Critical Infrastructure Alert: CISA and FBI Warn of Iranian Attacks on Schneider Electric and Siemens PLCs
Executive Summary
On July 23, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) released an updated joint security advisory (AA26-204A) warning that Iranian state-supported cyber actors have significantly expanded their operational target set against critical infrastructure. Threat actors affiliated with the Islamic Revolutionary Guard Corps (IRGC) are actively targeting Programmable Logic Controllers (PLCs) manufactured by Schneider Electric, Siemens, and Rockwell Automation/Allen-Bradley across United States municipal water facilities, wastewater treatment plants, and regional energy grids. By exploiting default credentials, unauthenticated control ports, and unencrypted industrial communication protocols, state-sponsored actors are directly injecting malicious control logic to disrupt physical industrial operations and disable automated emergency shutdown systems.
Deep-Dive Technical Analysis
The escalation in Iranian cyber operations reflects a strategic pivot toward multi-vendor Industrial Control System (ICS) and Operational Technology (OT) exploitation:
1. Multi-Vendor PLC Expansion: While earlier campaigns focused almost exclusively on Rockwell Automation Unitronics Vision and Allen-Bradley PLCs, current forensic evidence demonstrates active scanning and exploitation targeting Schneider Electric Modicon PLCs and Siemens S7-300/1200 series controllers.
2. Exploitation Vectors: Threat actors gain initial access by targeting internet-facing OT devices via default administrative credentials, unauthenticated Modbus TCP (Port 502) and Siemens S7comm (Port 102) protocols, or unpatched remote desktop/cellular gateway connections.
3. Control Logic Tampering: Attackers deploy custom industrial exploit kits to overwrite native PLC project files (.ap17, .smw). By altering physical logic blocks, memory registers, and sensor thresholds, attackers alter valve positions, disrupt chemical dosing in water treatment plants, or force physical pressure overloads.
4. Disabling Human-Machine Interface (HMI) Feeds: To mask physical disruptions, actors simultaneously manipulate HMI telemetry streams, feeding false operational readings to human operators while physical equipment operates out of safe parameters.
Industry Impact and Mitigation Strategies
Targeted attacks against industrial controllers in critical sectors threaten public health, clean water supplies, and electrical grid stability, highlighting severe OT security gaps across municipal entities.
Recommendations and Mitigation Protocols
* Remove All PLCs from the Public Internet: Immediately isolate all industrial logic controllers, HMIs, and engineering workstations behind air-gapped industrial firewalls. Disallow direct internet routing to Ports 502 (Modbus), 102 (S7comm), and 44818 (EtherNet/IP).
* Enforce Strict Multi-Factor Authentication (MFA): Require robust MFA and VPN access control for any external vendor or engineering remote access connection into the OT perimeter.
* Change Default Administrative Passwords: Immediately update all factory-default administrative and programming passwords across Schneider, Siemens, and Rockwell PLCs and cellular gateways.
* Integrate Cryptographic Project File Hashing: Regularly audit and verify the digital integrity and cryptographic hashes of active PLC logic project files to detect unauthorized tampering or unauthorized code injections.
References:
* CISA, FBI warn that Iran-linked hackers are expanding target set for water, energy
* Cybersecurity Alerts & Advisories - CISA