Federal agencies broaden alert on Iran-linked OT attacks

The federal government has expanded a warning that it issued in April about attacks on internet-facing operational technology (OT) by hackers affiliated with the Iranian regime.
The initial advisory focused on programmable logic controllers (PLCs) from manufacturers Rockwell Automation and Allen-Bradley. Wednesday’s revision “expands the manufacturer scope to include observed targeting of Schneider Electric, Siemens and possible other PLC manufacturers,” according to a news release from CISA.
The observed incidents include “malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays,” the advisory says. Targeted organizations suffered “operational disruption and financial loss.”
PLCs are core technology for critical infrastructure like power utilities, wastewater treatment and manufacturing plants. Officials from CISA, the FBI and the Environmental Protection Agency (EPA) said that the pressure from Iran-affiliated attackers is expected to continue.
“The additional manufacturers being targeted emphasizes the importance for OT owners and operators to restrict direct internet access and ensure secure PLC deployment,” the news release said.
PLCs from Schneider and Siemens are widely used in the U.S. and beyond.
President Donald Trump threatened Iranian critical infrastructure on Wednesday, saying the U.S. would target a bridge or a power plant if Tehran continued to target ships in the Strait of Hormuz.
The federal advisory does not mention specific cyberthreat groups or attacks. Attribution of Iranian government-affiliated attacks can be difficult because the regime sometimes uses ransomware gangs or other groups as cover, researchers say.
A pro-Iranian hacktivist group that attacked a Los Angeles transit agency was actually an arm of the country’s intelligence services, researchers said.
References in this story
- FBI, Pentagon warn of Iran hacking groups targeting operational technology therecord.media The advisory said Iranian actors are targeting local municipal governments, water and wastewater systems and the energy sector.
- Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure | CISA www.cisa.gov U.S. organizations should review the TTPs and IOCs in this advisory for indications of current or historical activity on their networks, and apply the recommendations listed in this advisory to reduce the risk of…
- Iranian government hackers using Chaos ransomware as cover, researchers say therecord.media Incident responders from cybersecurity firm Rapid7 published a report about a recent intrusion that initially appeared to be a Chaos ransomware attack but was later discovered to be an attack attributed to MuddyWater…
- Iranian intelligence service behind hack of LA transit system, researchers say therecord.media The hacking group claimed to be a standalone hacktivist crew but actually has ties to the Ministry of Intelligence of the Islamic Republic of Iran (MOIS), researchers at Gambit Security said in a report published…
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your business.
- Joe Warminsky (@jwarminsky.bsky.social) bsky.app News Editor at The Record: @therecordmedia.bsky.social [ Tired of bios ] [ Often thinking about music ] [ Etc. ]



