Iranian Hackers Blind Siemens, Schneider PLCs with Fake Sensor Data in Escalating ICS Campaign

Iranian Hackers Blind Siemens, Schneider PLCs with Fake Sensor Data in Escalating ICS Campaign

Why it matters now: Industrial control systems form the invisible backbone of global infrastructure — water treatment, power grids, and manufacturing floors. When attackers manipulate Programmable Logic Controllers (PLCs) at the hardware level, they don't just steal data; they rewrite physical reality. On July 22, 2026, a landmark joint advisory from seven U.S. federal agencies confirmed that Iranian-affiliated hackers have escalated a months-long campaign, extending their reach beyond Rockwell Automation into Siemens and Schneider Electric PLCs — planting hidden code that blinds operators with falsified sensor readings while suppressing safety alarms.

🔍 Analyst Insight: This campaign represents a paradigm shift from ICS reconnaissance to active manipulation. The ability to falsify Human-Machine Interface (HMI) readings while disabling alarms means an attacker could cause physical damage — overpressure events, turbine overspeed, chemical mixing errors — long before any operator notices.

The Attack Vector: Legitimate Tools, Illicit Access

The sophistication of this campaign lies not in exotic zero-days, but in the attackers' ability to weaponize trusted industrial software. The advisory, jointly released by the FBI, CISA, NSA, EPA, DOE, and U.S. Cyber Command, details how threat actors leverage authorized engineering platforms — Rockwell's Studio 5000 Logix Designer, Schneider Electric's EcoStruxure Control Expert, and Siemens' TIA Portal — accessed through leased overseas infrastructure.

By routing connections through foreign IP addresses, the attackers mask their origin while connecting directly to internet-exposed PLCs. Once authenticated — or in many cases, bypassing authentication entirely — they deploy malicious ladder logic that silently substitutes genuine sensor data with fabricated values on operator screens.

Affected Systems and Exploited Vulnerabilities

Three major PLC families are now confirmed targets. At Rockwell Automation and Allen-Bradley sites, the attackers exploit CVE-2021-22681, a critical authentication bypass vulnerability carrying a CVSS score of 9.8 — the highest severity rating possible. This flaw, disclosed in 2021, permits remote code execution without credentials on affected CompactLogix and ControlLogix controllers.

📊 Confirmed Targeted PLC Families — Click to Expand
Vendor PLC Family Engineering Software Used Key Vulnerability
Rockwell Automation CompactLogix, ControlLogix Studio 5000 Logix Designer CVE-2021-22681 (CVSS 9.8)
Siemens SIMATIC S7 Series TIA Portal Direct internet exposure
Schneider Electric Modicon, EcoStruxure EcoStruxure Control Expert Credential harvesting / open exposure

Threat Actor Profile: State-Linked Groups Behind the Campaign

The advisory identifies two primary Iranian threat clusters: CyberAv3ngers, a group with documented ties to Iran's Islamic Revolutionary Guard Corps (IRGC), and Handala, an Iranian hacktivist persona that has claimed responsibility for multiple ICS intrusions since late 2025. The collaboration between a state-directed APT and a hacktivist front represents a hybrid threat model increasingly favored by nation-state actors seeking plausible deniability.

Previous CyberAv3ngers activity focused on Unitronics Vision series PLCs in water and wastewater systems across the United States. The expansion to Siemens and Schneider ecosystems signals a deliberate broadening of operational capability — and a deepening understanding of multi-vendor industrial environments.

🌐 Market Trend: The global ICS security market is projected to grow at a CAGR exceeding 7% through 2030, driven precisely by these escalating nation-state threats. PLC-level security — historically a blind spot — is now the fastest-growing segment within operational technology (OT) cybersecurity spending.

Operational Impact: The Danger of Falsified Reality

The attackers' payload does not simply disrupt operations — it methodically corrupts the operator's situational awareness. Malicious ladder logic intercepts legitimate sensor inputs — temperature, pressure, flow rate, tank level — and replaces them with fabricated steady-state readings on the HMI. Simultaneously, safety alarm triggers are suppressed, meaning threshold breaches that should trigger automatic shutdown sequences or operator alerts go unreported.

