Iran-linked control system attacks widen to telecom
Iran-linked hackers rewriting exposed PLCs at US water and energy sites are now reported probing telecom. How the attack works and what to lock down.
By Yaali. September 28, 2026, 7 min read, Threat intel, Resilience.
On September 2, NBC News reported that Iranian hackers had targeted US telecommunications, energy and other infrastructure in recent weeks, not only the water systems already under attack. The report rests on four unnamed people with access to government and industry threat information. According to NBC, the attempts went after automated systems connected to the internet and had so far failed. That week, a Telegram channel calling itself APT IRAN threatened "unexpected and critical events in the energy, water, and telecommunications industries."
The official warning is joint advisory AA26-097A from CISA, the FBI, NSA, the EPA, the Department of Energy, US Cyber Command and the Treasury. It still lists government facilities, water and wastewater, and energy, and its last update was on July 22. So far telecom appears only in press reporting, and CISA has not added it. The warning applies to anyone who runs a programmable logic controller (PLC) that answers on the internet, because internet-exposed controllers are what this campaign goes after in every sector.

How it works
A PLC is a small, rugged computer bolted into a cabinet next to the equipment it runs. Many times a second it reads inputs (tank level, pressure, flow), runs its program and switches outputs: start a pump, close a valve, trip a breaker. Engineers write that program, called the logic, in the vendor's own software: Studio 5000 Logix Designer for Rockwell Automation (Allen-Bradley), EcoStruxure Control Expert for Schneider Electric, TIA Portal for Siemens. They then download it to the controller as a project file.
These controllers speak industrial protocols built for closed plant networks: EtherNet/IP on TCP 44818 and UDP 2222, Siemens S7comm on port 102, Modbus TCP on port 502. Anyone who reaches those ports can often read or replace the program. For Rockwell Logix controllers, CVE-2021-22681 (CVSS 9.8) makes even the built-in check weak: the key that Logix Designer uses to verify it is talking to a genuine controller can be discovered, so other software can authenticate. CISA added it to its Known Exploited Vulnerabilities (KEV) catalog on March 5, 2026.
The exposure usually comes from remote sites. A lift station or pump house far from the main plant gets a cellular modem with a public IP address so an integrator or on-call engineer can connect without driving out, often with no firewall between the controller and the internet. Censys counted 5,219 hosts answering EtherNet/IP on the internet on April 8, 3,891 of them in the US. It found 49.1% on Verizon Business address space and another 13.3% on AT&T Mobility, which points to field devices on cellular links. The attackers needed no zero-day. The advisory says they connected from leased hosting using the vendors' own programming software.
The human-machine interface (HMI) is the screen beside the process. SCADA (supervisory control and data acquisition) is the central system that gathers readings from every site. Both show what the PLC reports, so whoever controls the PLC controls the picture. The advisory says the actors modified and deleted project logic and changed the data on HMI and SCADA displays. In some cases they disabled shutdown and alarm logic, "allowing systems to enter unsafe conditions without notifying operators." An operator could watch a normal tank level on screen while the pump behind it runs dry.
The July update added a Rockwell-specific place to hide: Add-On Instructions (AOIs), the reusable code blocks a program calls in many places. A change to one AOI changes the behaviour everywhere it is used, so a reviewer who reads only the main routines will miss it.

What attackers are doing
In November 2023, CyberAv3ngers, a group tied to the Cyber-Electronic Command of Iran's Islamic Revolutionary Guard Corps, compromised at least 75 Unitronics PLCs, mostly at water utilities, and replaced their logic. The current campaign has run since at least March 2026. The April 7 advisory named Rockwell CompactLogix and Micro850 controllers and said that in a few cases the activity caused operational disruption and financial loss.
The July 22 update added Schneider Electric BMX P34 (Modicon M340) and Siemens S7-1200 controllers, with guidance on tampered AOIs. It also described Dropbear SSH installed on victim modems for remote access over port 22, and project files copied out through third-party hosted command-and-control infrastructure.
Water incidents spread over the summer. Cybersecurity Dive counted intrusions in at least 12 states by August 4, up from the seven the FBI had disclosed five days earlier, with more than 30 community water systems targeted in Minnesota alone. In Georgia, the Clayton County Water Authority issued a boil-water advisory after a pump station failed at about 1 a.m. on July 27. The utility is investigating whether unauthorized cyber activity on its PLCs caused or contributed to the failure. That link had not been confirmed when this post went out.
Every technique the advisory lists changes what equipment does or what operators see, which is why the agencies describe the intent as disruption. NBC's sources describe the telecom attempts as aimed at the same kind of internet-connected automated systems.
What to do
1. Find what is exposed. Scan your own public ranges from outside for TCP 22, 102, 502 and 44818 and UDP 2222, for example nmap -Pn -p T:22,102,502,44818,U:2222 -sU -sT <range>. Include every cellular modem: ask your carrier for the IP addresses behind your SIMs; they rarely appear in IT asset lists. Search Shodan or Censys for the same ranges, such as net:<your-range> port:44818.
2. Take it off the internet. Disconnecting the PLC from the public internet is the advisory's first step. Where remote access is needed, put it behind a VPN or firewall gateway with multifactor authentication (MFA). For cellular sites, the advisory suggests a private APN (a carrier network closed to the public internet) or zero trust network access. Put PLCs on their own OT network zone, and allow only named engineering workstations to reach their ports, with everything else denied by default.
3. Lock the controllers. On controllers with a physical key switch, set it to RUN, which blocks remote program changes. Turn on programming protection in the vendor software. On Siemens S7-1200, set an access level under Protection & Security in TIA Portal so writes need a password. Change every default password. CVE-2021-22681 has no single firmware fix across all affected Logix families, so for Rockwell the key switch and the network isolation in step 2 are the mitigation.
4. Check whether you were hit. Compare the running logic of every controller against an offline known-good backup using the vendor's compare tools, and look at each AOI separately. On Logix firmware v20 and later, change detection gives the controller an audit value that changes on every download or edit. FactoryTalk AssetCentre 4.1 or later can track it and read the Controller Log. Confirm that alarm and shutdown routines still exist. Search firewall and flow logs for inbound connections to the ports above from hosting providers and from the advisory's indicators, including 185.82.73[.]162 to .171 and 88.80.150[.]199 to .202. On modems, look for SSH on port 22 that you did not set up.
5. Do not trust the screen alone. Check critical values against something the PLC does not report: a local gauge, a separate flow meter or a manual reading. If they disagree, run the process by hand, restore logic from the offline backup, change the passwords on the controller, the modems and the engineering workstations, and report it to CISA or your local FBI field office.
Our attack surface management work finds the controllers and modems in your address space that answer from the internet, and our network penetration tests check whether someone who reaches your network can reach your controllers. Open the chat and Yaali, our AI agent, will pass your question to an engineer.
Sources: CISA: advisory AA26-097A, CISA: July 22 update announcement, NBC News, Iran International, Cybersecurity Dive: expanding target set, Cybersecurity Dive: water campaign, AFCEA Signal, Censys, The Record, Georgia Recorder, Atlanta News First, OpenCVE: CVE-2021-22681, Rockwell Automation: Logix 5000 controller information and status manual.
Read next
- Arizona courts breach puts protected addresses at risk
- How an Adif breach became a Renfe data leak
- Pentagon's DMDC breach: 9 months of hidden access
Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.