Jul 23, 2026
Policy

CISA Iran PLC alert expands to Schneider Electric and Siemens devices

CISA says Iranian-affiliated hackers may be targeting more PLC brands at US water and energy facilities, with internet-facing devices at risk.

Dominic Okoye

By Dominic Okoye · Staff Writer

· 3 min read

CISA Iran PLC alert expands to Schneider Electric and Siemens devices
Photo: The Register

CISA’s Iran PLC alert now covers more than Rockwell Automation and Allen-Bradley equipment, after the agency warned that Iranian-affiliated hackers may also be going after Schneider Electric, Siemens and possibly other industrial controllers. The expansion matters for operators in water, energy and other critical infrastructure because the activity targets programmable logic controllers exposed to the internet, a recurring weakness in operational technology environments.

The Cybersecurity and Infrastructure Security Agency said the activity has been observed since March, as the US-Iran conflict enters its fourth month. Authorities described the actors as Iranian-affiliated advanced persistent threat crews seeking disruption by targeting PLCs, the devices used to monitor and control industrial processes.

CISA linked the pattern to earlier PLC attacks associated with CyberAv3ngers, also known as the Shahid Kaveh Group. Authorities have tied that group to Iran’s Islamic Revolutionary Guard Corps Cyber Electronic Command.

What did CISA add to the Iran PLC alert?

The original warning centered on PLCs made by Rockwell Automation and Allen-Bradley. CISA has now broadened its guidance after seeing signs that the same activity may extend to equipment from Schneider Electric and Siemens, along with other manufacturers not yet named.

According to CISA, the targeting of ports used by other operational technology vendors suggests the actors are looking opportunistically for reachable devices rather than limiting themselves to one supplier’s hardware. That is a practical distinction for security teams: the brand list is widening, but the core risk remains internet-exposed industrial control gear.

CISA also reported one incident in which the actors used Dropbear Secure Shell software on victim modems to maintain remote access through port 22. Once inside, the agency said, attackers took project files from devices and changed or removed logic from the PLCs.

The operational risk is more direct than data theft. CISA said some changes disabled shutdown and alarm functions, which could let systems enter unsafe states without operators receiving alerts. The agency did not disclose the number of affected facilities, name victims or say whether any physical damage occurred.

What should industrial operators do now?

The updated advisory puts asset visibility back at the center of the response. Operators need to know which PLCs are reachable from the public internet, which ports are open and which third parties have access to devices that control physical processes.

  • Disconnect PLCs from public-facing internet access where possible.
  • Use isolated architectures for operational technology networks.
  • Control and restrict network access to PLC devices.
  • Review PLC project files for unauthorized changes.
  • Make sure service providers know PLCs are being targeted.
  • Replace default passwords on industrial devices and related network equipment.

The broadened scope is a reminder that vendor-specific advisories can age quickly when attackers are scanning for exposed OT interfaces. For operators, the immediate question is less which brand is named next and more whether critical control logic can be reached, altered or erased from outside the plant network.

This story draws on original reporting from The Register.

More from Policy

All Policy →