Table of Contents
ToggleOT Cybersecurity · PLC Security · Remote Access
PLC Remote Access Security: 5 Urgent Lessons From the 2026 CISA Advisory
In April 2026, six US federal agencies jointly warned that nation state hackers were actively breaking into internet connected PLCs, without using a single zero day exploit. This guide covers PLC remote access security through the lens of that real advisory, with the actual mitigations agencies published for defenders.
PLC Remote Access Security: The 2026 CISA Advisory Explained
On April 7, 2026, the FBI, CISA, NSA, EPA, Department of Energy, and US Cyber Command jointly published advisory AA26-097A, warning that Iranian affiliated threat actors were actively exploiting internet facing programmable logic controllers across US critical infrastructure. The affected devices were manufactured by Rockwell Automation and sold under the Allen-Bradley brand, specifically CompactLogix and Micro850 families, deployed across government facilities, water and wastewater systems, and energy sector operations.
This was not theoretical. The advisory confirmed real operational disruption and real financial loss at victim organizations, caused by attackers tampering with PLC project files and manipulating the data shown on HMI and SCADA displays, meaning operators were looking at readings that no longer reflected what was actually happening in their process. The threat group involved, tracked under names including CyberAv3ngers and linked to Iran's IRGC Cyber Electronic Command, had previously compromised at least 75 Unitronics PLCs across US and international water utilities back in 2023, including a widely reported incident at a Pennsylvania water authority.
The attackers did not need a sophisticated, unknown exploit. They connected to internet exposed PLCs using Rockwell's own legitimate engineering software, Studio 5000 Logix Designer, the same tool a plant engineer would use for normal configuration work. The fundamental weakness being exploited was not a software flaw, it was the simple fact that these controllers were reachable from the public internet at all.
How Many PLCs Are Actually Exposed to the Internet
Independent internet scanning by Censys, conducted the same week the advisory was released, quantified the actual scale of this exposure. Globally, 5,219 hosts responding to the EtherNet/IP protocol self identified as Rockwell Automation or Allen-Bradley devices, meaning every one of them was reachable from the public internet.
Data source: Censys internet scanning, April 7, 2026, as reported by Industrial Cyber and Censys.com
Notably, a large share of that US exposure traced back to cellular carrier networks rather than fixed corporate connections, consistent with PLCs deployed in the field and connected through cellular modems for remote monitoring, exactly the kind of convenient but unmonitored connection that this advisory warns against.
Watch: OT Cybersecurity for Beginners, ICS, SCADA and PLC Security Explained
This video gives a complete crash course on OT cybersecurity fundamentals, directly relevant to understanding why incidents like this happen.
Video: "OT Cybersecurity for Beginners: ICS, SCADA & PLC Security Explained (Complete 2026 Guide)", embedded via YouTube
5 Urgent Lessons for PLC Remote Access Security
PLC Remote Access Security Mitigations Recommended by CISA
These specific steps form the practical core of PLC remote access security in response to this exact campaign.
Everything in this section comes directly from CISA's own published guidance, intended specifically to help asset owners defend against this exact threat. None of it depends on expensive new technology, it is almost entirely configuration hardening of infrastructure that already exists in most plants.
| Mitigation | Why It Matters Here |
|---|---|
| Remove PLCs from direct internet exposure | Eliminates the exact attack surface this campaign relies on entirely |
| Mediate all remote access through a jump host or secure gateway | Ensures no PLC is ever reachable directly from an external network |
| Set the physical mode switch to RUN on supported devices | Blocks remote logic modification at the hardware level, immune to network attacks |
| Disable VNC, Telnet, and FTP on hosts near PLCs | Removes cleartext, weakly authenticated remote access paths |
| Enforce MFA on all remote OT access | Blocks credential based access even if a password is compromised |
| Maintain tested, offline backups of PLC logic and configuration | Ensures recovery is possible without paying a ransom or losing production time |
| Monitor logs for traffic on relevant OT ports | Ports 44818, 2222, 102, 502, and 22 were specifically named in the advisory |

PLC Cyberattack History: 2023 Unitronics vs 2026 Rockwell Campaign
The organizations behind AA26-097A were not new to this. Beginning in November 2023, the same IRGC linked group compromised at least 75 internet exposed Unitronics PLCs across US and international water utilities, in an operation that gained public attention after attackers took control of a booster station regulating water pressure at a Pennsylvania water authority. A separate incident in County Mayo, Ireland, left residents without running water for several days.
Between that 2023 campaign and the 2026 advisory, the attackers evidently moved on from exploiting simple factory default passwords to exploiting a known authentication weakness in Rockwell's Logix controller software, tracked as CVE-2021-22681. That vulnerability, involving an insufficiently protected cryptographic key, had already been publicly disclosed and patched years earlier, which underscores a recurring theme across both campaigns: attackers consistently succeed against internet exposed OT devices using known weaknesses and legitimate tools, not sophisticated zero day exploits.
| Campaign | Target | Root Cause |
|---|---|---|
| November 2023 | Unitronics PLCs, US and international water utilities | Factory default passwords on internet exposed devices |
| March to April 2026 | Rockwell/Allen-Bradley CompactLogix and Micro850 PLCs | Internet exposure combined with a known authentication bypass vulnerability |
Quick FAQs: PLC Remote Access Security
These are the questions engineers ask most often once PLC remote access security moves from advisory reading into an actual site walkthrough.
External References
- CISA Advisory AA26-097A: Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
- Cybersecurity Dive: Iran-Linked Hackers Target Water, Energy in US
- CISA Advisory AA23-335A: IRGC-Affiliated Cyber Actors Exploit PLCs in Water and Wastewater Systems
What we learn today
- PLC remote access security failed in this real 2026 incident not because of a sophisticated exploit, but because controllers were reachable directly from the public internet.
- A physical mode switch set to RUN blocks remote logic changes at the hardware level, immune to any network based attack technique.
- Legacy remote protocols like VNC, Telnet, and FTP have no place on internet facing OT infrastructure, and MFA on remote access is no longer optional.
- This exact pattern, internet exposed OT devices exploited through known weaknesses, has repeated at least twice with the same threat actor group since 2023, and will likely repeat again.
