Targeting US Critical Infrastructure Systems
Multiple Adversaries, One Attack Surface
The FBI’s Internet Crime Complaint Center (IC3) issued a September 23, 2026 industry alert specifically addressing risks faced by critical-infrastructure operators that rely on third-party Industrial Control System (ICS) integrators. The warning adds to a growing set of federal advisories documenting malicious cyber activity involving U.S. infrastructure, including China-linked activity against critical infrastructure, Iranian-affiliated exploitation of Programmable Logic Controllers (PLCs), and recent North Korean activity targeting IT professionals and organizations.
The important feature is the common attack surface, rather than assuming these activities are part of one coordinated campaign. Third-party access, internet-facing or vulnerable edge devices, Operational Technology (OT) and PLC environments, as well as compromised credentials can provide different actors with pathways into organizations that operate physical systems. The FBI and EPA have already documented PLC compromises that caused operational effects in U.S. water and wastewater systems, including loss of pressure and flooding, demonstrating how cyber access to OT can produce physical consequences.
For defenders, the relevant indicators are therefore broader than malware signatures or attribution alone: Who has remote access? Which third parties can reach operational systems? Which edge devices remain exposed? Which credentials have unusual activity? And can an intrusion move from IT networks into OT? The FBI's current cyber guidance emphasizes that the U.S. attack surface is expanding and that nation-state actors including China, Iran and North Korea continue to target U.S. victims and critical infrastructure.
SOURCES
FBI Internet Crime Complaint Center (IC3) — September 23, 2026
Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators
FBI/IC3 Industry Alerts
FBI/EPA — July 30, 2026
Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions
FBI Cyber Alert
FBI/CISA/NSA/CNMF — August 26, 2026
China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure
FBI Cyber Alerts
FBI — July 22, 2026
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across U.S. Critical Infrastructure
FBI Cyber Alert
FBI — September 18, 2026
North Korean “WaterPlum” / “Contagious Interview” Cyber Activity
FBI Cyber Alerts