CISA broadens warning on Iranian-linked attacks against internet-exposed PLCs

CISA broadens warning on Iranian-linked attacks against internet-exposed PLCs

CISA updated its warning on Iranian-linked PLC attacks, expanding scope to Schneider Electric, Siemens and other exposed systems.

Format News Brief
Read Time 2 min
Category Cyber Security
Updated Jul 23, 2026

CISA, the FBI, the Environmental Protection Agency and other U.S. government partners have updated a joint cybersecurity advisory on Iranian-affiliated activity against programmable logic controllers, adding fresh detection guidance and expanding the list of industrial systems that defenders should treat as exposed risk.

The July 22 update says the campaign is no longer framed only around Rockwell Automation and Allen-Bradley environments. CISA's revised advisory says observed targeting now includes Schneider Electric and Siemens PLCs as well, and warns that potentially all internet-exposed PLCs should be considered in scope. The agencies say the activity has affected multiple U.S. critical infrastructure sectors, including water and wastewater, energy, government services and local municipalities.

What changed

The new guidance focuses on reusable code modules in Rockwell Automation PLC programs, where defenders are being asked to look for malicious changes. The advisory also points operators toward network-log review for suspicious traffic on ports commonly associated with operational technology devices, including 44818, 2222, 102 and 502, especially when that traffic originates from foreign hosting providers.

CISA says the reported activity involves malicious interaction with project files and manipulation of data shown on human-machine interface and SCADA displays. In practical terms, that can disrupt operations even when attackers do not directly damage physical equipment, because plant operators rely on those displays to understand what industrial processes are doing in real time.

Why it matters

The warning lands in a high-risk corner of security: internet-reachable industrial control systems that were often designed for reliability and long service life rather than exposure to hostile networks. The agencies are urging owners and integrators to remove PLCs from direct internet access, put them behind secure gateways and firewalls, validate project files for unauthorized changes and coordinate with service providers that manage operational technology environments.

The alert also links the current concern to earlier Iranian-linked activity against PLCs and HMIs, including disruptive campaigns that targeted water and wastewater systems. For smaller utilities and municipal operators, the update is a reminder that basic architecture choices, especially whether a controller can be reached directly from the internet, can determine whether a distant actor can turn a cyber intrusion into an operational incident.

  • Organizations should review PLC manufacturer security guidance and deployment recommendations.
  • Operators should restrict network access to PLC devices and inspect logs for the listed indicators of compromise.
  • Suspected targeting should be reported to the authoring agencies and the relevant PLC manufacturer.

Sources

Cover photo by Fernando Narvaez on Pexels, used under the Pexels License.

Comments (0)

Leave a Comment

Loading comments...