U.S. federal agencies have updated a cybersecurity advisory warning that Iran-linked threat actors are targeting internet-exposed industrial control system devices and programmable logic controllers from Siemens, Schneider Electric, and Rockwell Automation. Investigators said the attackers used legitimate vendor programming software to connect to vulnerable PLCs, steal project files, alter ladder logic, and interfere with safety-related functions, including disabling shutdown and alarm mechanisms while manipulating HMI and SCADA displays to conceal the changes.
The activity has affected organizations in government services, facilities, energy, and water and wastewater sectors, with identified targeting that includes Rockwell CompactLogix and Micro850, Schneider Electric Modicon M340, and Siemens S7-1200 devices. The updated advisory adds refreshed indicators of compromise and detection guidance, and places the campaign in the broader pattern of Iranian operational technology intrusions associated with groups such as CyberAv3ngers and Handala, underscoring the risk of disruptive or destructive attacks against critical infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
U.S. federal agencies updated a cybersecurity advisory warning that Iran-linked threat actors are targeting internet-exposed industrial control system devices, including PLCs from Siemens, Schneider Electric, and Rockwell Automation. The update added detection guidance and refreshed indicators of compromise, and described attacker actions such as exfiltrating project files, modifying ladder logic, and disabling shutdown and alarm functions.
U.S. agencies said Iranian-affiliated threat actors have been observed since at least March 2026 targeting internet-exposed operational technology in the U.S. water and energy sectors. The activity included accessing exposed PLCs, exfiltrating project files, modifying controller logic, manipulating HMI/SCADA displays, and disabling shutdown and alarm functions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
17 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceblog.polyswarm.io
Open sourcecommunity.gurucul.com
Open sourcesecurityaffairs.com
Open sourcecommunity.gurucul.com
Open sourcetechcrunch.com
Open sourceic3.gov
Open sourcevifindia.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.