Expert Opinions

Iran Got In Without Breaking Anything

Written by:
Bobby Wescott
Bobby Wescott
Published on:
July 21, 2026
Iran Got In Without Breaking Anything

Back in April of this year, CISA published an advisory confirming that Iranian-affiliated hackers had broken into operational technology, the industrial controllers that run water utilities, energy operators, and government facilities across the United States. The intrusions had been running since at least March 2026, and the group behind them is tied to the same Iranian actors who hit a Pennsylvania water utility back in 2023. It's the latest reminder that OT security has become the front line of critical infrastructure defense, not an afterthought bolted onto IT.  

Here's the sentence in that advisory every executive in critical infrastructure should sit with: the weakness these hackers used wasn't a software bug. It was the fact that the equipment could be reached from the internet at all.

That distinction matters more than it sounds like it does. A software bug gets a patch, a deadline, a ticket in a queue. This was different. The hackers didn't break in through some clever trick. They found OT devices sitting out in the open, connected to them using the same kind of tools a technician would use, and started poking around. Nothing about the equipment failed. It simply wasn't protected from being found in the first place, and that's an OT security gap, not an IT one.

What Happened

The equipment targeted was mostly Rockwell Automation controllers, the kind of industrial control systems (ICS) that run pumps, valves, and process logic at water plants and energy facilities, along with some Siemens and Modbus-connected OT assets. Once inside, the attackers did two things worth knowing about. First, they copied out the actual control logic, essentially the blueprint for how a facility runs. Second, and this is the part that should worry people, they altered what operators saw on their SCADA and HMI monitoring screens. An operator looking at a dashboard that says everything is fine has no reason to go check.

That's not a data breach in the way most people think about a data breach. That's the setup for something that shows up in the physical world, not just an incident report.

One known flaw in a piece of Rockwell software was confirmed to be part of this campaign and has since been added to the federal government's list of actively exploited vulnerabilities. Fix it, absolutely. But don't let that one fix create a false sense that the OT cybersecurity problem is solved. The advisory is clear that most of this campaign didn't rely on any flaw at all. It relied on OT equipment that could be reached from outside the plant floor.

CISA's Own Advice Tells You Everything

Look at what the government is telling OT operators to do in response: take these controllers off the open internet, put a secure layer in front of OT remote access, require stronger authentication, and lock down the specific pathways these attackers used.

Strip away the technical language and that's one idea, repeated a few different ways: stop letting anyone connect to this OT equipment until you actually know who they are. That's the right instinct. Most OT security tools on the market weren't built to deliver it without ripping out equipment or adding software to industrial devices that were never designed to run it.

That's the gap we built Invisinet to close, and it's the same story we keep seeing play out across IT and OT networks alike. Volt Typhoon. The Everest ransomware group hitting bank vendors. Now this OT-focused campaign. Different attackers, different targets, same root cause: something inside the operational technology network was reachable that should never have been visible at all.

How Invisinet Changes This Story

Here's the plain version of what we do for OT and ICS environments. Before any device or user can even start a connection to something we protect, they have to present a verified identity, checked automatically, in real time. If that identity isn't there or isn't valid, the connection attempt gets nothing back. No error. No response. As far as an outside scanner is concerned, the OT asset isn't even there.

Apply that to what happened in this campaign. The attackers' entire first move depended on finding OT equipment that would answer when they came knocking. Equipment protected by Invisinet doesn't answer. There's no confirmation that anything exists at that address at all, let alone a way in.

And this is the detail that matters most for water utilities, energy operators, and anyone running legacy OT equipment: none of this requires installing anything on the controller itself. These industrial devices were never built to run modern security software, and in most cases they never will be. We sit in front of the OT equipment, not on it, so the device stays exactly as it is while what's allowed to reach it changes completely. That's what lets Zero Trust extend into IT/OT convergence points without touching a single PLC, RTU, or SCADA server.

Why This Keeps Happening

This advisory didn't come out of nowhere. Earlier this year, CISA gave federal agencies and infrastructure operators eighteen months to retire outdated edge devices sitting at the boundary of their OT networks. Iranian-linked groups have gone after American defense facilities. Russian hackers disrupted part of Poland's power grid in December. The pattern is consistent across every recent OT cybersecurity incident: aging, exposed operational technology is the target, and checking a compliance box once a year isn't catching it.

Eighteen months sounds reasonable until you're the person responsible for replacing thousands of controllers across a water system you can't take offline. That gap between the deadline and the reality of operating a live OT environment is exactly where our approach earns its place. You don't have to wait until every piece of legacy OT hardware is swapped out to stop it from being visible to anyone with a scanner. You can make it invisible today, and keep it that way while the clock runs on replacing it.

The Questions Worth Asking This Week

If you run OT infrastructure, three questions matter more than anything else in this advisory. Can someone on the open internet get any kind of response from your OT network right now? If you're not sure, that uncertainty is the exposure. If a piece of ICS or SCADA equipment can't be replaced or upgraded before your next audit, what's actually standing between it and whoever finds it? And when your current OT security stack blocks an unwanted connection, does the attacker learn anything from that, or does the asset simply not exist to them?

CISA didn't uncover a brilliant piece of hacking here. It found OT equipment that was listening when it shouldn't have been. That's a problem you can solve without waiting for a replacement budget, a maintenance window, or a vendor upgrade cycle. Make the equipment invisible to anyone who hasn't proven who they are, and this specific OT exposure closes. We're already showing operators across enterprises, critical infrastructure and government exactly what's reachable on their OT and ICS networks right now. Together, let's review your OT systems before they end up in the next advisory.

P.S. As we were finishing this piece, Coca-Cola confirmed that Fairlife, its dairy brand, halted milk production across the US after a ransomware attack. The company says unauthorized access reached beyond its IT systems and into elements of its production processes and OT environments. Canada kept running. The US plants didn't.

Coca-Cola hasn't said yet how the attacker got from the corporate network to the plant floor, and that's the exact question this whole piece has been about. Water utilities. Energy operators. Now a $4 billion dairy brand. Different industries, same story: production systems that should never have been reachable got reached anyway. We'll be watching this one.

Bobby Wescott is the Chief Revenue Officer of Invisinet Technologies. Invisinet's First Packet Authentication technology is patented and FIPS 140-3 validated (Certificate #5273, Active May 2026). It is currently deployed in U.S. government and critical infrastructure environments. For more information, visit invisinet.com.

Table of contents
sign up for newsletter
Receive updates on Invisinet’s solutions and security insights.