What the Iran hackers power grid warning tells utility operators
The Iran hackers power grid warning is a joint federal advisory that the Cybersecurity and Infrastructure Security Agency issued together with 6 partner agencies on April 7, 2026, stating that hackers affiliated with Iran are exploiting programmable logic controllers, the small computers that directly control equipment inside the facilities they run, across United States critical infrastructure. The Federal Bureau of Investigation, the National Security Agency, the Environmental Protection Agency, the Department of Energy, the Cyber National Mission Force of United States Cyber Command and the Department of Treasury joined the Cybersecurity and Infrastructure Security Agency in signing the advisory, 7 agencies in total. It names 3 sectors under threat, government services and facilities including local municipalities, water and wastewater systems, and energy. This advisory states its own release date as April 7, 2026, in its own advisory at a glance section, a day before the 2 news accounts that first made the warning public described it as breaking news.
How the hackers get into grid equipment and what they do
The advisory describes exactly what the hackers do once inside a controller. They tamper with a project file, the stored program that tells a controller what to do, change the screens operators watch to control and monitor equipment, alter or delete the logic that runs the equipment including reusable code blocks called Add On Instructions, turn off the shutdown and alarm systems meant to catch a problem automatically, and copy project files to computers the hackers control outside the network. Federal agencies traced malicious internet addresses tied to the campaign from January 2025 through July 2026, active for a year and a half, scanning for controllers through 5 specific network ports.
CISA has consistently warned critical infrastructure stakeholders that Iranian affiliated threat actors are conducting a range of targeted cyber activity to include compromise unsecure internet connected accounts and devices.
Chris Butera, CISA Acting Executive Assistant Director for Cybersecurity, speaking in a CISA follow up statement. Source 2.
A warning that grew from 1 manufacturer to 3
The warning originally named only Rockwell Automation equipment, 2 controller lines called CompactLogix and Micro850. When federal agencies updated the advisory on July 22, 2026, they widened it to cover controllers from 2 more manufacturers, Schneider Electric BMX P34 and Modicon M340 controllers, and Siemens S7 1200 series controllers.
The advisory named only Rockwell Automation controllers when issued in April. The July update added Schneider Electric and Siemens, widening coverage to 3 manufacturers.
Show the numbers
| Rockwell Automation | 2 |
| Schneider Electric | 2 |
| Siemens | 1 |
The expansion matters because Rockwell equipment carries a named flaw, tracked as CVE 2021 22681, an authentication bypass that can let an attacker find a cryptographic key, the digital code a device checks before it lets another device connect, and use that key to connect an application not made by Rockwell to a Logix controller configured through the Studio 5000 Logix Designer software made by Rockwell Automation. A cybersecurity company that scans for exposed industrial equipment, Nozomi Networks, counted more than 3,000 Rockwell devices still reachable from the public internet.
The public exposure of these OT devices creates a vast attack surface that a motivated and capable adversary can exploit, which is especially relevant given the current conflict.
Markus Mueller, Field Chief Information Security Officer at the industrial cybersecurity company Nozomi Networks. Source 4.
A rising pattern of attacks and what to do about it
The warning also follows a rising pattern of attacks. Check Point Research counted more than 1,160 weekly attack attempts against United States energy and utility organizations in 2024, a figure source 5 states was 70% higher than the year before. Working backward from that reported increase, this site calculates the prior year figure at approximately 682 attempts a week, a number none of the 5 sources states directly.
This site calculated the prior year figure by working backward from the 70% increase source 5 itself reports for 2024. No source states the prior year figure directly. The 2024 figure itself is Check Point Research data as source 5 reports it.
Show the numbers
| Prior year, calculated | 682 |
| 2024 | 1,160 |
The advisory tells operators to disconnect controllers from the public internet, physically set mode switches to run so a device cannot be reprogrammed remotely, require multifactor authentication, keep offline backups and turn off unused remote access tools. The North American Electric Reliability Corporation, the organization that oversees the reliability of the North American power grid, says its watch operations team is actively monitoring the grid directly rather than only reading the advisory.