Threat Insight
Iranian Cyberattacks Against Critical Infrastructure
An Iranian threat actor has conducted a series of cyberattacks against critical infrastructure in USA and UK in late July 2026. Known targets include several community water treatment facilities in Minnesota, USA [1] and a relatively small energy plant in Britain. [2]
The attacks appear to have targeted operational technology (OT) devices like programmable logic controllers (PLCs). A warning from FBI specifically mentioned Rockwell Automation and Allen-Bradley PLCs – particularly the MicroLogix 1100 and 1400 series – although systems using PLCs from other brands were also advised to be cautious. [1]
Assessment
Based on available information, it appears that these attacks have been mostly unsophisticated and opportunistic attacks targeting relatively small plants with minimum security, likely having OT devices exposed to the internet without proper protection. Given the limited impact of these attacks, it appears they were mostly aimed at creating psychological impact rather than real damage.
Truesec has previously assessed that the risk of destructive cyberattacks from Iran against Europe as low, as long as European countries don’t get directly involved in the conflict between USA and Iran. This assessment still stands.
While UK and France are not participating in the US led attacks on Iran. Both countries are honoring their bilateral defense agreements with several Gulf-states and assist them in shooting down incoming Iranian missiles, which is likely the reason Iran have also targeted Britain in the wave of cyberattacks.
The main threat to critical infrastructure in the Nordics is still Russian threat actors. The above attacks still highlight the need for heightened cybersecurity awareness in all parts of critical infrastructure, not just the most vital parts of it. Swedish authorities have previously announced that a Russian threat actor has attempted a similar attack against a Swedish power plant. [3]
If you or your organization have concerns about the topic above or need support, please reach out to your Truesec contact for further assistance.
References
[1] https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet–facing-programmable-logic-controllers-causing-operational-disruptions
[2] https://www.telegraph.co.uk/news/2026/08/22/iranian-hackers-shut-down-uk-power-plant/
[3] https://www.tv4.se/artikel/17J99Fsf8GKue4fYSFcxVF/proryskt-angreppsfoersoek-mot-svenskt-vaermeverk
Stay ahead with cyber insights
Newsletter
Stay ahead in cybersecurity! Sign up for Truesec’s newsletter to receive the latest insights, expert tips, and industry news directly to your inbox. Join our community of professionals and stay informed about emerging threats, best practices, and exclusive updates from Truesec.
Your current browser privacy settings may be preventing this form from loading properly. To continue, please allow cookies/tracking for this site or temporarily disable strict privacy protection, then refresh the page.
If you’re still experiencing issues, please contact us at hello@truesec.com