Iranian government-linked hackers have widened their targeting of American critical infrastructure, attempting to breach systems tied to water utilities, telecommunications networks and energy providers in the weeks leading up to September 2026. NBC News reported on September 2, 2026, citing four people with access to government and industry cyber-threat information, that the attempts have so far focused on internet-exposed automated control systems and have not caused major damage. The National, an Abu Dhabi-based outlet, published an analysis the same day framing Iran’s approach as a low-cost, high-leverage tool against a much larger military power, an assessment that lines up with a pattern of federal advisories stretching back to a 2023 breach at a small water authority outside Pittsburgh.
The story matters less for any single intrusion than for the shape of the campaign. Since November 2023, Iran-linked operators have moved from defacing one brand of industrial controller to probing a second, expanded from water systems to energy and telecom networks, and drawn a joint federal advisory along the way. What follows is a look at what has actually been confirmed, what officials and reporters are still hedging on, and why the pattern points to a longer-running strategy rather than a one-off incident.
What NBC News and The National Reported on September 2
NBC News‘ September 2 report said Iranian hackers had targeted not only US water systems but also telecommunications, energy networks and other infrastructure in recent weeks. The outlet’s sources described the activity as part of Iran’s readiness to retaliate against the United States outside of a military theater, and stressed that the attempted intrusions, so far, had not succeeded in causing operational damage. Iran International, an English-language outlet covering Iranian affairs, summarized the same NBC reporting on September 2 and repeated the detail that the attempts focused on automated systems connected directly to the internet.
The National’s piece, titled “Iran’s cyber attack strategy is ‘perfect weapon’ against US,” built on that NBC reporting and argued that cyber operations let Tehran pressure Washington without risking a conventional military response. The article cited an unnamed expert making the case that cyber is an asymmetric tool suited to Iran’s position, one that can affect a population without deploying aircraft, missiles or personnel on American soil, while leaving room for ambiguity about attribution. Because the expert is not named in the available reporting, this analysis treats that framing as an editorial assessment from the outlet rather than an on-the-record government statement, and relies instead on named federal sources for the operational specifics below.
The Federal Advisory Behind the Headlines: AA26-097A
The September reporting builds directly on a joint advisory that US agencies issued months earlier. On April 7, 2026, the Cybersecurity and Infrastructure Security Agency, working with the FBI, NSA and other federal partners, published advisory AA26-097A, warning that Iran-affiliated advanced persistent threat actors were breaking into industrial control systems across multiple sectors. The agencies wrote that they “urgently warn US organizations of ongoing Iranian-affiliated cyber targeting of internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs),” according to the advisory cited in coverage from The Guardian.
The advisory went further than a generic warning. It described actual operational consequences, stating that the intrusions “disrupted PLCs across several US critical infrastructure sectors through malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss.” That is a meaningfully different claim from an attempted-but-blocked intrusion. It says facilities actually saw their control interfaces manipulated, not just probed.
NBC News reported at the time that the April advisory tied the intrusions to internet-facing tools made by Rockwell Automation, specifically its Allen-Bradley line of industrial controllers, and that the disruptions touched government services, water and wastewater utilities, and the energy sector. That is a notable pivot from the vendor targeted in the original 2023 incidents, and it is one of the clearest signals that the campaign has not stayed static.
From Unitronics to Rockwell: How the Targeting Evolved
The current campaign has roots that go back nearly three years. On November 25, 2023, a group identifying itself as CyberAv3ngers, which CISA and outside researchers describe as linked to Iran’s Islamic Revolutionary Guard Corps, defaced the human-machine interface of a Unitronics Vision-series controller at the Municipal Water Authority of Aliquippa, a small utility outside Pittsburgh. The defacement carried a political message about Israeli-made equipment being a legitimate target. NPR reported on December 2, 2023, that the same actors had gone after roughly ten small US utilities running the same Israeli-built Unitronics systems, and that the affected Pennsylvania utility had to switch to manual operation while officials said drinking water safety was not compromised.
Washington’s initial response was financial rather than technical. On February 2, 2024, the Treasury Department’s Office of Foreign Assets Control sanctioned Hamid Reza Lashgarian, described as head of the IRGC’s Cyber-Electronic Command, along with five other Iranian officials, over their alleged role in the water utility hacks. The sanctions notice, published through Treasury’s recent-actions page, tied the officials directly to the CyberAv3ngers persona and to the exploitation of Israeli-made industrial control devices across multiple states.
