Federal cybersecurity agencies including CISA, the FBI, and NSA have issued an urgent advisory warning that threat actors are actively targeting internet-connected programmable logic controllers (PLCs) across U.S. critical infrastructure. This activity has already caused operational disruptions and financial losses for organizations in the government services, water/wastewater, and energy sectors.
Click here to view the official CISA advisory.
What’s happening: Iranian-affiliated threat actors are exploiting internet-exposed PLCs from major manufacturers, including Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens, by accessing devices that lack sufficient network protections. Once inside, they’ve been able to alter project files, manipulate what operators see on HMI and SCADA displays, and in some cases disable critical safety and alarm functions.
Why it matters: If your organization relies on PLCs, HMIs, or SCADA systems as part of its industrial automation, regardless of manufacturer, this advisory applies to you. The threat is opportunistic, meaning any misconfigured, internet-facing device is a potential target.
What you can do now: The advisory recommends several immediate steps, including:
- Removing direct internet access to PLCs and routing remote connections through a secure gateway
- Monitoring modem and device logs for suspicious activity
- Reviewing project files for unauthorized changes
- Enforcing multi-factor authentication for any remote access to OT networks
- Keeping devices patched with the latest manufacturer updates
Turtle is committed to helping our customers and partners navigate evolving cybersecurity risks as part of a secure, resilient automation and controls strategy. If you have questions about how this advisory may affect your systems or want guidance on hardening your OT environment, our team is here to help.