Cyber Resilience
← All news
Corroborated4

US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices

CISA, FBI and partners warn that Iranian actors are actively targeting Siemens, Schneider and Rockwell ICS gear with known techniques for PLC access. If you run any of these in your environment, review the advisory and harden now.
Sources (2)
What this means for you — CISO:Review the updated federal advisory on Iranian actor techniques against Siemens, Schneider, and Rockwell PLCs. Validate segmentation, remote-access controls, and monitoring on any plant networks running those vendors' ICS.
What this means for you — Lean IT orgs:If you don't run Siemens, Schneider, or Rockwell industrial control gear on a plant floor, this advisory does not apply. Shops that do should pull the federal guidance and work the listed mitigations with your OT vendor or integrator.
What this means for you — MSP:Inventory clients for Siemens, Schneider, or Rockwell ICS/PLC deployments and forward the federal advisory to those OT environments. Prioritize plant and critical-infrastructure accounts for segmentation and detection checks.
What this means for you — Researcher:Diff the updated technique details against prior Iranian ICS reporting and map TTPs to the Siemens, Schneider, and Rockwell PLC families named in the advisory.