Particle.news
Download on the App Store

U.S. Warns Iran-Linked Hackers Are Altering PLCs From Rockwell, Siemens and Schneider

The agencies say attackers exfiltrated and changed controller project files to disable alarms and shutdowns, creating unsafe states and prompting urgent mitigation advice.

Overview

  • U.S. cyber agencies updated a joint advisory on July 22 that names specific targeted models: Rockwell/Allen‑Bradley CompactLogix and Micro850, Schneider BMX P34 and Modicon M340, and Siemens S7‑1200.
  • Investigators found attackers used vendor programming suites to download PLC project files to third‑party hosted infrastructure, then added instructions that overrode safety logic and manipulated HMI/SCADA displays.
  • The adversaries accessed internet‑exposed PLCs over ports such as 44818, 2222, 102, 502 and 22 and the agencies published indicators of compromise and detection steps for defenders to search logs and traffic.
  • The campaign has disrupted water, energy and government services and at least one U.S. victim had critical shutdown and alarm logic disabled, while some public hacktivist claims of impact have been disputed by affected organizations.
  • Agencies urge operators to remove PLCs from direct internet access, validate project files against unauthorized changes, follow vendor security guidance, and prepare for more costly audits and operational pulls as utilities harden systems.