News Room
16
Share
Rockwell Automation Issues Urgent Directive to Disconnect Public-Facing ICS Devices Amid Global Infrastructure Threats
criticalCritical Infrastructure

Rockwell Automation Issues Urgent Directive to Disconnect Public-Facing ICS Devices Amid Global Infrastructure Threats

Rockwell Automation and CISA are urging the immediate disconnection of all internet-facing ICS devices due to 'heightened geopolitical tensions' and increasing state-sponsored targeting of water and energy sectors.

15 July 2026Last updated 20 August 20264 min readRockwell Automation / CISA / EPA
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Critical Infrastructure
Severity:
Critical
Actor Type:
Nation-State
Geography:
North America
Confidence:
High Confidence
CVE:
CVE-2021-22681
Source:
Rockwell Automation / CISA / EPA
Read Time:
4 min

Executive Summary

On July 14, 2026, Rockwell Automation, in coordination with the Cybersecurity and Infrastructure Security Agency (CISA), issued an emergency advisory (V3-2026-05) compelling industrial operators to immediately disconnect all Industrial Control Systems (ICS) and Operational Technology (OT) assets from the public-facing internet. This directive comes in response to a significant surge in unauthorized access attempts and successful infiltrations targeting critical infrastructure providers. The alert underscores a worsening threat landscape where nation-state actors are moving beyond reconnaissance toward active operational disruption. This follows recent data from the Environmental Protection Agency (EPA) indicating that over 70% of inspected US water facilities still harbor critical security gaps, including default credentials and lack of network segmentation.

Threat Analysis

The primary drivers for this emergency directive are the persistent activities of the China-linked 'Volt Typhoon' and the Iranian-affiliated 'Cyber Av3ngers.' Analysis of recent traffic patterns indicates that these groups are systematically scanning for internet-exposed Programmable Logic Controllers (PLCs) and Human-Machine Interfaces (HMIs). Unlike traditional cyber espionage, current activity patterns suggest a 'pre-positioning' strategy designed to facilitate disruptive kinetic effects in the event of further geopolitical escalation. The threat is not limited to large-scale utilities; small-to-mid-sized water treatment plants and regional energy distributors are being targeted due to perceived weaknesses in their security architecture.

Technical Details

The advisory specifically highlights the exploitation of several long-standing vulnerabilities combined with basic security failures. Key technical observations include:

  • Exploitation of Known Vulnerabilities: Active targeting of CVE-2021-22681 (CVSS 10.0) in Rockwell Automation Logix controllers and other legacy vulnerabilities that allow for unauthenticated remote code execution.
  • Living-off-the-Land (LotL): Actors are utilizing legitimate administrative tools (e.g., PowerShell, WMI) to maintain persistence within OT environments, making detection difficult for standard EDR solutions.
  • Credential Abuse: A majority of the observed compromises involved the use of default manufacturer passwords or the lack of Multi-Factor Authentication (MFA) on remote access portals like VPNs and RDP sessions.
  • Insecure Exposure: Hundreds of PLCs remain directly reachable via Shodan and Censys, exposing critical chemical dosing and valve control systems to direct manipulation.

Attribution Assessment

Encrygma Intelligence attributes these campaign escalations with high confidence to the People's Republic of China (PRC) state-sponsored group known as Volt Typhoon. Their tactics—specifically the focus on persistence within US and allied critical infrastructure without immediate data theft—align with historical disruptive doctrines. Moderate confidence is placed on the involvement of the Iranian IRGC-linked group Cyber Av3ngers, who have shifted their focus to targeting Israeli-manufactured technology (e.g., Unitronics) within the global water sector to achieve political signaling through service disruption.

Implications

The continued exposure of ICS devices represents a critical risk to public safety. A successful breach of a water treatment facility could lead to the manipulation of chemical levels (e.g., chlorine or lye) or the disruption of water supply to healthcare facilities and residential areas. In the energy sector, unauthorized access to grid-tied controllers could facilitate localized blackouts or damage to expensive transformer equipment that carries long replacement lead times.

Recommendations

  • Immediate Disconnection: Audit all OT assets and immediately disconnect any device that does not have an absolute operational requirement for internet connectivity.
  • Enforce MFA: Implement hardware-based Multi-Factor Authentication for all remote access points into the OT network.
  • Password Hardening: Conduct an immediate sweep to identify and change all default manufacturer passwords on PLCs, HMIs, and industrial routers.
  • Network Segmentation: Employ a 'Purdue Model' approach to isolate OT environments from IT business networks using robust firewalls and unidirectional gateways (data diodes).
  • Incident Response: Update and exercise site-specific incident response plans that include 'manual override' procedures for critical industrial processes.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo