PLC (Programable Logic Controller)'s are at the heart of many of our automated systems in our water plants, waste water plants, electrical power generating plants, switching devices, telecommunications control systems, defense systems, and on and on.
When those who employ these devices leave the default passwords, they become points of danger for any system they control. Hackers from Iran have already proven they can get in and create destruction.
Now you know why people who deal in networking safeguard their systems and their passwords. However, there are many who are simply too damn lazy to manage the passwords to their systems control devices.
CISA warns Iran-linked hackers can shut down US power plants by targeting the PLCs that run 80% of grid endpoints
When those who employ these devices leave the default passwords, they become points of danger for any system they control. Hackers from Iran have already proven they can get in and create destruction.
In late 2023, hackers tied to Iran’s Islamic Revolutionary Guard Corps broke into programmable logic controllers at American water utilities using a technique that required no special tools and no insider access. They simply tried the factory-default passwords that shipped with the devices. It worked. Now, more than two years later, federal officials say the underlying vulnerabilities remain widespread, and the same class of attack could reach far beyond water systems into the electrical grid, manufacturing, and other sectors where PLCs govern physical machinery.
A series of joint advisories from CISA, the EPA, the FBI, and the NSA has laid out the threat in unusually direct terms. The agencies identified the attackers as “CyberAv3ngers,” a persona linked to the IRGC, and confirmed that the group had compromised Unitronics-brand PLCs at multiple U.S. water and wastewater facilities. As of mid-2026, the federal government continues to treat this campaign as an active and evolving threat to critical infrastructure, with CISA advisory AA26-097A extending the technical guidance and indicators of compromise first published in December 2023.
A series of joint advisories from CISA, the EPA, the FBI, and the NSA has laid out the threat in unusually direct terms. The agencies identified the attackers as “CyberAv3ngers,” a persona linked to the IRGC, and confirmed that the group had compromised Unitronics-brand PLCs at multiple U.S. water and wastewater facilities. As of mid-2026, the federal government continues to treat this campaign as an active and evolving threat to critical infrastructure, with CISA advisory AA26-097A extending the technical guidance and indicators of compromise first published in December 2023.
Now you know why people who deal in networking safeguard their systems and their passwords. However, there are many who are simply too damn lazy to manage the passwords to their systems control devices.
CISA warns Iran-linked hackers can shut down US power plants by targeting the PLCs that run 80% of grid endpoints
Comment