US Agencies Warn That Iranian Hackers Are Targeting Industrial Control Systems Made by Siemens, Schneider Electric, and Rockwell Automation

An updated federal advisory names the specific techniques used to break into programmable logic controllers, the computers that run factories, water plants, and power grids.

ThreatVectr Newsdesk· 3 min read
A dimly lit modern security operations centre viewed from behind an empty analyst chair, multiple large curved monitors glowing with abstract log data and netwo
Share

Key points

  • US federal agencies issued an updated advisory warning that Iranian state-linked hackers are actively targeting industrial control systems made by Siemens, Schneider Electric, and Rockwell Automation.
  • The hackers are focusing on programmable logic controllers (PLCs), small specialised computers that directly operate physical machinery in factories, water-treatment plants, and energy facilities.
  • The advisory names the specific techniques the hackers use to break into these devices.
  • No single breach date is given; the advisory treats this as an ongoing, active threat.

Federal agencies have updated a standing advisory to warn that hackers linked to Iran are targeting industrial control systems, the hardware and software that keeps physical infrastructure running. The advisory, first covered by SecurityWeek, names Siemens, Schneider Electric, and Rockwell Automation as the manufacturers whose equipment is under active attack.

At the centre of the warning are programmable logic controllers, or PLCs. A PLC is a small, ruggedised computer bolted to a factory floor or inside a water-treatment facility. It sends direct commands to pumps, valves, motors, and circuit breakers. When a PLC is compromised, whoever controls it can, in the worst case, cause physical damage to equipment or interrupt services that ordinary people depend on every day.

Why does this matter to people who don't work in a factory?

It matters because PLCs sit inside the systems that treat your drinking water, distribute electricity, and run pharmaceutical production lines. Disrupting one does not stay inside a corporate network. The effects can reach taps, hospital wards, and supermarket shelves.

The updated advisory describes the specific techniques the hackers use once they find a PLC reachable from the internet. Details on exact methods are included so that engineers and security teams can look for matching signs inside their own networks.

This sits firmly inside the regulatory spotlight. The Cybersecurity and Infrastructure Security Agency, known as CISA, is the federal body responsible for critical-infrastructure warnings. Under the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), operators of critical infrastructure will eventually face mandatory reporting deadlines when incidents like these occur. The final CIRCIA rulemaking is still pending, but advisories like this one feed directly into the compliance picture that regulators are building.

For facility operators, the advisory is a clear prompt to check whether any PLCs from the three named manufacturers face the open internet without a firewall, or still carry factory-default passwords, which are the login credentials set by the manufacturer before a device ships and which attackers know by heart.

For ordinary members of the public, the most practical takeaway is straightforward: if a local utility or public service reports an unexplained outage or disruption in the weeks ahead, this advisory provides context for what may be happening behind the scenes.

© 2026 Threat Vectr