Saturday, 25 July 2026

iberempresa

IBEX 3519.585,40 +1,65%EuroStoxx 506280,94 +1,14%S&P 5007411,98 +0,05%€/$1,1375 -0,06%Brent96,78 -3,88%Bitcoin56.274 -0,12%
Breaking

Iranian hackers attack water and energy PLCs in the U.S. since March

Since March 2026, IRGC hackers have compromised PLCs in U.S. water and energy infrastructures, causing operational disruptions and financial losses.

Beatriz Lorenzo AguirreBeatriz Lorenzo Aguirre· · 4 min read

Since March 2026, hackers from the Islamic Revolutionary Guard Corps (IRGC) have compromised industrial controllers in water and energy facilities in the United States, causing operational disruptions and financial losses, according to the FBI, NSA, CISA, and the Department of Energy.

A campaign of cyberattacks attributed to the Islamic Revolutionary Guard Corps of Iran (IRGC) has been compromising programmable logic controllers (PLCs) in critical infrastructure in the United States since March 2026, according to a joint alert from the FBI, NSA, CISA, and the Department of Energy updated in July.

The attacks, carried out by a group known as CyberAv3ngers, have caused operational disruptions and financial losses in drinking water, wastewater, and power generation facilities. The alert expands the initial scope: it now affects not only Rockwell Automation equipment but also products from Schneider Electric and Siemens, putting virtually any industrial control system (ICS) exposed to the Internet at risk.

For tech startups developing industrial IoT, automation, or cybersecurity solutions, this scenario represents both a threat and a critical market opportunity. The security of OT (Operational Technology) environments has become a strategic priority.

Attack methods: basic but devastating vulnerabilities

The attackers are exploiting basic configuration flaws. According to security agencies, entry vectors include default credentials that were never changed on the PLCs, ports directly exposed to the Internet without VPN or multi-factor authentication, remote access without segmentation between IT and OT networks, and legacy configurations that do not follow manufacturers' hardening guidelines.

The campaign does not seek traditional espionage or data theft. The stated goal is operational disruption: to cause shutdowns in physical processes, degrade control systems, and generate significant recovery costs. This represents a paradigm shift from previous cyberattacks, which focused on espionage or extortion.

According to TechCrunch, the updated government advisory in July 2026 confirms that the activity had already been underway since March and has caused measurable disruptive effects across multiple sectors of critical infrastructure.

Specific systems under attack

The compromised equipment includes PLCs from Rockwell Automation, controllers and HMIs from Schneider Electric, Siemens industrial automation systems, and any ICS exposed to the Internet with vulnerable configurations. The affected facilities supply drinking water, wastewater, power generation and distribution, and in some reports, also government facilities with industrial control systems.

Wired en español contextualizes that these attacks occur within a framework of rising geopolitical tension, where cyber responses become a tool of pressure without direct military escalation.

Economic impact: no official figures

U.S. agencies confirm financial losses and operational disruptions, but have not published specific figures regarding the exact number of compromised facilities, the aggregate cost of the disruptions, the volume of exfiltrated data (when applicable), or the average recovery time. This opacity is intentional: disclosing operational details could help attackers refine their methods or identify additional uncompromised targets.

What is documented is the attack pattern: initial access through weak credentials, lateral movement in poorly segmented OT networks, and execution of commands that alter physical processes such as valves, pumps, and switches.

Background: an evolving threat

This campaign is not isolated. Verifiable background includes prior U.S. alerts in 2024 regarding IRGC activity against water infrastructure, with specific pressure on water and sanitation companies. In December 2023, CyberAv3ngers publicly claimed responsibility for attacks on supply systems in multiple states. In March 2024, the Secretary of Homeland Security and the FBI Director warned about 'the drought war', pointing to Chinese and Iranian hackers as key actors against water companies.

The evolutionary pattern is clear: from passive espionage to active sabotage, from government targets to private providers of essential services, from exploiting zero-day vulnerabilities to abusing negligent configurations.

For Spanish companies with critical infrastructure or industrial control systems, this campaign underscores the urgent need to audit and harden their OT environments. Recommended measures include changing all default credentials, segmenting IT and OT networks, implementing multi-factor authentication, and applying manufacturers' security guidelines.

The joint alert urges operators of critical infrastructure to review their systems and report any signs of compromise to the authorities. Meanwhile, the cybersecurity community continues to monitor the evolution of this threat, which has already demonstrated its ability to cause physical and economic harm at the heart of the U.S. power and water networks.

Beatriz Lorenzo Aguirre

Written by

Beatriz Lorenzo Aguirre

Redactora

Periodismo económico por la Carlos III y lectora compulsiva de cuentas anuales. Cafés a destajo, alergia a las notas de prensa vacías y memoria para los ERE; en Iber Empresa escribe de empresas y empleo.