Back to Blog
Cybersecurity April 10, 2026 5 min read

CISA Joint Advisory: Iran-Linked IRGC Hackers Targeting U.S. Power and Water Networks via Exposed PLCs

The FBI, CISA, NSA, and four other agencies issued advisory AA26-097A after Iranian IRGC-affiliated actors disrupted U.S. energy and water infrastructure through internet-exposed Rockwell PLCs. No CVE involved — attackers abused default credentials.

CISA Joint Advisory: Iran-Linked IRGC Hackers Targeting U.S. Power and Water Networks via Exposed PLCs

Six U.S. agencies issued a joint cybersecurity advisory on April 7, 2026 warning that Iranian-affiliated actors have been disrupting energy, water, and government operations by exploiting internet-exposed industrial control systems — and there is no CVE to patch.

The actors, linked to the IRGC and tracked as CyberAv3ngers (also called Storm-0784 and Hydro Kitten), have been active since at least March 2026. Their method is blunt: find Rockwell Automation Allen-Bradley PLCs exposed to the internet, log in using default or weak credentials, then use Rockwell’s own Studio 5000 Logix Designer software to manipulate HMI displays and disrupt operations. Several victims reported operational outages and financial losses.

The advisory — CISA AA26-097A — was signed by the FBI, CISA, NSA, EPA, DOE, and U.S. Cyber Command. It is one of the broadest multi-agency ICS warnings since the 2021 Oldsmar water treatment plant attack.

Why this is different from a typical CVE

There is no vulnerability to patch. Allen-Bradley PLCs do exactly what they are designed to do — accept network connections and execute commands. The problem is that thousands of these devices are reachable on the public internet with factory-default credentials still in place. CyberAv3ngers are not running sophisticated exploits; they are walking through unlocked doors.

This is a credential and architecture problem. Studio 5000 Logix Designer, the legitimate engineering workstation software, was used to modify logic and display values on HMI panels — the same interface operators use to monitor pumps, valves, and turbines. From the PLC’s perspective, the attacker looked like a legitimate engineer.

Affected sectors

The advisory specifically names U.S. energy (electric utilities, oil and gas), water and wastewater, and federal government networks. The geographic spread has not been disclosed, but CISA language indicates multiple victims across more than one sector.

Immediate actions from the advisory

  • Take all internet-exposed PLCs offline or place them behind a VPN with MFA
  • Change all default credentials on Allen-Bradley and other OT devices immediately
  • Apply the principle of least privilege to all engineering workstation accounts
  • Enable audit logging on PLCs where the firmware supports it
  • Segment OT from IT networks and enforce strict firewall rules

Attribution

CyberAv3ngers have a documented history of targeting Western critical infrastructure. In late 2023 they compromised Unitronics PLCs at U.S. water facilities in Pennsylvania and claimed attacks on Israeli infrastructure. The group consistently operates below the threshold that would trigger a direct military response, making disruption their preferred outcome rather than destruction.

This advisory is notable for its scope. Six agencies coordinating on a single OT threat disclosure is rare. If your organization runs Allen-Bradley hardware on a routable network segment — even on a private WAN — audit it today. The advisory is available at cisa.gov/news-events/cybersecurity-advisories/aa26-097a.

cybersecurity ICS SCADA CISA critical infrastructure