CISA Updates PLC Threat Advisory as Iran-Linked ICS Attacks Escalate

CISA Updates PLC Threat Advisory as Iran-Linked ICS Attacks Escalate

Why it matters now: Programmable logic controllers — the embedded devices that regulate pumps, turbines, valves, and safety shutdowns across industrial facilities — have become a prime target in an escalating state-sponsored cyber campaign. In a newly updated joint cybersecurity advisory, the Cybersecurity and Infrastructure Security Agency (CISA), FBI, NSA, EPA, Department of Energy, U.S. Cyber Command, and Department of the Treasury warn that Iranian-affiliated threat actors are actively compromising PLCs manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens. The attacks have already resulted in documented operational disruption and financial loss across multiple critical infrastructure sectors, and the scope of targeted vendors continues to widen.

The Escalating Threat Landscape

The advisory — originally issued in April and updated in July — marks a significant escalation from earlier campaigns. Where previous Iranian-linked activity focused primarily on Israeli-manufactured Unitronics hardware, the current wave represents a deliberate platform shift toward Western-made controllers that dominate U.S. industrial environments. Cybersecurity firm Tenable assesses that the attack techniques have now proliferated to an estimated 60 or more affiliated pro-Iranian hacktivist groups.

The July update expanded the manufacturer scope beyond Rockwell Automation to include confirmed targeting of Schneider Electric and Siemens PLCs, with agencies noting that devices from other manufacturers may also be at risk. This broadening underscores a critical reality: no major PLC brand is immune, and the attack surface is only growing.

Analyst Insight: The expansion from Rockwell-exclusive targeting to multi-vendor exploitation signals a maturing adversary capability. Organizations running Schneider Electric Modicon or Siemens SIMATIC controllers can no longer treat this as a competitor-specific problem. The attack methodology — leveraging manufacturers' own programming software against misconfigured devices — is inherently vendor-agnostic.

Anatomy of the Attack: How Iranian Actors Compromise PLCs

The attack chain is deceptively straightforward. Adversaries scan for internet-facing PLCs using legitimate manufacturer programming software — such as Rockwell Automation's Studio 5000 Logix Designer — to connect to devices that have been deployed without adequate network segmentation or hardening controls. Once connected, the actors extract project files, modify or delete logic including Add-On Instructions (AOIs), and manipulate data displayed on human-machine interfaces (HMIs) and SCADA displays.

Critically, the intrusions have included disabling alarm and safety shutdown logic, allowing systems to enter unsafe conditions while operators remain blind to anomalies. The actors modify reusable code modules within project files — a technique that can propagate malicious changes across multiple controllers sharing a common code library, compounding the damage.

Technical Indicators: Ports and Protocols Under Attack

The advisory identifies specific ports associated with targeted OT protocols. Organizations should audit logs for suspicious traffic on:

  • Port 44818 — EtherNet/IP (Rockwell Automation/Allen-Bradley)
  • Port 2222 — Ethernet/IP or proprietary vendor protocols
  • Port 102 — ISO-TSAP (Siemens S7 protocol)
  • Port 502 — Modbus TCP (Schneider Electric and others)
  • Port 22 — SSH (potential administrative backdoor access)

Inbound connections on these ports from foreign-based IP addresses — particularly those associated with leased, third-party hosted infrastructure — should be treated as high-priority indicators of compromise.

Market Trend: According to internet monitoring data, the number of internet-exposed industrial control system devices globally has climbed from approximately 129,000 in 2024 to over 138,000 in early 2026. North America accounts for the largest share. Each exposed device represents a potential entry point — and the trend line is not moving in the right direction.

Sectors Under Fire

The Iranian-affiliated campaign has cut across multiple U.S. critical infrastructure sectors. Confirmed targets include Water and Wastewater Systems (WWS), where compromised PLCs can disrupt treatment processes and water distribution. The Energy sector — including electrical substations and generation facilities — has also faced intrusions. Government Services and Facilities, including local municipalities, round out the confirmed target set.

The water sector warrants particular attention. Security researchers have noted that human-machine interfaces widely deployed in water and wastewater — such as C-More HMIs — remain disproportionately exposed online, with 34 percent of internet-facing C-More devices tied to the water sector. This convergence of exposure and geopolitical targeting creates an acute risk profile for municipal water systems.

CISA's Mitigation Framework: Immediate and Long-Term Actions

The authoring agencies have issued a tiered set of recommendations. The first tier — immediate steps to prevent attack — centers on one non-negotiable action: disconnect PLCs from the public-facing internet. Where remote access is operationally essential, it must be routed through a VPN with multi-factor authentication, consistent with CISA's secure connectivity principles for operational technology.

Longer-term hardening measures include verifying PLC configurations for unauthorized changes, auditing project files — particularly Add-On Instructions and reusable code modules — and placing physical mode switches on Rockwell Automation controllers into the run position to prevent remote programmatic changes. Organizations are also urged to ensure that system integrators, vendors, and third-party service providers are made aware of the current threat and have aligned their security postures accordingly.

FAQ: Practical Steps for OT Security Teams

Q: Is simply placing a firewall in front of the PLC sufficient?
Not necessarily. While firewalling is essential, many of the observed intrusions leveraged legitimate programming software over standard industrial protocols. Defense-in-depth requires network segmentation, protocol-aware monitoring, and configuration auditing — not just perimeter controls.

Q: How can we detect if our PLC project files have been tampered with?
Compare current project files against known-good backups. Pay particular attention to Add-On Instructions and reusable code modules — these are the vectors adversaries used to hide alarm-disabling override code. Rockwell Automation has published specific guidance on detecting malicious changes in .ACD project files.

Q: Are only U.S.-based organizations at risk?
No. While the advisory focuses on U.S. critical infrastructure, the same techniques can be deployed against PLCs anywhere. Organizations globally should review their OT network architecture and apply the recommended mitigations.

The Geopolitical Dimension

The PLC targeting campaign cannot be divorced from its geopolitical context. The advisory follows a pattern of escalating cyber operations coinciding with kinetic conflict between Iran, the United States, and Israel. A predecessor group — CyberAv3ngers — targeted Unitronics PLCs at U.S. water facilities in late 2023. The current campaign represents a broader, more sophisticated iteration of that playbook, aimed at higher-value Western-manufactured controllers that form the operational backbone of U.S. industry.

For industrial operators, the message is unambiguous: PLCs are no longer peripheral assets that can be set and forgotten. In an era when nation-state actors view industrial controllers as strategic targets, OT cybersecurity hygiene — starting with the fundamental step of removing devices from direct internet exposure — must become a boardroom priority, not just an engineering afterthought.

Related Articles

Tilbage til blog