AI Stories on SHORT INFO are generated & curated with AI
unverified 23 Jul, 23:11

Iran-affiliated hackers exploit PLCs Rockwell Schneider Siemens US water energy critical infrastructure CISA advisory

Iran-affiliated hackers have exploited internet-connected PLCs from Rockwell, Schneider Electric and Siemens at US water, energy and government facilities, per an updated CISA, FBI, NSA advisory. They disabled shutdown and alarm logic, letting unsafe conditions go unnoticed by op

Iran-affiliated hackers have been exploiting internet-connected programmable logic controllers, or PLCs, made by Rockwell Automation, Schneider Electric and Siemens across US water, wastewater, energy and government facilities, according to a joint advisory from CISA, the FBI, NSA and other federal agencies, first issued in April 2026 and updated July 22. The threat actors reach these devices over the internet using default credentials, insecure remote access protocols and unpatched firmware, then use the vendors' own legitimate engineering software, including Rockwell's Studio 5000, Schneider's EcoStruxure Control Expert and Siemens' TIA Portal, to modify or delete project file logic. Investigators found the actors disabled critical shutdown and alarm functions and manipulated data shown on operator displays, so unsafe conditions would go unnoticed. Because the intrusion relies on the same software plant operators use for routine maintenance rather than custom malware, it does not present as a typical cyberattack to standard security tools, meaning operators at affected water and energy facilities may not realize their safety systems have been compromised until something fails.

Published on
FacebookXThreadsBlueskyReddit