Background
Since the start of the US-Iran war in February 2026, there has been much concern and speculation over possible cyber components of the US-Iran conflict. Much of the noted activity linked to Iranian entities has fallen under “hacktivist” personas. In nearly all cases the activity has been directly tied to or controlled by elements of the Iranian state, with relatively little impact aside from a few notable successes.
Separate from the hacktivist “noise” was a warning from US Cybersecurity and Infrastructure Security (CISA) on Iranian actors operating under the name CyberAv3ngers. This group is effectively an entity under the IRGC Cyber-Electronic Command (CEC), targeting internet-exposed programmable logic controllers (PLCs). CISA published their initial report in early April 2026, with indications the activity may have preceded the conflict into 2025.
The initial CISA advisory only identified exploitation of Rockwell Automation/Allen-Bradley PLCs, specifically devices such as CompactLogix and Micro850. Interestingly, CISA added CVE-2021-22681, an authentication bypass vulnerability impacting CompactLogix devices along with other Logix-based controllers, to its known exploited vulnerabilities (KEV) list in early March 2026. While CISA and other entities have not definitively stated that IRGC CEC entities leveraged CVE-2021-22681 in observed intrusions, the correlation of events is interesting to note, given the vulnerability’s potential utility in accessing exposed devices.
Campaign victims included entities in industries such as water and wastewater, energy, and government facilities, and impact included operational disruption although no specific examples were provided. Notable in the report, CISA identified network activity targeting various ports associated with products other than Rockwell devices, but did not indicate malicious activity extended to additional devices at the time.
July Update
CISA updated their advisory in late July 2026. This update included two critical updates: first, the potential targeting of other vendor PLCs was confirmed. Second, and arguably most concerning, was extension of activity beyond simple process disruption to process and potentially even safety manipulation.
The July update notes the following devices were also observed as victims in the ongoing IRGC CEC campaign:
- Schneider Electric BMX P34/Midocon M340 PLCs
- Siemens S7-1200 series PLCs
The specifics as to how these devices were accessed were not provided, similar to the earlier reporting on Rockwell devices. However, it is worth noting that the Schneider Electric devices also feature an authentication bypass vulnerability, CVE-2021-22779 (also referred to as “ModiPwn”), while the Siemens SIMATIC family features a hard-coded key vulnerability, CVE-2022-38465. Neither is listed in CISA’s KEV at the time of publishing, but the possibility exists that these vulnerabilities or similar ones could have been leveraged to access internet-accessible devices.
While the contents of the update represent an expansion in scope for the IRGC CEC campaign, CISA also notes an extension in depth as well. Particularly, the campaign is now known to include not just operational disruption, but the retrieval of project files from impacted devices and, more concerning still, the upload of malicious project files to compromised PLCs. The last point is especially concerning as this activity can lead to loss of process integrity, reduction in process safety, and potentially even process or equipment destruction. As explicitly stated by CISA:
“Analysis indicated the project file retained ladder logic for downstream function but added logic that overrode specific instruction sets responsible for maintaining safe operating parameters in the victim’s environment.”
Update Implications
CISA’s updated reporting shows a worrying expansion in Iran-linked critical infrastructure targeting focused on the United States. Initial reporting was concerning enough between the combination of critical infrastructure targets and documented, if not publicly specific, process disruption. Extending this activity to encompass additional equipment lines and pairing this with process manipulation and safety degradation makes matters more concerning as it enables various physical impact scenarios.
To date, the only publicly known instances of OT-specific process protection and process safety targeting are the 2016 Ukraine power incident and the 2017 Saudi Arabia petrochemical attack, respectively. In both these cases, all evidence indicates the attacks failed in their ambition, but each represented concerning escalations in process targeting for critical infrastructure.
The two historical events in question were both linked to Russian state entities. Expansion of such targeting objectives to Iranian-linked entities represents worrying proliferation in the most concerning type of OT system attack: compromise of system integrity. The reason for this is that loss of integrity for OT systems can lead not just to physical process disruption but also physical damage and potentially even loss of life within impacted facilities when safety parameters are manipulated.
Conclusions
While most of the cyber activity surrounding the 2026 US-Iran war has been hacktivist nuisance or noise, the activity documented by CISA represents a real and concerning threat to critical infrastructure operations. Based on available information, no physically destructive attacks have been publicly identified at this time. Furthermore, historical incidents demonstrate how difficult it is to actually succeed with these types of integrity or safety-oriented attacks. However, the mere fact that these types of intrusions are taking place represents a clear escalation in cyber targeting of civilian infrastructure as part of the US-Iran conflict.
Defensive Responses
While concerning, defensive responses to the identified tradecraft deployed is straightforward and quite effective.
First and foremost, critical systems and assets, such as PLCs, should never, under any circumstances, be directly accessible to the open internet. If remote access is necessary, compensating controls and architectural design MUST be used, such as VPNs or jump hosts, to ensure that sensitive OT devices cannot be directly reached or accessed.
Second, while CISA’s reporting does not specifically link identified activity to exploitation of known vulnerabilities, each affected product line features historical authentication bypass items that could be used to facilitate compromise for accessible devices. While patching cycles in critical infrastructure are different from enterprise IT environments for various reasons, organizations must nonetheless apply critical patches (such as for the vulnerabilities noted in this report) at the first available opportunity, and apply compensating controls and monitoring in the interim.
Third, always change authentication material on devices from system or factory defaults when possible. The use of default passwords and similar is widely exploited by various threat actors, and represents a non-exploitation route to devices such as those listed in this advisory.
Fourth, capture and periodically evaluate critical ladder logic, such as for process protection and safety, to identify potential unexplained or malicious modifications. While this is difficult, this is a necessary step that should be paired with keeping devices in “run” mode (i.e., not allowing for update, typically via a physical switch) to ensure that known valid, known good logic is running on devices.
Admittedly, the latter two recommendations are not always easy (and for smaller organizations and certain devices, may not even be possible). However, the first two controls of access limitation and timely patching are necessary steps in critical infrastructure defense that must be taken by all asset owners and operators in an increasingly hostile networking environment.

Read the 2026 Cyber Threat Landscape Report
In a time of increasing cyber threats and AI-driven attacks, security teams need actionable insights to drive a preemptive cyberdefense strategy. This report analyzes global risks and offers the intelligence needed for a proactive cybersecurity strategy.
Download Report