• Cogent DataHub
  • Industrial
    • Industrial AI
    • Industrial IoT
      • Edge Computing
      • DHTP – The DataHub Transfer Protocol
      • IIoT Protocol Comparison
      • Demo
    • Cogent DataHub
    • Security
    • DataHub™ Service
    • ETK – Embedded Toolkit
      • IoT Gateways
      • Tested Devices
  • Case Studies
    • Blog
    • White Papers
    • News
  • Partners
    • Microsoft
    • Siemens
    • AVEVA
    • Join Now!
  • Investors
    • Financials
  • About Us
    • Management
    • Customers
    • Careers
    • Legal Notices
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
Blog
CISA warns of attacks on PLCs like these

CISA Warns of Attacks on PLCs Across U.S. Critical Infrastructure

by Bob McIlvride

If your PLCs are reachable from the internet, they may already be compromised.

Last week CISA, the FBI, the NSA, and other federal agencies jointly issued an urgent cybersecurity advisory: “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure“. The advisory describes an active campaign targeting internet-facing PLCs — primarily Rockwell Automation/Allen-Bradley devices — across water, energy, and government facilities.

The attacks are not theoretical. Threat actors used overseas IP addresses and standard configuration software to connect directly to exposed PLCs, extract project files, and manipulate HMI and SCADA displays. “In a few cases, this activity has resulted in operational disruption and financial loss,” the CISA advisory states. The actors’ intent, according to the authoring agencies, was “to cause disruptions” to U.S. critical infrastructure.

The attack vector is remarkably simple: the PLCs were internet-accessible. No zero-day exploit was needed.

Executives and Plant Leadership – What Should Concern You

This is not a software bug that can be patched. It is an architectural failure in how OT is connected to the outside world. The business implications go beyond operational disruption:

  • Financial loss from unplanned downtime and incident response
  • Reputational damage when customers and regulators learn that basic network segmentation was absent
  • Regulatory exposure under NIS2, NIST CSF 2.0, and sector-specific CISA directives
  • Theft of proprietary engineering designs and production logic

CISA’s first recommendation is blunt: “Disconnect the PLC from the public-facing internet,” and “remove inbound port exposure” so OT systems are “never directly exposed to the internet or external networks.”

The instinct to hand this to IT is understandable, but traditional IT approaches — VPNs, remote desktop, perimeter firewalls with inbound rules — are precisely the patterns that created this exposure. This is an OT network architecture issue. The right conversation with your engineering teams starts with: Which of our OT devices are accessible from external networks? Do any firewall rules allow inbound connections to the plant? If we closed every inbound path today, what data access would we lose?

The goal is not to stop data from flowing. It is to ensure nothing can flow in.

A Structural Solution

The architecture that prevents this class of attack uses outbound-only connections from the OT network, carrying data across a DMZ to IT or cloud systems without opening any inbound ports. DataHub tunnel/mirror technology from Skkynet does exactly this — and has for over two decades. The attack described in this advisory is architecturally impossible when no inbound path to the OT network exists.

Closing all inbound firewall ports in response to CISA warning

This advisory also validates two other core DataHub design principles: a fractal namespace architecture that isolates each operational level so a compromise cannot cascade across the enterprise, and DMZ-compatible network segmentation that maintains guaranteed data consistency across multiple network hops — something standard MQTT and OPC UA cannot provide.

Control Engineers and Integration Teams – What Should Concern You

The CISA advisory (AA26-097A) describes Iranian-affiliated APT actors accessing internet-exposed CompactLogix and Micro850 PLCs using Studio 5000 Logix Designer. They connected on ports 44818, 2222, 102, and 502 — standard OT ports. They extracted .ACD project files, manipulated SCADA displays, and deployed Dropbear SSH for persistent access. The targeting of Siemens S7 ports indicates this is not limited to Rockwell devices.