For a water treatment plant, this could mean a chemical dosing failure that goes unnoticed. For a power substation, a transformer overload with no alarm. For a manufacturing line, a robotic arm collision with no emergency stop. The physical consequences are limited only by the attacker's understanding of each facility's specific process parameters.

⚠️ Indicators of Compromise (IoCs) & Threat Hunting Guidance — Click to Expand
  • Unexpected ladder logic modifications appearing in controller audit logs outside scheduled maintenance windows.
  • Engineering workstation connections originating from foreign IP addresses, particularly those associated with leased infrastructure or VPN services.
  • Mismatch between HMI-displayed values and independent physical gauge readings — a hallmark of sensor data falsification.
  • Alarm suppression: review alarm historian databases for gaps or disabled alarm points that coincide with controller logic changes.
  • Presence of unknown user accounts or authentication bypass artifacts in PLC access control lists.

Mitigation: CISA's Urgent Recommendations

CISA's guidance is unambiguous: immediately remove all PLCs from direct internet exposure. Any controller accessible via Shodan, Censys, or similar internet scanning platforms is a sitting target. Beyond this immediate action, operators should implement network segmentation, deploy OT-specific firewalls, and enforce multi-factor authentication on all engineering workstations used to program PLCs.

The advisory further recommends that asset owners conduct proactive threat hunting against the published indicators of compromise and review controller audit trails for any signs of unauthorized ladder logic modification. For Rockwell environments, patching CVE-2021-22681 remains the single most effective technical control — yet three years after disclosure, a significant percentage of affected controllers remain unpatched in production environments.

❓ Frequently Asked Questions — Click to Expand

Q: How do attackers connect to PLCs without being detected?
They use the same engineering software that authorized technicians use — Studio 5000, TIA Portal, EcoStruxure Control Expert — often routed through leased overseas infrastructure. This makes malicious sessions blend in with legitimate maintenance traffic.

Q: Can a firewall alone protect my PLCs?
Not if the PLC is directly internet-accessible. A properly configured OT firewall with deep packet inspection can help, but physical or logical air-gapping remains the gold standard. PLCs should never be reachable from the public internet.

Q: Are Siemens and Schneider PLCs inherently less secure than Rockwell?
No. The attackers target internet-exposed controllers regardless of vendor. The vulnerability exploited on Rockwell (CVE-2021-22681) is a known, patchable flaw. Siemens and Schneider controllers are being compromised primarily through credential harvesting and direct exposure — not vendor-specific zero-days.

Q: What sectors are most at risk?
Water and wastewater (EPA co-authored the advisory), energy (DOE), and manufacturing are the primary targets observed so far. However, any sector with internet-exposed PLCs — food processing, pharmaceuticals, oil and gas — faces similar risk.

The Bigger Picture: PLC Security as a Boardroom Priority

This advisory lands at a moment when industrial cybersecurity is transitioning from an engineering concern to a board-level governance issue. Regulators in the U.S., EU, and Asia-Pacific are increasingly mandating OT-specific security controls, and cyber insurance underwriters are scrutinizing whether industrial organizations can demonstrate basic hygiene — starting with whether their PLCs appear on Shodan.

The Iranian campaign underscores an uncomfortable truth: the convergence of IT and OT has expanded the attack surface faster than most organizations' ability to defend it. A PLC purchased a decade ago and never intended for network connectivity now sits exposed, running processes that — if manipulated — could cause environmental harm, production loss, or worse. The fix begins with visibility: you cannot protect what you cannot see.

🛡️ Analyst Insight — The Path Forward: Organizations should treat this advisory as a stress test, not a one-time checklist. Conduct an immediate Shodan/Censys sweep of your IP ranges. Segment OT networks from IT and the internet. Patch CVE-2021-22681. And most critically, implement continuous PLC logic monitoring — because the next campaign may not be detected by a joint advisory until damage is already done.

Related Articles

Retour au blog