Federal agencies broaden alert on Iran-linked OT attacks
The federal government has expanded a warning that it issued in April about attacks on internet-facing operational technology (OT) by hackers affiliated with the Iranian regime.
The initial advisory focused on programmable logic controllers (PLCs) from manufacturers Rockwell Automation and Allen-Bradley. Wednesday’s revision “expands the manufacturer scope to include observed targeting of Schneider Electric, Siemens and possible other PLC manufacturers,” according to a news release from CISA.
The observed incidents include “malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays,” the advisory says. Targeted organizations suffered “operational disruption and financial loss.”
PLCs are core technology for critical infrastructure like power utilities, wastewater treatment and manufacturing plants. Officials from CISA, the FBI and the Environmental Protection Agency (EPA) said that the pressure from Iran-affiliated attackers is expected to continue.
“The additional manufacturers being targeted emphasizes the importance for OT owners and operators to restrict direct internet access and ensure secure PLC deployment,” the news release said.
PLCs from Schneider and Siemens are widely used in the U.S. and beyond.
President Donald Trump threatened Iranian critical infrastructure on Wednesday, saying the U.S. would target a bridge or a power plant if Tehran continued to target ships in the Strait of Hormuz.
The federal advisory does not mention specific cyberthreat groups or attacks. Attribution of Iranian government-affiliated attacks can be difficult because the regime sometimes uses ransomware gangs or other groups as cover, researchers say.
A pro-Iranian hacktivist group that attacked a Los Angeles transit agency was actually an arm of the country’s intelligence services, researchers said.
Joe Warminsky
has been the news editor for Recorded Future News since 2022. He has three decades of experience as an editor and writer in the Washington, D.C., area. He previously he helped lead CyberScoop for more than five years. Prior to that, he was a digital editor at WAMU 88.5, the NPR affiliate in Washington, and he spent more than a decade editing coverage of Congress for CQ Roll Call.