Sanctions did not end the activity. Through 2025 and into 2026, reporting shows the same IRGC-linked cluster shifting from Unitronics equipment to Rockwell Automation’s Allen-Bradley product line, broadening past water utilities into energy and telecom targets, and eventually prompting the April 2026 joint advisory. Read as a sequence, the pattern looks less like scattered opportunism and more like a persistent unit iterating on which internet-exposed vendors are easiest to reach.
Timeline: Iran’s Cyber Campaign Against US Infrastructure
| Date | Event | Source |
|---|---|---|
| Nov. 25, 2023 | CyberAv3ngers defaces a Unitronics PLC at the Aliquippa, PA water authority; utility switches to manual operation | NPR, Dec. 2, 2023 |
| Dec. 6, 2023 | Foundation for Defense of Democracies reports nearly 10 additional US utilities hit via the same Unitronics flaw | FDD |
| Feb. 2, 2024 | Treasury/OFAC sanctions six IRGC Cyber-Electronic Command officials over the water utility hacks | Treasury OFAC |
| Mar. 12, 2026 | An Iran-linked group claims a cyberattack on a US medical technology firm, described as the first significant hack of a US company since the two countries’ conflict began | NBC News |
| Apr. 7, 2026 | CISA, FBI, NSA and partners issue advisory AA26-097A on Iran-affiliated actors exploiting internet-exposed PLCs, now including Rockwell/Allen-Bradley systems | CISA advisory; The Guardian |
| Sept. 2, 2026 | NBC News reports Iranian hackers broadened targeting to telecoms and energy networks in recent weeks; intrusions reported unsuccessful so far | NBC News; Iran International |
Who Is CyberAv3ngers, and Why the Persona Matters
CyberAv3ngers functions as a public-facing brand for what US officials assess as IRGC Cyber-Electronic Command activity, rather than an independent hacktivist crew. That distinction shapes how seriously agencies treat its output. A hacktivist group defacing a water utility’s control panel is an embarrassment. A state military-intelligence unit doing the same thing through a hacktivist mask is a signal, one the sanctions against IRGC-CEC leadership in 2024 were designed to raise the cost of sending.
The broader alphabet soup of Iran-linked threat actors, including APT33, APT34 and MuddyWater, has historically focused on espionage against aerospace, energy and government targets in the Middle East and beyond, with credential theft and web shells as common tools. Reporting on the current infrastructure-focused campaign has concentrated specifically on the CyberAv3ngers persona and IRGC-CEC, though the underlying operational capability likely overlaps with those longer-running espionage units to some degree, since Iran’s cyber program has historically shared tooling and personnel across ostensibly separate operations.
Why Officials Are Calling It a Public Health Issue, Not Just an IT Problem
Federal officials have been careful to frame these intrusions around physical consequences rather than data theft. Jeffrey Hall, the Environmental Protection Agency’s assistant administrator for enforcement and compliance assurance, said that “cyberattacks on drinking water and wastewater systems directly threaten public health and community resilience,” a statement reported by The Guardian around the April advisory. Hall added that “a single breach can disrupt treatment or introduce contaminants, damage equipment, and erode public trust,” language that puts water-sector intrusions in the same category as a public health hazard rather than a routine network breach.
That framing is echoed in the joint advisory itself. CISA, the FBI, the NSA and their partner agencies wrote that the goal of the campaign is straightforward: “the hackers are seeking to cause disruptive effects within the United States,” according to Reuters’ coverage of the same April advisory. Combined with Hall’s public health framing, the message from Washington is that these intrusions should be judged by their potential to interrupt a service people depend on daily, not by whether any single facility’s data was copied.
Water and Wastewater: The Softest Target
Small municipal utilities remain the weak point. Many run older SCADA and PLC hardware, often connected to the internet for remote monitoring by staff who cover multiple plants, and few have dedicated security teams. The Aliquippa authority that CyberAv3ngers hit in 2023 served roughly 6,000 customers, a scale typical of the utilities named in subsequent reporting. Larger metro water systems generally carry more security investment and network segmentation, which is part of why the confirmed intrusions to date have concentrated on smaller operators rather than major city utilities.
The EPA‘s Hall pointed to exactly this gap, and the agency’s public messaging around AA26-097A leaned on plain language about contamination risk rather than technical jargon, a choice aimed at an audience of small-utility operators who may not have a security team reading CISA advisories in the first place.
Energy and Telecoms: The September Expansion
The September reporting is the first to place telecommunications squarely alongside water and energy as an active target category, based on NBC’s sourcing. Telecom networks make an odd target for the kind of PLC-focused intrusion the April advisory described, since carrier infrastructure runs on different control systems than water treatment plants. That suggests the September activity may involve reconnaissance and access-gaining against a broader set of network-facing systems, rather than a straightforward continuation of the PLC-defacement tactics documented in 2023 and April 2026. NBC’s sourcing described the recent attempts as unsuccessful so far, which is consistent with early-stage scanning and access attempts rather than a completed intrusion with demonstrated impact.
