Over the past year, geopolitical friction between the United States and Iran has continued to influence cyber activity, particularly in the industrial control systems (ICS) space. Throughout March 2026, several Iranian-linked actors publicly claimed responsibility for attacks targeting ICS infrastructure across different regions.
In this report, we revisit four ICS technologies that have historically drawn attention from Iranian threat groups. These include:
- Unitronics Vision PLC/HMIs
- Orpak SiteOmat systems
- Red Lion industrial equipment
- Tridium Niagara framework
Our updated analysis compares exposure data from June 2025 to March 2026. While there is a noticeable global decline in exposed devices, the risk remains significant due to continued misconfigurations and weak security practices.
Introduction
Back in June 2025, rising tensions between Iran and the United States coincided with increased cyber activity targeting ICS environments. At that time, we evaluated how widely exposed certain ICS systems were on the public internet.
It’s important to clarify that these systems are rarely “targeted” in a precise, surgical way. Instead, attackers often exploit devices that are simply easy to find—those exposed online with weak or default credentials. In many cases, poor security hygiene creates opportunities rather than intentional targeting.
Now, in early 2026, we revisited the same systems to understand how their exposure has changed over time. The goal was to measure whether organizations have improved their security posture or if the attack surface remains largely unchanged.

Devices Analyzed
1. Unitronics Vision PLC/HMI
Unitronics produces industrial controllers and interfaces widely used across sectors like water and wastewater management. Historically, these systems shipped with a default password (“1111”), making them easy targets if left unchanged.
Communication between these devices relies on a proprietary protocol known as PCOM.
2. Orpak SiteOmat
SiteOmat is a fuel management platform used in gas stations and fleet systems. It originally shipped with default credentials (“Admin/Admin”), which significantly increases risk when exposed online.
3. Red Lion Industrial Systems
Red Lion manufactures industrial HMIs, controllers, and meters used in sectors such as oil & gas, manufacturing, and automation. Their Crimson software simplifies device configuration but does not inherently protect against exposure risks.
4. Tridium Niagara Framework
Niagara is widely used in building management systems (BMS), enabling centralized control of lighting, HVAC, and security. It communicates via the FOX protocol.
Global Exposure Trends
The following table summarizes exposure changes between June 2025 and March 2026:
| Device Type | June 2025 | March 2026 | Change |
|---|---|---|---|
| Unitronics | 1,697 | 1,649 | -2.8% |
| Orpak SiteOmat | 123 | 85 | -30.9% |
| Red Lion | 2,639 | 2,303 | -12.7% |
| Tridium Niagara | 43,167 | 40,200 | -6.9% |
All four categories show a decline in exposure, though the scale and pattern differ.
- Orpak SiteOmat shows the sharpest and most consistent reduction.
- Unitronics and Red Lion show gradual, stable decreases.
- Tridium Niagara displays unusual fluctuation, peaking above 62,000 instances in late 2025 before dropping again.
These variations suggest that while some remediation efforts are happening, they are uneven across technologies and regions.
Important Context
The numbers in this report represent exposed devices, not necessarily vulnerable ones. However, exposure itself is a major risk—especially for systems tied to critical infrastructure.
Even a well-configured system becomes a potential target when directly accessible from the internet.
Detailed Findings
Unitronics Systems
Unitronics devices gained attention after a 2023 defacement campaign attributed to CyberAv3ngers, a group linked to Iranian interests. These attacks were made possible largely due to default credentials and internet exposure.
Key observations:
- Australia still hosts the highest number of exposed systems
- The United States and Netherlands saw reductions of 39% and 26%
- Israel experienced a 12% increase overall
Interestingly, Israel’s exposure dropped between May and September 2025 before rising again in early 2026. While no direct cause can be confirmed, this period aligns with heightened concerns about cyber threats.
Another notable trend is the sharp decline (53%) on CELLCO-PART (Verizon), driven by reduced U.S. exposure.

Orpak SiteOmat
These systems were also reportedly compromised in 2023 using default credentials.
Findings include:
- The United States remains the largest source of exposure
- Turkey reduced its exposure by 51%
- Chile showed a slight increase
Telecom-level changes were also observed:
- TURKCELL saw a 57.7% drop, reflecting Turkey’s overall decline
- ENTEL Chile showed slight growth, aligning with increased exposure
Red Lion Devices
Red Lion systems were linked to IOCONTROL malware activity reported in 2024, believed to be used by Iranian actors targeting ICS and IoT environments.
Key trends:
- The United States still leads in exposure despite a 15.8% reduction
- France, Canada, and the UK follow at much lower levels
- Decreases were observed across major U.S. ISPs like CELLCO-PART and ATT
Interestingly, exposure via satellite providers like Starlink increased, highlighting how non-traditional networks are becoming part of the ICS landscape.
Tridium Niagara
Although no confirmed Iranian attacks have directly targeted Niagara, there is evidence of interest in these systems.
Recent claims from groups such as the Cyber Islamic Resistance suggest attacks on building management systems in Israel. These include incidents affecting hotels and universities, where attackers allegedly disrupted electricity, water, and access control systems.
Observations:
- The U.S. dominates global exposure
- Canada, Italy, and the UK follow distantly
- Most systems are hosted on consumer or mobile ISPs
This distribution creates challenges in identifying responsible organizations and coordinating remediation.
Conclusion
The overall reduction in exposed ICS systems is a positive sign. It suggests that awareness around cybersecurity risks in industrial environments is improving, even if slowly.
However, several concerns remain:
- Many systems are still exposed via consumer-grade networks
- Attribution remains difficult due to ISP-based deployments
- Default credentials and weak authentication continue to be exploited
Ultimately, reducing exposure is one of the simplest and most effective defenses. Removing ICS devices from direct internet access should remain a top priority for operators.
Indicators of Risk (IOCs / Key Risk Factors)
- Default credentials (e.g., “1111”, “Admin/Admin”)
- Publicly exposed ICS interfaces
- Devices accessible via mobile or consumer ISPs
- Use of proprietary protocols without additional protection (PCOM, FOX)
- Unpatched or legacy ICS firmware
Our Analysis and Opinion
From our perspective, the findings in this report highlight a recurring issue in industrial cybersecurity: the gap between awareness and execution. While exposure numbers are decreasing, the pace of improvement is not strong enough given the stakes involved. Critical infrastructure systems are still being deployed in ways that make them easily discoverable and, in many cases, exploitable.
What stands out most is not the sophistication of attackers, but the simplicity of their entry points. Default credentials, direct internet exposure, and lack of segmentation continue to be the primary weaknesses. These are not advanced vulnerabilities—they are basic security failures.
Another concern is the growing presence of ICS devices on consumer and satellite networks. This trend complicates accountability and makes coordinated defense more difficult. Organizations may not even realize their assets are exposed in such environments.
In our view, the industry needs to shift from reactive fixes to proactive design. Security should not be an afterthought added post-deployment. Instead, it must be embedded into how these systems are configured, monitored, and maintained from the beginning.
Until that shift happens, opportunistic attacks will continue to succeed—even without advanced techniques.
