Federal agencies have broadened an alert regarding attacks on internet-facing operational technology (OT) by hackers linked to the Iranian regime. The updated warning, issued by the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Environmental Protection Agency (EPA), expands on an initial advisory from April.
The initial alert focused on programmable logic controllers (PLCs) manufactured by Rockwell Automation and Allen-Bradley. The revised advisory now includes observed targeting of Schneider Electric and Siemens PLCs, along with the possibility of other manufacturers.
According to CISA, the observed incidents involve "malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays." These attacks have resulted in "operational disruption and financial loss" for targeted organizations.
PLCs are fundamental components in critical infrastructure sectors such as power utilities, wastewater treatment facilities, and manufacturing plants. Officials anticipate that the pressure from Iran-affiliated attackers will persist.
The agencies emphasized the importance for OT owners and operators to restrict direct internet access to these systems and ensure secure PLC deployment. PLCs from Schneider Electric and Siemens are extensively deployed both within the United States and internationally.
The advisory does not specify particular cyberthreat groups or individual attacks. Cybersecurity researchers note that attributing attacks to the Iranian government can be complex, as the regime has been known to utilize ransomware gangs or other groups as proxies to obscure its involvement. For instance, a pro-Iranian hacktivist group that targeted a Los Angeles transit agency was later identified by researchers as an arm of Iran’s intelligence services.