Market Impact: OT Security Spending Under Pressure
Repeated federal advisories tend to move budget lines even when no single incident causes visible damage. Utilities and industrial operators facing a named advisory like AA26-097A typically face pressure from insurers, regulators and boards to show concrete remediation, not just an acknowledgment letter. For operational technology security vendors, that translates into renewed interest in network segmentation, PLC monitoring and asset inventory tools aimed specifically at the water and energy sectors, categories that have historically lagged well behind enterprise IT in security spending.
Cyber insurers covering critical infrastructure operators are also watching the pattern closely. A named federal advisory citing “operational disruption and financial loss,” as AA26-097A does, gives underwriters a documented basis for tightening terms or requiring specific controls, such as removing PLCs from direct internet exposure, before renewing coverage for water and energy clients. Expect insurers to increasingly treat internet-facing OT devices the way they already treat unpatched VPN appliances: as a named, auditable exclusion or a required remediation before binding a policy.
How Iran’s Approach Compares to Russia, China and North Korea
Iran is not the only nation-state actor probing US infrastructure, and its approach looks different from its peers in both target selection and messaging. The table below lays out the broad strategic contrast based on publicly documented US government attribution patterns through 2026.
| Actor | Primary Target Pattern | Apparent Objective | Attribution Style |
|---|---|---|---|
| Iran (IRGC-CEC / CyberAv3ngers) | Water utilities, energy, telecoms via internet-exposed PLCs and HMIs | Signal retaliatory capability without conventional escalation | Semi-overt; hacktivist-branded defacements with political messaging |
| Russia (state-linked units) | Energy grid operators, government networks | Pre-positioning for potential future disruption, espionage | Covert; long-dwell, low-visibility intrusions |
| China (state-linked units) | Telecoms, water, transportation, “living off the land” persistence | Long-term pre-positioning inside infrastructure for crisis leverage | Covert; minimal malware footprint, native tool abuse |
| North Korea (state-linked units) | Financial systems, cryptocurrency platforms, defense contractors | Revenue generation and espionage, less infrastructure-disruption focus | Mixed; some overt theft, some covert espionage |
The contrast is instructive. Where Chinese state-linked activity against US infrastructure has generally been described by US officials as quiet, long-dwell pre-positioning meant to stay hidden until needed, Iran’s operators have repeatedly left calling cards, defacement messages, political branding, and a named hacktivist persona. That is consistent with The National’s framing of cyber as a signaling tool for Tehran: the point is not necessarily to stay hidden, it is to demonstrate reach while keeping the attribution just ambiguous enough to avoid a clear-cut act-of-war framing.
Why the Timing Lines Up With Broader Iran-US Tensions
NBC’s September sourcing directly connected the broadened targeting to Iran’s posture toward the United States following the countries’ recent military conflict, describing the cyber activity as part of Tehran’s readiness to retaliate outside a military theater. The March 2026 hack of a US medical technology firm, which NBC described as the first significant Iranian hack of an American company since the conflict began, fits that same window. Read together, the medical technology intrusion, the April industrial-control advisory and the September broadening to telecoms and energy describe an escalating cadence rather than an isolated spike.
What Utility Operators Should Actually Do
Remove direct internet exposure
The single recurring thread across every confirmed incident, from Aliquippa in 2023 to the Rockwell-targeted intrusions named in AA26-097A, is that the affected PLCs and HMIs were reachable directly from the internet. Utilities that place these devices behind a VPN or a segmented industrial network, rather than exposing management interfaces publicly, eliminate the exact access path these actors have used repeatedly.
Treat vendor advisories as time-sensitive
Both the Unitronics and Rockwell Automation intrusions followed a pattern where the vulnerable configuration, default or weak credentials on an internet-facing device, was well known before it was exploited at scale. Utilities that patch and reconfigure quickly after vendor and CISA advisories close the window that IRGC-linked operators have exploited twice already.
What CISA’s Advisory Language Signals for Compliance
The specific wording in AA26-097A, describing “malicious project file interactions and manipulation of data” on HMI and SCADA displays, is more technically precise than earlier advisories in this series, and that precision matters for compliance officers. Naming the exact mechanism, tampering with project files and display data rather than a generic “unauthorized access,” gives utilities a concrete checklist item: audit who can modify PLC project files and whether HMI data feeds are authenticated. Environmental Protection Agency enforcement staff, per Hall’s comments, are treating that operational detail as the basis for compliance conversations with water utilities going forward, rather than leaving remediation guidance at a high level.
