Iranian Hackers Are Inside American Factories Right Now. Here's What Every Business Leader Must Know.
The FBI and CISA issued an urgent joint advisory July 22, 2026: Iranian-affiliated hackers are actively hacking internet-connected industrial control systems across U.S. critical infrastructure. Here's what it means for your business.
Yesterday, the FBI, CISA, NSA, and four other federal agencies issued an urgent joint advisory. The headline: Iranian-affiliated hackers are actively targeting internet-connected industrial control systems across multiple U.S. critical infrastructure sectors — and they've been doing it successfully.
This isn't a theoretical warning. These attacks have already caused operational disruption and financial loss. Real factories. Real operations. Real consequences.
If your business touches manufacturing, utilities, water treatment, energy, food production, or any other sector that relies on operational technology — this advisory is directly about you.
What's Actually Happening
Iranian-affiliated APT (Advanced Persistent Threat) actors — specifically a group tracked as Cyber Av3ngers, also known as Storm-0784 — have been systematically targeting programmable logic controllers (PLCs) that are directly exposed to the internet.
If that sounds technical, here's the plain-English version: a PLC is the computer that controls physical machinery. It tells a pump when to run, a valve when to open, a conveyor belt when to stop. When an attacker gets inside a PLC, they don't just steal data — they can physically disrupt operations.
The July 22 advisory update expanded the scope significantly. Originally focused on Rockwell Automation equipment, the advisory now confirms active targeting of Schneider Electric and Siemens PLCs as well — two of the most widely deployed industrial control brands on the planet. Virtually every major industrial facility in America uses at least one of these three manufacturers.
The attack method is straightforward and ruthless: the hackers use the manufacturers' own legitimate programming software to connect to misconfigured devices that are directly reachable via the internet. No sophisticated zero-day exploit required. They just log in — because the door was left open.
Why This Is a Business Problem, Not Just an IT Problem
Here's the framing that matters: when these hackers get in, they don't go after your accounting system or your email. They go after the systems that make your business physically function.
Think about what a multi-day operational shutdown costs your organization. Not just in lost revenue — in spoiled inventory, customer penalties, emergency response costs, regulatory scrutiny, and reputational damage. The attacks documented in the advisory caused exactly this type of disruption.
And unlike a data breach, you can't restore operations by resetting passwords. Physical processes may need manual inspection, equipment verification, and careful restart procedures to ensure machinery hasn't been tampered with in dangerous ways.
The advisory notes that attackers manipulated data displayed on HMI (Human Machine Interface) screens — the dashboards your operators watch to understand what's happening on the plant floor. If an operator is seeing fabricated data, they may not know a system is operating unsafely until something fails.
Who Is Actually at Risk
Let me be specific about the exposure profile. If your organization:
- Uses Rockwell Automation, Schneider Electric, or Siemens PLCs - Has those PLCs connected to the internet directly (not behind a secure gateway) - Hasn't changed default passwords or authentication settings on those devices - Relies on a managed service provider or OT vendor for remote monitoring
...you need to act this week, not next quarter.
The advisory specifically notes that 5,600 Rockwell Automation or Allen-Bradley SCADA devices are currently visible on the internet globally. Visible means reachable. Reachable means targetable.
Small and mid-size manufacturers are particularly exposed here. Large enterprises often have dedicated OT security teams. Smaller operations frequently have their PLCs installed and maintained by an integrator who set up remote access years ago — and no one has reviewed that configuration since.
Three Questions for Every Business Leader
1. Do you know which of your operational systems are internet-connected?
Most business leaders don't have a clear answer to this. The OT environment — the operational technology that runs physical processes — often exists in a separate silo from the IT environment that your security team manages. Legacy systems get connected for remote monitoring convenience, and no one ever revisits whether that connection is secure. This week, ask your IT and operations teams to map every device that has any internet connectivity, including through third-party vendors.
2. Who has remote access to your operational systems, and when did you last audit it?
The Iranian-affiliated actors in this advisory used legitimate remote access methods — the same tools your vendors use for remote maintenance. If your equipment vendor has remote access to your PLCs, that access needs the same scrutiny as any other privileged connection: least-privilege access, multi-factor authentication, and session logging. Ask your vendor today: how is remote access to our systems protected?
3. What is your operational continuity plan if your control systems are compromised?
Most businesses have disaster recovery plans for data systems. Far fewer have tested their ability to operate manually if control systems fail or are compromised. For critical processes, you need documented manual procedures, clear escalation paths, and a tested playbook for what happens when the system can't be trusted. If you don't have this, start building it.
What the Advisory Recommends — Right Now
The joint advisory from FBI, CISA, and NSA has specific immediate actions. The most critical:
- Disconnect PLCs from direct internet exposure. Route any remote access through a secure gateway or jump host that brokers and logs all connections. - Place physical mode switches on controllers into run position to prevent remote modification. - Review PLC project files for unauthorized changes — especially reusable code modules and input/output configurations. - Change all default passwords and disable unused services (Telnet, FTP, RDP, VNC). - Notify your managed service providers and OT vendors of the active threat and confirm they've reviewed their access to your systems.
These aren't complex security measures. They're fundamentals that should have been in place already. But in the rush to connect operational systems for monitoring convenience, they frequently weren't.
The Bigger Picture
This advisory sits inside a broader pattern: nation-state cyber actors have identified operational technology as high-value, lower-security terrain. While enterprise IT has hardened significantly over the past decade — MFA, EDR, zero trust architectures, cloud security controls — OT environments often haven't kept pace. They run older operating systems, use proprietary protocols, and prioritize uptime over security patching.
That gap is now being actively exploited.
For business leaders in industrial, manufacturing, utilities, and critical infrastructure sectors, this is the moment to close it. Not because regulators are watching — though CISA and the EPA are increasingly focused on OT security requirements. But because your operations, your employees, and your customers depend on these systems working correctly.
TrustPoint Cyber helps businesses assess and secure operational technology environments — including mapping internet-connected OT exposure, reviewing vendor access, and building OT-specific incident response plans. If this advisory raised concerns about your environment, let's talk. A conversation costs nothing. A breach costs everything.
Ready to strengthen your security?
TrustPoint Cyber delivers Zero Trust architecture, incident response, managed security, and vCISO services — built for your business.