Techtimes
Iranian Hackers Target U.S. Critical Infrastructure with Advanced PLC Attacks
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Iran-affiliated hackers have expanded their attacks on U.S. critical infrastructure, targeting programmable logic controllers (PLCs) from Siemens and Schneider Electric, in addition to Rockwell Automation systems. The Cybersecurity and Infrastructure Security Agency (CISA) and FBI issued an advisory on July 22, 2026, confirming operational disruptions and financial losses across various sectors, including water treatment and energy facilities. Attackers used legitimate software tools to manipulate PLCs, replacing real sensor data with false readings, which poses significant risks to operational safety. The advisory highlights a shift in tactics, with attackers leveraging existing vulnerabilities, including CVE-2021-22681, to gain unauthorized access. The ongoing campaign is linked to Iranian threat groups, including the CyberAv3ngers, and is believed to be part of a broader geopolitical conflict. Organizations are urged to strengthen access controls and validate project files to mitigate risks.
Key Points: • Iran-affiliated hackers are targeting Siemens and Schneider Electric PLCs in addition to Rockwell Automation. • The attacks manipulate sensor readings, posing risks to critical infrastructure operations. • CISA and FBI confirm operational disruptions and financial losses across multiple sectors.