Advisory reference: CISA AA26-097A (issued April 7, 2026)
Actors: Iran-affiliated APT, CyberAv3ngers persona, IRGC Cyber-Electronic Command
Sectors named: Water/wastewater, energy, government services (2026); telecoms added in Sept. 2026 reporting
Vendors named: Unitronics (2023 activity), Rockwell Automation/Allen-Bradley (2025-2026 activity)
Technique pattern: Internet-exposed PLC/HMI access, project file manipulation, SCADA display tampering
Recommended control: Remove PLC/HMI management interfaces from direct internet exposure
Predictions: Where This Campaign Goes Next
First, expect a follow-up CISA advisory specifically addressing telecom-sector targeting within the next two to three months, mirroring how the water-sector activity in 2023 led to a broader industrial-control advisory by April 2026. Second, additional OFAC sanctions against IRGC-CEC-linked individuals are plausible if attribution for the September telecom and energy targeting firms up, following the same playbook used against Lashgarian and five others in February 2024. Third, smaller water and energy utilities will likely face new state-level or EPA-driven security requirements, given Hall’s public health framing and the recurring finding that small operators are the entry point. Fourth, watch for OT security vendors to report increased sales pipeline specifically from water and energy customers in coming quarters, driven by the compliance pressure described above rather than by a single dramatic breach. Fifth, expect continued ambiguity around attribution and impact severity in public reporting, since both Iran’s operators and US officials have incentives, retaliatory signaling on one side and avoiding panic on the other, to keep the public picture vague even as technical advisories get more specific.
The Broader Pattern: Signaling Without Escalation
Nearly three years of documented activity, from a single defaced water panel in a Pittsburgh suburb to a joint federal advisory naming a major industrial automation vendor to reports of telecom and energy targeting, tells a consistent story about Iran’s cyber strategy: probe widely, favor targets that are cheap to reach because they are exposed to the internet, and stop short of causing damage severe enough to force a conventional response. Whether that restraint holds as tensions between the two countries persist is the open question that both the April advisory and the September reporting leave unanswered. What’s confirmed so far is a widening target list and an escalating advisory record, not a catastrophic outcome.
Frequently Asked Questions
Has Iran successfully disrupted US electricity or water service in 2026?
Federal advisory AA26-097A, issued April 7, 2026, described operational disruption and financial loss at affected facilities, but did not report a widespread service outage. NBC News’ September 2026 reporting on broadened telecom and energy targeting described those specific attempts as unsuccessful so far.
What is CyberAv3ngers?
CyberAv3ngers is a hacktivist-branded persona that CISA and outside researchers link to Iran’s IRGC Cyber-Electronic Command. It first drew wide attention after defacing a water utility controller near Pittsburgh in November 2023 and has been tied to subsequent industrial control system intrusions.
What is CISA advisory AA26-097A?
It is a joint advisory issued April 7, 2026 by CISA, the FBI, the NSA and other federal partners warning that Iran-affiliated actors were exploiting internet-exposed programmable logic controllers, including Rockwell Automation/Allen-Bradley equipment, causing operational disruption across water, energy and government-services targets.
Which sectors has Iran’s cyber campaign targeted?
Confirmed and reported targeting spans water and wastewater utilities (2023-2026), energy and government services (named in the April 2026 advisory), and telecommunications networks (added in NBC’s September 2026 reporting).
Were any US officials sanctioned or penalized over these hacks?
The Treasury Department’s Office of Foreign Assets Control sanctioned six Iranian officials, including IRGC Cyber-Electronic Command leader Hamid Reza Lashgarian, on February 2, 2024, over their alleged role in the 2023 water utility hacks.
How is this different from Chinese state-linked activity against US infrastructure?
US officials have generally described China-linked infrastructure intrusions as covert, long-dwell pre-positioning meant to stay hidden. Iran’s campaign has repeatedly involved public defacements and a named hacktivist persona, a more overt signaling approach.
What should small utilities do to protect against this specific threat?
The recurring factor across confirmed incidents is direct internet exposure of PLC and HMI management interfaces. Removing that exposure, segmenting industrial networks, and applying vendor and CISA advisories promptly addresses the access method used in every documented case so far.
Is this connected to the broader Iran-US military conflict?
NBC News reported that the broadened September 2026 targeting reflects Iran’s readiness to retaliate against the US outside a military theater, and that a March 2026 hack of a US medical technology firm was described as the first significant Iranian hack of an American company since the conflict between the two countries began.




