U.S. cyber and law enforcement agencies have broadened an April warning about Iran-linked attacks on industrial control equipment, adding Schneider Electric and Siemens programmable logic controllers to the list of observed targets.
The Cybersecurity and Infrastructure Security Agency said in a Wednesday release that a revised federal advisory now covers attacks seen against Schneider Electric, Siemens and possibly other PLC makers. The earlier warning focused on Rockwell Automation and Allen-Bradley controllers.
That expansion matters for utilities, water systems and factories because PLCs sit close to the physical process. They read sensor data and send commands to machinery, pumps, valves and other equipment. If an owner leaves that gear reachable from the public internet, attackers do not need to breach a normal corporate network first. They can try to talk to the controller directly, which is usually a terrible architectural choice dressed up as convenience.
The revised advisory from CISA, the FBI and the Environmental Protection Agency says agencies have observed malicious interactions with project files and manipulation of data shown on human-machine interface and supervisory control and data acquisition displays. HMI and SCADA screens are the panels operators use to monitor and manage industrial processes. The advisory says affected organizations experienced operational disruption and financial loss.
CISA did not name victim organizations in the public alert. The advisory also does not identify a specific Iranian hacking unit or list particular incidents. That leaves the public with a warning about tactics and exposure rather than a neat attribution chart.
Agencies urge owners to take PLCs off the open internet
CISA, the FBI and EPA said Iran-affiliated attackers are expected to keep pressuring operational technology operators. In its release, CISA said the broader set of targeted manufacturers underscores the need for OT owners and operators to block direct internet access and deploy PLCs securely.
Schneider and Siemens controllers are widely deployed in the United States and abroad, so the alert is not a niche warning for one vendor’s customer base. The practical advice is the familiar part: reduce exposure, segment industrial systems from business networks, and treat engineering workstations and project files as high-value assets. The advisory’s concern is that internet-facing PLCs give attackers a simpler path into systems that were designed to run equipment, not absorb hostile traffic from the open web.
The warning lands amid broader tension with Tehran. President Donald Trump said Wednesday that the United States would target Iranian critical infrastructure, such as a bridge or power plant, if Iran continued targeting ships in the Strait of Hormuz, according to The New York Times.
Attribution around Iran-linked cyber activity can be messy. Researchers have said Iranian government operations have used ransomware crews or other groups as cover. Researchers also previously assessed that a pro-Iranian hacktivist group behind an attack on a Los Angeles transit agency was actually tied to Iran’s intelligence services.
The federal advisory stays narrower than that history. It says Iran-affiliated hackers are targeting internet-exposed industrial controllers from more manufacturers than agencies had previously named, and that organizations have already paid for that exposure in downtime and money.
This story draws on original reporting from The Record.