.
-
U.S. cybersecurity officials urge organizations to remove direct internet access and watch for harmful changes.

Iran-affiliated cyber actors continue to target operational technology systems across the United States, the FBI says. These systems help run important services and physical processes. The FBI Cyber Division said the activity has affected several U.S. critical infrastructure sectors.
The attacks involved PLC project files and data shown through HMI and SCADA systems. PLCs, or programmable logic controllers, help control machines and industrial processes. Many critical services depend on these systems to operate safely and properly.
The FBI’s latest warning updates guidance that the agency and its partners issued in April. The new advisory also expands the types of PLCs that attackers have targeted. The warning now includes equipment made by Rockwell Automation, Schneider Electric, Siemens, and other manufacturers. Earlier guidance focused mainly on Rockwell Automation and Allen-Bradley PLCs.
FBI Expands Warning Over PLC Attacks
The updated advisory says investigators found new ways to spot harmful changes inside reusable code modules. These modules can form part of PLC programs used to control industrial systems. The earlier U.S. government warning said Iran-affiliated advanced persistent threat actors targeted OT devices that faced the public internet. The FBI’s expanded guidance reflects the ongoing threat from Iran-linked hackers targeting critical infrastructure.
Rockwell Automation and Allen-Bradley PLCs received particular attention in that warning. In some reported cases, attackers interacted with PLC project files and changed information shown through HMI or SCADA systems. These actions reportedly caused operational problems and financial losses for affected organizations.
The FBI’s warning covers systems used across areas such as energy, water, wastewater, manufacturing, and government facilities. An attack against these systems can affect both computer networks and physical operations. The agency and its partners have repeatedly warned organizations about exposing OT systems directly to the internet.
The updated guidance again urges operators to limit that exposure. Organizations should also use stronger security controls around industrial systems. They should monitor PLC programs and look for changes that attackers did not authorize. The warning does not announce one new cyberattack. Instead, it expands existing guidance about a threat that U.S. officials continue to track.
Social Media Users React to the Warning
The FBI’s warning also sparked reactions on X, where some users focused on the wider U.S.-Iran conflict. One user, posting as Murder Hornets or Monkey Pox, responded sarcastically to the warning.
The user questioned how Iranian cyber operations could continue after claims that U.S. actions had badly damaged Iran’s military strength. Another user, The Vanguard, wrote, “I thought Trump already destroyed Iran though,” showing doubt about continued Iranian activity after U.S. military actions.
Other posts included unrelated allegations and conspiracy claims. Those comments have not been independently verified and do not appear connected to the FBI’s technical findings. The FBI’s warning instead focuses on the security of industrial control systems.
These systems can directly control physical processes and support services that people rely on. The wider range of PLC manufacturers named in the update means organizations should not focus on only one brand. The FBI’s guidance points to a broader concern involving industrial systems from several vendors.
Officials Urge Organizations to Secure Industrial Systems
The latest warning reinforces the need for critical infrastructure operators to review their OT security. Organizations should avoid unnecessary direct internet access to industrial systems. They should also monitor PLC programs for unauthorized changes and protect computers used by engineers. Operators should review their systems for signs of compromise. They should also strengthen controls around industrial networks and limit access where possible.
The FBI’s updated guidance shows that Iran-affiliated cyber actors remain a concern for U.S. critical infrastructure. The activity involves systems that support important services and control physical operations. The warning also shows why organizations need to pay close attention to their industrial environments.
Attackers who gain access to PLC systems may affect more than digital information. For now, the FBI’s message remains focused on awareness and protection. The agency has expanded its warning as investigators identified new targeting methods and additional PLC manufacturers.
The updated advisory, therefore, serves as a reminder for critical infrastructure operators to review their defenses. It also urges them to reduce unnecessary internet exposure and watch closely for unauthorized changes.