Iran Targets US Critical Infrastructure With PLC Cyberattacks Since March 2026
Iran's war with the US is going beyond normal warfare as they move towards cyber-attacks. As both countries engage in actual warfare, Iran is also reportedly working on cyber-attacks targeting critical infrastructure with a Programmable Logic Controller or PLC.
Attacks against PLCs "has been underway since at least March 2026 and relies on exposed or poorly secured operational technology," according to Cyber Security News. The objective of these attacks is to disrupt the processes and services of these important infrastructures. A compromised PLC might operate against the norm and cause problems with important public services such as energy and water.
The report has named the following PLCs were targeted:
● Rockwell CompactLogix
● Micro850 Controllers
● Schneider BMX P34 Systems
● Modicon M340 Systems
● Siemens S7-1200 Devices
The devices are relatively secure against various attacks. However, weaker login protocols and credentials have left these devices exposed. Exposed PLCs are another concern. Without added protection, such as a firewall or VPN, they can be easy targets for hackers.
The following IP addresses were associated with the exploit:
● 185.82.73.175
● 141.11.164.153
● 175.110.121.42
● 175.110.121.39
● 175.110.121.41
● 175.110.121.107
● 192.142.54.79
● 84.200.205.165
● 185.225.17.225
● 79.133.46.209
● 88.80.150.199
● 88.80.150.200
● 88.80.150.202
● 185.82.73.162
● 185.82.73.164
● 185.82.73.165
● 185.82.73.167
● 185.82.73.168
● 185.82.73.170
● 185.82.73.171
● 135.136.1.133
● 135.136.1.133
Manipulation and Disruption
The Cybersecurity & Infrastructure Security Agency (CISA) released an advisory about these attacks:
“These actions disrupted PLCs across several U.S. critical infrastructure sectors through malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss.”
CISA has identified Iran as the source of the files with nefarious commands. These files were originally traced to “foreign hosting providers.”
Beyond Iran
The Iranian infiltration of US-based infrastructures is part of larger nation-state-sanctioned actions against other countries. Russia and the People’s Republic of China have also positioned themselves for an attack and/or reconnaissance in anticipation of war.
Domain Tools reports that the previously mentioned countries each have a purpose in conducting cyberattacks. Iran, because it’s currently at war with the US, is obviously in attack/retaliatory mode. Iran is showing the US and other countries they can do more than just close the Straight of Hormuz and fire rockets.
Russia is also interested in this type of attack, but its purpose is more about showing its might to NATO nations. It’s also a warning to these nations that they can also infiltrate sensitive facilities and damage them as they see fit.
The People’s Republic of China, although not in active war with any country, is also conducting its own cyberwarfare-like activities. Although they are not attacking anyone, they are in reconnaissance mode and stealthily monitoring for an advantage in case of war.
Protection from Unauthorized Access
Protection from this type of infiltration often comes with complete disconnection from the public internet. A firewall, VPN (for IP address encryption), and updated security programs are common and highly effective security practices against unauthorized access.

Comments