Iran-linked crews are probing more flavors of US industrial kit
Jump to main content
Search
REG AD
SECURITY
Iran-linked crews are probing more flavors of US industrial kit
CISA widens alert beyond Rockwell controllers as intruders target internet-facing devices across critical infrastructure
Richard Speed
Richard<br>Speed
MICROSOFT ECOSYSTEM REPORTER
Published<br>thu 23 Jul 2026 // 15:30 UTC
The US Cybersecurity and Infrastructure Security Agency (CISA) has expanded the scope of its alert on Iranian-affiliated hackers attacking critical infrastructure, including water and energy facilities.<br>The original advisory focused on programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley. The update warns that the activity may also target devices from Schneider Electric, Siemens, "and potentially other branded/manufactured PLCs."<br>The conflict between the US and Iran is well into its fourth month, and authorities have noticed Iranian-affiliated advanced persistent threat (APT) crews targeting PLCs to cause disruption since March.
REG AD
PLCs are used to control and monitor industrial processes. Authorities said the activity resembled earlier attacks on PLCs by CyberAv3ngers (aka the Shahid Kaveh Group) - hackers affiliated with Iran's Islamic Revolutionary Guard Corps (IRGC) Cyber Electronic Command (CEC).
REG AD
MORE CONTEXT
Water company's leaky security earns near-£1M fine
Iran cyber actors disrupting US water, energy facilities, FBI warns
Iran's cyberwar has begun
Cyberpunks mess with Canada's water, energy, and farm systems
The focus is principally related to internet-facing PLCs. CISA noted attackers targeting devices through open ports: "The targeting of ports associated with other OT vendors' protocols suggests these actors are opportunistically targeting devices manufactured by companies other than Rockwell Automation/Allen-Bradley, including Schneider Electric and Siemens.<br>"In one reported instance, the actors utilized Dropbear Secure Shell (SSH) software on victim modems to enable them to gain remote access through port 22."<br>Once in, attackers extract device project files and modify or delete their logic.<br>"Additionally, the changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators of the anomalies," CISA said.<br>The expansion of the advisory's scope to include additional PLCs highlights the importance of being aware of what is accessible. On top of to earlier mitigations that included disconnecting the PLC from the public-facing internet, authorities have suggested organizations consider implementing isolated architectures and controlling network access to PLC devices.<br>It would also be a good idea to check project files running on PLCs for unauthorized changes, make sure service providers are aware of threats targeting PLCs, and ensure default passwords are changed. ®
critical infrastructure<br>cisa<br>security<br>iran
REG AD
Patches
Year-long Russian attacks infect users as soon as they look at an email
Phishing for dummies
DEVOPS
Model Context Protocol prepares to break with its stateful past
Biggest overhaul since launch ditches sessions, guts little-used features, and leaves homebrew implementations facing a slog
Gobi X: Creating more energy for AI, not taking it from society
PARTNER CONTENT: How Envision is reversing the datacenter playbook by making computing chase abundant desert power, not the other way around
security
Millions of California-bought cars can be hijacked via Bluetooth
Aftermarket dealer-installed KARR/SWDS security systems all use the same secure key, say UCSD researchers
columnists
Airbus takes flight from AWS. What happens next is critical
Which way to the Land of the Free again?
Security
Oracle drops 1,449 security patches like it's the new normal
Experts say the era of AI bug hunting is here, so defenders will simply have to adapt to busier workloads
MOST POPULAR
columnists
Airbus takes flight from AWS. What happens next is critical
off-prem
Anyone with a shed, an extension cord, a couple of GPUs and an overdraft is building datacenters. Fujitsu just offloaded five
security
Linux kernel team publishes 432 CVEs in two days
AI AND ML
OpenAI admits it was the source of the agent swarm that attacked Hugging Face
off-prem
AWS customer learns the hard way how even the smallest oversight can be mission-critical
AI
DEVOPS
Model Context Protocol prepares to break with its stateful past
Biggest overhaul since launch ditches sessions, guts little-used features, and leaves homebrew implementations facing a slog
Offbeat
Tesla burns through a billion as Musk bets the farm on chips and bots
Optimus remains 'very complex' and Robotaxis will try not to flatten your cat
software
IBM insists AI didn't kill software deals, just delayed them
Big Blue says customers postponed rather than abandoned major purchases as hardware soaked up enterprise...