Back to Feed
Nation-stateJul 23, 2026

US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices

US warns of Iranian hackers targeting Siemens, Schneider, Rockwell ICS devices with malicious PLC files.

Summary

US federal agencies issued an updated advisory detailing Iranian APT attacks on critical infrastructure industrial control systems, specifically targeting programmable logic controllers from Siemens, Schneider Electric, and Rockwell Automation. Attackers deployed malicious PLC project files to manipulate HMI/SCADA displays, disable safety logic, and disrupt operations in government, energy, and water sectors. The advisory includes new indicators of compromise and detection guidance.

Full text

The US government has updated a recent cybersecurity advisory describing Iran-linked attacks on critical infrastructure organizations, warning that hackers have been targeting industrial control systems (ICS) made by Siemens, Schneider Electric, and Rockwell Automation. The advisory was initially published in early April, when federal agencies said Iranian hackers had been conducting disruptive attacks targeting operational technology (OT) devices at organizations in the government services and facilities, energy, and water and wastewater sectors. The authoring agencies said at the time that threat groups had hacked internet-exposed programmable logic controllers (PLCs), naming Allen-Bradley devices made by Rockwell Automation. The hackers had used malicious PLC project files and manipulated the data displayed on human-machine interfaces (HMIs) and supervisory control and data acquisition (SCADA) systems. The updated advisory, published on July 22, adds Schneider Electric and Siemens to the list of vendors whose PLCs have been targeted by Iranian APT actors and notes that devices from other companies may also be targeted. In the case of one victim in the United States, FBI investigators discovered that the attacker had used configuration software to download a malicious project file to a PLC.Advertisement. Scroll to continue reading. “Analysis indicated the project file retained ladder logic for downstream function but added logic that overrode specific instruction sets responsible for maintaining safe operating parameters in the victim’s environment,” the updated advisory explains. Investigators are aware of attacks against Rockwell Automation CompactLogix and Micro850, Schneider Electric Modicon M340 (BMX P34), and Siemens S7-1200 series PLCs. The attacks targeted ports 44818, 2222, 102, 502, and 22, and the hackers connected to the vulnerable PLCs via manufacturers’ programming software and leased third-party-hosted infrastructure. The vendor configuration software targeted by APTs includes Rockwell Automation Studio 5000 Logix Designer, Schneider Electric EcoStruxure Control Expert, and Siemens TIA Portal. According to the updated advisory, the hackers extracted and exfiltrated PLC project files and then modified and deleted the logic in those files. The attackers included add-on instructions and manipulated data on HMI and SCADA displays. “Additionally, the changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators of the anomalies,” the advisory notes. The advisory now includes new guidance for detecting malicious activity, as well as updated indicators of compromise (IoCs). Iranian hacker groups targeting ICS/OT The Iranian government has been using hacktivist personas to carry out many of the attacks targeting ICS/OT. The group named CyberAv3ngers made many headlines in the past years for its attacks on such systems. A group named Handala has taken the lead this year, starting with a highly disruptive attack on the US medical technology giant Stryker. Last month, Handala claimed it could have disrupted the water supply after hacking systems owned by California Water Service (Cal Water). The hackers’ statements suggested they had gained deep access to ICS, but the water utility said it had found no evidence of activity in its OT environment. While cyber adversaries once focused primarily on exposed, poorly secured ICS, these latest findings demonstrate that their capabilities are steadily advancing, underscoring the need for organizations to maintain proactive, up-to-date defenses. Related: Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks Related: LA Metro Cyberattack Linked to Iranian State-Sponsored Hackers Related: Iranian APT Targets Aviation, Software Companies With Updated Tools Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security UpdatesRansomware Group Threatening to Leak Data Stolen From Coca-Cola’s FairlifeOpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support DataExploitation of ServiceNow Vulnerability Seen Days After DisclosureSonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before PatchNew Index Tracks Material Breaches — And Refuses to Add Up the LossesWP2Shell WordPress Vulnerabilities Exploited in the Wild Latest News Suno, Paidwork Data Breaches Affect Tens of Millions of AccountsPalo Alto Networks to Acquire Observability Platform Provider EmbraceFlaw in Adobe Extension With 300M Installs Enabled WhatsApp Data TheftWhen Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account TakeoverVibe-Coded Apps Riddled With Exploitable Security FlawsStrongestLayer Raises $4.1 Million in Seed Funding ExtensionFourth SharePoint Vulnerability Exploited in Past Month’s Wave of AttacksEndpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Closing the Exploitation Gap July 22, 2026 Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveAssaf Keren, who previously served as CSO/CISO at Qualtrics and PayPal, is Meta's new CISO.Jazz has named Sean Robinson, Rickie Goyal, Danielle Guetta, Shani Nago, and Lior Magram as VPs and Michael Calev as COO.AJ Shipley has been appointed Chief Product Officer at CrowdStrike.More People On The MoveExpert Insights When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors From model selection and automation to validation and measurable results, the right questions can help enterprises separate genuine AI capabilities from marketing hype. (Joshua Goldfarb) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • mitre_attack — T1505.004
  • mitre_attack — T1657
  • malware — Handala
  • malware — CyberAv3ngers

Entities

Siemens (vendor)Schneider Electric (vendor)Rockwell Automation (vendor)Siemens S7-1200 (product)Schneider Electric Modicon M340 (product)Rockwell Automation CompactLogix (product)