US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices

The US government has sounded a warning bell about Iranian hackers targeting critical infrastructure organizations in the United States and elsewhere. The threat groups, linked to the Iranian government, have been using advanced tactics to infiltrate industrial control systems (ICS) made by top manufacturers such as Siemens, Schneider Electric, and Rockwell Automation.

According to a recent update to a cybersecurity advisory issued by US federal agencies, Iranian hackers have been conducting disruptive attacks on operational technology (OT) devices at organizations in the government services and facilities, energy, and water and wastewater sectors. The attackers are said to be exploiting vulnerabilities in programmable logic controllers (PLCs), which are used to control industrial processes.

The hackers use malicious PLC project files, downloaded through configuration software, to manipulate data displayed on human-machine interfaces (HMIs) and supervisory control and data acquisition (SCADA) systems. This allows them to gain deep access to the affected systems and potentially cause significant disruptions or even physical damage. In one case investigated by FBI agents, a malicious project file was used to override critical safety protocols in a victim’s environment.

The advisory warns that devices from other manufacturers may also be targeted, and lists specific models of PLCs that have been compromised, including Rockwell Automation CompactLogix and Micro850, Schneider Electric Modicon M340 (BMX P34), and Siemens S7-1200 series PLCs. The attackers are using a range of ports to connect to the vulnerable PLCs, including 44818, 2222, 102, 502, and 22.

The Iranian government has been linked to several high-profile cyberattacks in recent years, with groups such as CyberAv3ngers and Handala carrying out attacks on ICS/OT systems. These groups have claimed responsibility for disrupting operations at US companies, including Stryker and California Water Service (Cal Water). While the effectiveness of these claims is unclear, they demonstrate the increasingly sophisticated capabilities of Iranian hackers.

The latest findings underscore the need for organizations to maintain proactive, up-to-date defenses against ICS/OT threats. The advisory provides new guidance on detecting malicious activity and includes updated indicators of compromise (IoCs) to help organizations identify potential attacks. As the threat landscape continues to evolve, it’s essential that critical infrastructure organizations prioritize their cybersecurity efforts to prevent disruptions and protect public safety.

The takeaway for security professionals is clear: Iranian hackers are now targeting ICS/OT systems with a level of sophistication previously seen only in high-end nation-state operations. To stay ahead of these threats, organizations must ensure their defenses are up-to-date, including implementing regular software updates, conducting thorough risk assessments, and monitoring their networks for signs of suspicious activity.


Source: SecurityWeek — 2026-07-23