CISA, FBI, EPA and U.S. Government Partners Update Warning of Iran-Affiliated Threat Actors Targeting Critical Infrastructure Programmable Logic Controllers
U.S. agencies updated a joint advisory warning of Iranian-affiliated cyber actors targeting industrial control systems, including Rockwell Automation, Schneider Electric, and Siemens PLCs, across critical infrastructure sectors.
The Cybersecurity and Infrastructure Security Agency (CISA), FBI, EPA, and partners issued an updated advisory on Iranian-affiliated cyber threats targeting internet-connected programmable logic controllers (PLCs) in U.S. critical infrastructure. The update expands manufacturer scope to include Schneider Electric and Siemens, alongside Rockwell Automation, and provides new detection guidance for malicious code changes in PLC programs. Organizations are urged to restrict direct internet access to PLCs and implement recommended mitigations to reduce exposure to these threats.
The FBI emphasized its commitment to disrupting Iranian cyber activity, stating that timely intelligence sharing is essential for defenders to identify malicious activity and strengthen defenses. The advisory highlights the group’s attempts to manipulate human-machine interfaces and SCADA systems, which have disrupted operations and caused financial losses in sectors such as water, energy, and government facilities. The FBI’s Assistant Director Brett Leatherman underscored the importance of the advisory in providing actionable intelligence to protect critical services.
The EPA warned that cyber threats pose serious risks to drinking water and wastewater systems, which support communities, businesses, and essential services. Assistant Administrator Jess Kramer stressed the need for vigilance and adoption of cybersecurity best practices to safeguard these systems. The advisory targets multiple U.S. critical infrastructure sectors, including local municipalities, underscoring the broad scope of the threat and the urgency for enhanced security measures.
CISA Acting Executive Assistant Director Chris Butera reiterated the agency’s ongoing warnings about Iranian-affiliated threat actors exploiting unsecured internet-connected devices. The updated advisory includes additional mitigations and expands manufacturer targeting to emphasize the need for secure PLC deployment. CISA continues to collaborate with government and industry partners to provide actionable guidance, aiming to reduce risks to digital and physical infrastructure relied upon by Americans daily.