Iranian PLC Attacks: CISA Expands Siemens, Schneider Warning

CISA, FBI, NSA, and partners expanded an Iranian OT attack warning to Siemens and Schneider PLCs, urging owners to remove direct internet exposure and review project logic.

CISA, the FBI, NSA, EPA, DOE, U.S. Cyber Command, and Treasury have expanded their warning about Iranian-affiliated attacks on internet-exposed operational technology. The July 22, 2026 update to advisory AA26-097A says the activity now includes observed targeting of Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and possibly other programmable logic controllers, with victims seeing malicious project-file activity, manipulated HMI/SCADA displays, operational disruption, and financial loss.[1]

The update matters because it moves the warning beyond a narrow Rockwell-focused alert. CISA says the actors used leased third-party infrastructure and legitimate PLC configuration tools to connect to misconfigured devices, pull project files, and modify or delete logic. For defenders, this is not just a password-reset problem. A PLC can look reachable, patched, and online while its running project file or reusable logic has been changed in a way that affects alarms, shutdown logic, or safe operating parameters.[1]

What OT owners should check now

The advisory names Rockwell Automation CompactLogix and Micro850 PLCs, Schneider Electric BMX P34/Modicon M340 PLCs, and Siemens S7-1200 series PLCs among the observed targets. It also lists traffic against PLC-related ports 44818, 2222, 102, and 502, plus modem access on 22. Those identifiers are useful first pivots for firewall, VPN, modem, and asset-inventory reviews.[1]

The most urgent step is still the least glamorous one: remove direct internet exposure for PLCs and remote field modems. CISA’s update points operators toward mediated remote access through monitored gateways or jump hosts, rather than letting engineering workstations or vendor tools talk directly to controllers from the internet. The same lesson appears in earlier industrial-equipment risk stories, including the old INFRA:HALT vulnerability set across many industrial vendors and Microsoft’s BadAlloc warning for IoT and industrial devices: exposed embedded and OT systems often become security incidents because they were reachable before anyone noticed they were fragile.

For Rockwell environments, the new July guidance is especially specific. Before placing a controller into run mode, teams should validate the project file that is currently downloaded to the device, because switching modes can lock in malicious logic. CISA also tells owners to review Add-On Instructions and other reusable logic for anomalous modifications, compare running logic against a known-good copy, and verify that restored backups do not already contain attacker changes.[1]

Siemens and Schneider operators should treat this as a configuration-integrity check, not only a perimeter check. Look for unexpected use of Studio 5000 Logix Designer, EcoStruxure Control Expert, or Siemens TIA Portal from unusual infrastructure, then review engineering workstation, HMI, SCADA, modem, VPN, and firewall logs for signs of lateral movement. If a device was reachable from the internet or a modem accepted inbound SSH, assume the surrounding engineering path needs review too.

The advisory also gives defenders useful detection language: project-file exfiltration, modification or deletion of project logic, HMI/SCADA data manipulation, disabled alarm or shutdown logic, and Dropbear SSH on victim modems. Those are practical hunt terms for OT security teams, managed service providers, and integrators who need to translate the alert into tickets and downtime windows.[1]

SecurityWeek and The Record both framed the update as a broadened U.S. government warning for critical infrastructure operators, with Schneider and Siemens added to the manufacturer scope after the original April alert focused mainly on Rockwell/Allen-Bradley devices.[2][3] That timing is important: organizations that dismissed the April advisory because they did not run the originally emphasized PLC family should review it again.

For howtofix.guide readers, the practical takeaway is simple. If an OT network has PLCs, cellular modems, engineering software, or remote vendor access, confirm which devices are internet-facing, block direct inbound exposure, check project files against known-good versions, and move the review into the next planned maintenance window. Treat the same exposure discipline used for exploited edge appliances, such as recent SonicWall SMA1000 zero-day attacks, as the minimum bar for OT remote access.

References

  1. CISA, FBI, NSA, EPA, DOE, U.S. Cyber Command, and U.S. Treasury. “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure,” advisory AA26-097A, updated July 22, 2026. https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a
  2. SecurityWeek. “US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices,” July 23, 2026. https://www.securityweek.com/us-warns-of-iranian-hackers-targeting-siemens-schneider-and-rockwell-ics-devices/
  3. The Record. “Federal agencies broaden alert on Iran-linked OT attacks,” July 22, 2026. https://therecord.media/federal-agencies-broaden-alert-on-iran-linked-ot-attacks

About the author

Emma Davis

Content editor and security writer focused on making malware-removal and scam-prevention guides easier to understand. Emma reviews structure, clarity, and source consistency before articles are published.

Leave a Comment