Short-Term Mitigations

  • Disconnect PLCs from the public internet; place them behind gateways and firewalls
  • Set physical mode switches to run position to prevent remote logic modification
  • Create and test offline backups of PLC logic and configuration
  • Implement MFA for any remote OT access from external networks
  • Monitor OT ports for connections from unexpected IP ranges and check logs against the published IOCs

These are necessary but tactical. They reduce immediate exposure without solving the architectural problem.

Long-Term Solutions

The long-term answer is an architecture where inbound access to the plant is structurally impossible:

  1. Outbound-only tunnel/mirror connections that initiate from inside the OT network, with all firewall ports closed inbound and SSL encryption throughout. Even a compromised receiving side cannot reach back into the plant.
  1. DMZ-based network segmentation with guaranteed data consistency at every hop. Unlike MQTT, whose QoS guarantees do not propagate past a single broker, DataHub tunnel/mirroring flags stale or disconnected data immediately at every node in the chain.
  1. A fractal UNS that isolates each operational level — machine, line, site, enterprise — so lateral movement from a compromised node is constrained by architecture, not just policy.

This advisory validates what DataHub’s architecture was built to prevent. The attack succeeded because OT devices were directly accessible with no segmentation, no mediation, and no architectural barriers. An outbound-only, DMZ-compatible architecture eliminates that entire attack surface — and keeps production data flowing where it needs to go.

Share this entry
  • Share on Facebook
  • Share on X
  • Share on WhatsApp
  • Share on LinkedIn
  • Share by Mail
https://skkynet.com/media/Blog-CISA-Warns-of-Attacks.jpg 429 1000 Bob McIlvride https://skkynet.com/media/skkynet-logo.svg Bob McIlvride2026-04-15 13:47:052026-04-15 14:23:35CISA Warns of Attacks on PLCs Across U.S. Critical Infrastructure

Skkynet Blog

Explore the questions, watch the developments, and evaluate solutions for one of the biggest opportunities of our time: Implementing secure, real-time data access on the Industrial IoT.
- Bob McIlvride

Recent Entries

  • CISA warns of attacks on PLCs like these
    CISA Warns of Attacks on PLCs Across U.S. Critical Infrastructure
  • The Ransomware Threat Manufacturers Can’t Afford to Ignore
  • Wood processing plant case study - banner
    Case Study: Wood Processing Plant in North America
X Logo X Logo Followon X RSS Feed Logo RSS Feed Logo Subscribeto RSS Feed
About Us Icon white

About Us

Skkynet has been helping organizations securely share real-time data for more than 25 years. We offer privately-hosted or fully managed solutions for moving data in industrial, embedded and financial systems, from anywhere to anywhere.

News

January 28, 2026

Skkynet Reports Fiscal 2025 Financial Results: Subscription Revenue Surges 268% Amidst Strategic Pivot to AI and SaaS

December 18, 2025

Skkynet Announces C$2.6 Million Industrial AI Product Development Initiative

December 16, 2025

Skkynet Appoints M&A and Software Executive Shaunna Balady to Advisory Board

December 9, 2025

Skkynet Appoints Industry Veteran Gary Tillery as Chief Executive Officer

Contact us icon white

Contact Us

Skkynet
2233 Argentia Road, Suite 302
Mississauga, ON L5N 2X7

International: 1-905-702-7851

US/CA Toll Free: 1-888-702-7851

[email protected]

Skkynet logo white

Cogent DataHub | Industrial | Case Studies | Partners | Investors | About us

Back to Top

linkedIn logotwitter logoyoutube logo

© 2026 Skkynet | All rights reserved | Legal notices
Link to: The Ransomware Threat Manufacturers Can’t Afford to Ignore Link to: The Ransomware Threat Manufacturers Can’t Afford to Ignore The Ransomware Threat Manufacturers Can’t Afford to Ignore
Scroll to top Scroll to top Scroll to top

We are using cookies to give you the best experience on our website.

You can find out more about which cookies we are using or switch them off in .

Skkynet logo
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

3rd Party Cookies

This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping this cookie enabled helps us to improve our website.

Cookie Policy

More information about our Cookie Policy