US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices

The US government has issued a stern warning about Iranian hackers targeting critical infrastructure organizations, including those that rely on industrial control systems (ICS) from leading vendors such as Siemens, Schneider Electric, and Rockwell Automation. The attackers have been using sophisticated tactics to gain access to operational technology (OT) devices, putting the safety of people and the integrity of systems at risk.

The threat groups behind these attacks have been linked to the Iranian government, which has been using hacktivist personas to carry out their operations. One such group, known as Handala, made headlines earlier this year when it claimed to have disrupted a US medical technology giant’s systems and threatened to sabotage the water supply of a California-based utility company. While the latter incident turned out to be unfounded, it highlights the growing capabilities of these Iranian hackers.

The attackers are primarily targeting programmable logic controllers (PLCs), which are used to control industrial processes in various sectors, including energy and government services. They gain access to these devices by exploiting vulnerabilities in their programming software, such as Rockwell Automation’s Studio 5000 Logix Designer and Siemens’ TIA Portal. Once inside, the hackers extract and modify PLC project files, adding malicious logic that can override safety parameters and cause systems to malfunction.

One of the most disturbing aspects of these attacks is the way they manipulate data on human-machine interfaces (HMIs) and supervisory control and data acquisition (SCADA) systems. This allows the attackers to deceive operators into thinking everything is functioning normally, even when critical shutdown and alarm logic have been disabled. This can lead to catastrophic consequences, including equipment damage, environmental disasters, or even loss of life.

The US government has updated its advisory on this threat, which was first issued in April, to include Schneider Electric and Siemens as vendors whose PLCs have been targeted by Iranian hackers. The advisory also notes that other companies may be vulnerable to similar attacks. To mitigate these risks, organizations are urged to maintain up-to-date defenses, including regular software updates and monitoring of network activity for signs of unauthorized access.

In light of this threat, it’s essential for organizations that rely on ICS/OT devices to take proactive measures to protect themselves. This includes implementing robust security protocols, conducting regular vulnerability assessments, and training operators to recognize the warning signs of a potential attack. By staying vigilant and informed, we can reduce the likelihood of these devastating attacks occurring in the first place.


Source: SecurityWeek — 2026-07-23