AI-Generated · deepseek/deepseek-v4-pro via openrouter/openrouter/auto-beta; researched by moonshotai/kimi-k2-0905

Iranian Hackers Expand PLC Attacks to Siemens and Schneider, US Agencies Warn

CISA, FBI, NSA, and five other US agencies updated a joint advisory, revealing that Iranian-affiliated actors have expanded their industrial control system campaign to target Siemens and Schneider Electric programmable logic controllers, using legitimate engineering software to disable safety systems and feed operators falsified data.

Iranian Hackers Expand PLC Attacks to Siemens and Schneider, US Agencies Warn
Photo: KUKA Roboter GmbH, Bachmann, Public Domain

On July 22, 2026, CISA, the FBI, NSA, and five other US agencies updated joint advisory AA26-097A, expanding the scope of an ongoing Iranian-affiliated campaign against internet-exposed PLCs to now include Siemens and Schneider Electric devices. The original advisory, first released earlier in the year, had focused on Rockwell Automation equipment, but the update revealed a broader appetite for compromising industrial control systems across major manufacturers.

The devices at risk — programmable logic controllers, the industrial computers that govern everything from water treatment to turbine speed — are being compromised through methods that are hard to distinguish from legitimate engineering work. Attackers use the vendors’ own software tools to steal project files, then modify the ladder logic to plant hidden code that disables safety alarms and replaces real sensor readings with falsified data. A pump could be running at dangerously high pressure without a single alert, because the controller has been told to report the pressure as normal.

The campaign is not new, but the expansion to Siemens and Schneider Electric dramatically increases the pool of potential targets. Both manufacturers dominate the global market for industrial automation, and many of their devices are exposed to the internet, often without proper segmentation from corporate networks. This makes them reachable by adversaries scanning for vulnerable systems.

The sectors directly affected — Water and Wastewater Systems, Energy, and Government Services — are among the most critical in any nation’s infrastructure. The ability to disable safety shutdowns in a water treatment plant or a power station is a direct threat to public health and the economy. The advisory makes clear that this is not theoretical: the campaign has been active for months, and the update is a response to observed, not speculative, compromise attempts.

The use of legitimate engineering software is particularly insidious. Network defenders typically focus on spotting malicious tools or unusual protocols, but when an attacker uses the same software that a plant’s own engineers use, the activity blends into normal maintenance. The only tell might be the theft of project files or the unauthorized modification of logic, which requires deep visibility into the PLC’s programming — something many facilities lack.

For operators of Siemens and Schneider Electric PLCs, the advisory update is a blunt warning to audit internet exposure, segment operational technology networks, and ensure logging and monitoring are robust enough to detect logic changes, even when they come from signed, legitimate engineering tools. The joint message from eight US agencies indicates that the threat is persistent and sophisticated, and that the attackers are actively pursuing new targets.

Sources