U.S. federal agencies have updated a cybersecurity advisory warning that Iran-linked threat actors are targeting internet-exposed industrial control system devices and programmable logic controllers from Siemens, Schneider Electric, and Rockwell Automation. Investigators said the attackers used legitimate vendor programming software to connect to vulnerable PLCs, steal project files, alter ladder logic, and interfere with safety-related functions, including disabling shutdown and alarm mechanisms while manipulating HMI and SCADA displays to conceal the changes.
The activity has affected organizations in government services, facilities, energy, and water and wastewater sectors, with identified targeting that includes Rockwell CompactLogix and Micro850, Schneider Electric Modicon M340, and Siemens S7-1200 devices. The updated advisory adds refreshed indicators of compromise and detection guidance, and places the campaign in the broader pattern of Iranian operational technology intrusions associated with groups such as CyberAv3ngers and Handala, underscoring the risk of disruptive or destructive attacks against critical infrastructure.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Public reporting described a widening campaign targeting internet-exposed PLCs in U.S. water and wastewater systems across at least a dozen states. Minnesota said more than 30 water systems were targeted, and related incidents were reported in Georgia, Michigan, South Dakota, Alabama, and New Jersey, with some operators locked out of PLCs and forced to use manual workarounds.
U.S. federal agencies updated a cybersecurity advisory warning that Iran-linked threat actors are targeting internet-exposed industrial control system devices, including PLCs from Siemens, Schneider Electric, and Rockwell Automation. The update added detection guidance and refreshed indicators of compromise, and described attacker actions such as exfiltrating project files, modifying ladder logic, and disabling shutdown and alarm functions.
U.S. agencies said Iranian-affiliated threat actors have been observed since at least March 2026 targeting internet-exposed operational technology in the U.S. water and energy sectors. The activity included accessing exposed PLCs, exfiltrating project files, modifying controller logic, manipulating HMI/SCADA displays, and disabling shutdown and alarm functions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 27 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
19 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcelevelblue.com
Open sourcecybersecuritynews.com
Open sourceblog.polyswarm.io
Open sourcecommunity.gurucul.com
Open sourcetheregister.com
Open sourceic3.gov
Open sourcevifindia.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.