CISA, FBI and EPA expand warning on Iran-linked attacks targeting Schneider Electric, Siemens, Rockwell and Allen-Bradley PLCs

U.S. agencies widened an earlier warning that Iran-linked hackers are attacking internet-exposed industrial control systems used by critical infrastructure and manufacturers. The updated CISA, FBI and EPA advisory says observed activity now includes programmable logic controllers (PLCs) from Schneider Electric, Siemens, Rockwell Automation and Allen-Bradley, along with malicious project-file interactions and tampering with human-machine interface (HMI) and supervisory control and data acquisition (SCADA) displays. Officials say victims have suffered operational disruption and financial loss.
Why it matters: This is a live threat to organizations that run industrial equipment, especially if control systems are reachable from the internet. Operators should urgently remove direct internet exposure, review secure PLC deployment, and inspect HMI/SCADA environments for unauthorized project files or display manipulation.

Sources

Iran-linked crews are probing more flavors of US industrial kit
2026.07.23 98% relevant
This article reports the same widened U.S. government warning, adding that the activity extends beyond Rockwell/Allen-Bradley PLCs to Schneider Electric, Siemens, and potentially other vendors, and includes details on open-port targeting, Dropbear SSH abuse on victim modems, and attackers modifying or deleting PLC logic and disabling shutdown and alarm functions.
US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices
Eduard Kovacs 2026.07.23 97% relevant
This article directly updates that same U.S. government advisory, adding detail that investigators saw attacks against Rockwell CompactLogix and Micro850, Schneider Modicon M340, and Siemens S7-1200 PLCs, along with the use of vendor programming software, targeted ports, malicious project files, logic manipulation, disabled shutdown and alarm logic, and refreshed detection guidance and indicators.
Federal agencies broaden alert on Iran-linked OT attacks
2026.07.22 100% relevant
This article establishes a distinct tracked event: a broadened U.S. government alert tying Iran-linked activity to multiple PLC vendors and OT disruptions, not just one victim or a single product flaw.
← Back to all stories