CISA, FBI and EPA expand warning on Iran-linked attacks targeting Schneider Electric, Siemens, Rockwell and Allen-Bradley PLCs

U.S. agencies widened an earlier warning that Iran-linked hackers are attacking internet-exposed industrial control systems used by critical infrastructure and manufacturers. The updated CISA, FBI and EPA advisory says observed activity now includes programmable logic controllers (PLCs) from Schneider Electric, Siemens, Rockwell Automation and Allen-Bradley, along with malicious project-file interactions and tampering with human-machine interface (HMI) and supervisory control and data acquisition (SCADA) displays. Officials say victims have suffered operational disruption and financial loss.
Why it matters: This is a live threat to organizations that run industrial equipment, especially if control systems are reachable from the internet. Operators should urgently remove direct internet exposure, review secure PLC deployment, and inspect HMI/SCADA environments for unauthorized project files or display manipulation.

Sources

More than 100 water systems were hit in July cyberattacks
2026.08.26 82% relevant
The article ties the July water-sector intrusions to the same broader PLC-targeting campaign that federal agencies recently warned about, but here the concrete update is sector-specific scope: over 100 water and wastewater systems were hit, often via internet-exposed PLCs on cellular connections.
CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks
Eduard Kovacs 2026.08.26 87% relevant
The article updates the same Iran-linked PLC targeting campaign by quantifying impact at over 100 water-sector systems in July and tying the activity to internet-exposed PLCs, often directly reachable through cellular modems.
US sanctions Iranian cyber actors as UK discloses power plant attack
2026.08.24 56% relevant
The article references the same wave of Iran-linked operational-technology targeting by noting recent attacks on U.S. water systems and citing the FBI and NSA warning about hackers targeting programmable logic controllers used in energy, water, and agriculture.
Hackers Using AI to Target Siemens PLCs in Critical US Sectors
Eduard Kovacs 2026.08.20 83% relevant
This article appears to update the same broader U.S. government warning campaign about threats to industrial PLCs, adding that agencies say attackers are scanning for exposed Siemens S7 PLCs and using AI-generated scripts plus snap7 tooling to support initial access, credential access, denial-of-service, and ladder-logic tampering. It narrows the focus to Siemens S7-200/300/400/1200/1500 devices and reiterates the affected critical sectors.
'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers
2026.08.19 94% relevant
This is a direct update to the same Iran-linked PLC targeting campaign, adding that five U.S. agencies now say attackers are actively using AI coding assistants with snap7 libraries to generate custom exploitation tools against internet-exposed Siemens S7 controllers across water, manufacturing, energy, chemical, food, and commercial sectors.
NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology
2026.08.19 91% relevant
This article appears to update the same broader PLC-targeting campaign federal agencies warned about in July, adding a Siemens-specific advisory from NSA, FBI and partners that says the threat is active, emphasizes U.S.-based Siemens S7 Series PLCs, and says attackers are using AI-generated exploitation scripts disguised as monitoring tools.
US warns of AI-powered attacks on Siemens PLCs in critical infrastructure
Lawrence Abrams 2026.08.19 78% relevant
This article appears to update the same broader U.S. government warning campaign about attacks on internet-exposed PLCs in critical infrastructure, adding that agencies now say threat actors are using AI-generated Python scripts with snap7 libraries to target Siemens S7-200/300/400/1200/1500 devices and are focused on persistent reconnaissance that could precede disruption.
Water system controllers don't belong on the internet, says ex-NSA chief after suspected Iran attacks
2026.08.07 85% relevant
This article adds public comments from former NSA chief Paul Nakasone tying the recent wave of U.S. water-facility intrusions to likely Iranian actors, says at least 12 states' water systems were hit, and reinforces the defensive point that internet-exposed PLCs are a core weakness in the same campaign targeting operational technology.
Water utilities group partners with DEF CON offshoot for Water Watch Center
2026.08.07 49% relevant
The piece contextualizes the same broader Iran-linked water-sector threat activity by citing the growing campaign against U.S. water utilities and naming Iranian actors as a key concern, while adding a sector-level mitigation and support effort for small utilities.
Water system cyberattacks spread to Georgia, Michigan amid US-Iran conflict
2026.08.03 77% relevant
The article reinforces the broader federal warning by tying the Minnesota-linked water attacks to additional states and repeating that Rockwell Automation/Allen-Bradley PLCs have been observed in the incidents, while noting CISA guidance that Schneider Electric and Siemens devices may also be targeted by Iran-affiliated actors.
CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs
Mike Lennon 2026.07.30 74% relevant
The piece ties the Minnesota intrusions to CISA’s broader July 22 warning about Iran-linked PLC targeting, adding that the new July 30 water-sector alert says CISA is seeing a significant increase in attacks on exposed water PLCs and reiterates the affected PLC families and internet-exposure concerns.
Iran-linked crews are probing more flavors of US industrial kit
2026.07.23 98% relevant
This article reports the same widened U.S. government warning, adding that the activity extends beyond Rockwell/Allen-Bradley PLCs to Schneider Electric, Siemens, and potentially other vendors, and includes details on open-port targeting, Dropbear SSH abuse on victim modems, and attackers modifying or deleting PLC logic and disabling shutdown and alarm functions.
US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices
Eduard Kovacs 2026.07.23 97% relevant
This article directly updates that same U.S. government advisory, adding detail that investigators saw attacks against Rockwell CompactLogix and Micro850, Schneider Modicon M340, and Siemens S7-1200 PLCs, along with the use of vendor programming software, targeted ports, malicious project files, logic manipulation, disabled shutdown and alarm logic, and refreshed detection guidance and indicators.
Federal agencies broaden alert on Iran-linked OT attacks
2026.07.22 100% relevant
This article establishes a distinct tracked event: a broadened U.S. government alert tying Iran-linked activity to multiple PLC vendors and OT disruptions, not just one victim or a single product flaw.
← Back to all stories