Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices

0
Medium
Vulnerability
Published: 07/23/2026 (07/23/2026, 05:28:50 UTC)
Source: SecurityWeek

Description

The US government issued an updated advisory warning of Iranian state-linked hackers targeting industrial control systems (ICS) from Siemens, Schneider Electric, and Rockwell Automation. The attackers exploited internet-exposed programmable logic controllers (PLCs) by using malicious project files to manipulate control logic, disable safety functions, and alter data displayed on human-machine interfaces (HMIs) and SCADA systems. The advisory highlights attacks on specific PLC models including Rockwell CompactLogix and Micro850, Schneider Modicon M340, and Siemens S7-1200 series. Iranian APT groups used vendor programming software and third-party infrastructure to connect to and compromise these devices. The advisory includes new detection guidance and indicators of compromise but does not specify patches or fixes. The threat underscores the evolving capabilities of Iranian cyber adversaries targeting critical infrastructure operational technology (OT).

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/23/2026, 05:37:15 UTC

Technical Analysis

An updated US federal advisory details Iranian APT groups targeting ICS devices from Siemens, Schneider Electric, and Rockwell Automation. Attackers exploited internet-exposed PLCs by downloading malicious project files via vendor programming software (Rockwell Studio 5000 Logix Designer, Schneider EcoStruxure Control Expert, Siemens TIA Portal). These files retained legitimate ladder logic but added malicious instructions overriding safety controls, disabling shutdown and alarm logic, and manipulating HMI/SCADA data. Targeted PLC models include Rockwell CompactLogix and Micro850, Schneider Modicon M340 (BMX P34), and Siemens S7-1200 series. Attackers connected over ports 44818, 2222, 102, 502, and 22 using leased third-party infrastructure. The advisory provides updated detection techniques and IoCs but does not mention available patches or fixes. The activity reflects advancing Iranian ICS attack capabilities against critical infrastructure sectors such as energy, water, and government services.

Potential Impact

The attacks allow adversaries to manipulate PLC logic, disable critical safety shutdowns and alarms, and falsify data on operator interfaces, potentially causing unsafe operational conditions without operator awareness. This compromises the integrity and availability of industrial control processes in critical infrastructure sectors. The advisory does not report confirmed successful disruptions but indicates significant risk to operational safety and reliability. No known exploits in the wild are confirmed beyond the advisory's findings.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The advisory includes updated detection guidance and indicators of compromise for identifying malicious activity. Organizations should monitor for unauthorized project file changes and connections to PLCs via vendor programming software. Since no official fixes or patches are stated, applying vendor security updates when available and restricting network exposure of PLCs and programming interfaces is recommended. Follow the advisory's specific detection and response recommendations.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.securityweek.com/us-warns-of-iranian-hackers-targeting-siemens-schneider-and-rockwell-ics-devices/","fetched":true,"fetchedAt":"2026-07-23T05:37:04.960Z","wordCount":1275}

Threat ID: 6a61a8809c2644c7f86f898c

Added to database: 07/23/2026, 05:37:04 UTC

Last enriched: 07/23/2026, 05:37:15 UTC

Last updated: 07/23/2026, 07:12:25 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses