Recent cyber threats have emerged, specifically targeting operational technology (OT) devices crucial to the U.S. infrastructure. The U.S. Federal Bureau of Investigation (FBI) reported on Tuesday that these attacks are linked to Iranian cyber actors and have resulted in the disruption of programmable logic controllers (PLCs), leading to reduced functionality and financial losses.
These activities are part of a broader surge in cyber attacks by Iranian hacking groups against U.S. entities, motivated by the ongoing tensions involving Iran, the U.S., and Israel. The attacks primarily affect PLCs from Rockwell Automation and Allen-Bradley, impacting sectors such as government services, energy, and water management. Specific PLC models targeted include CompactLogix and Micro850 devices.
To mitigate these risks, cybersecurity agencies recommend measures such as avoiding internet exposure of PLCs, implementing multi-factor authentication (MFA), and using firewalls or network proxies to regulate access. The advisory also emphasizes the importance of keeping PLCs updated and monitoring for unusual network traffic to safeguard against these persistent threats.