Decoding the world of cybersecurity

Iran-linked attacks widen across industrial controllers

US authorities have expanded an alert on Iran-affiliated activity to include Siemens and Schneider controllers widely deployed across European infrastructure.

Iran-linked attacks widen across industrial controllers
Summary
  • The revised advisory adds Siemens and Schneider Electric equipment to earlier targeting of Rockwell products.
  • Attackers have manipulated project files and operational displays in confirmed US incidents.
  • No European victims are confirmed, although the same exposed controller types are widely deployed across the region.

US cybersecurity agencies have expanded a warning about Iran-affiliated activity against internet-facing industrial controllers, adding equipment from Siemens and Schneider Electric to the product families observed in attacks.

The revised joint advisory covers programmable logic controllers, human-machine interfaces, and supervisory control and data acquisition systems exposed through weak remote-access configurations. Earlier reporting concentrated on Rockwell Automation and Allen-Bradley equipment, while the 22 July update broadened the manufacturer scope and added detection guidance.

Authorities have observed malicious interaction with controller project files, manipulation of information displayed through operational interfaces, and activity that caused disruption and financial loss. Confirmed targets have included US government, energy, water, and other operational organisations.

The agencies attribute the activity to Iran-affiliated actors but do not identify a specific group or name affected organisations. No current UK or European victimisation is confirmed in the advisory. Siemens and Schneider equipment is nevertheless widely deployed across European utilities, manufacturing, water treatment, transport, building systems, and other industrial environments.

The attacks do not depend on one newly disclosed vulnerability. They exploit a persistent architectural weakness: controllers and engineering interfaces that can be reached from the public internet, use default or weak credentials, or allow remote administration without adequate segmentation and monitoring.

Industrial systems are often exposed for operational reasons. Vendors, integrators, maintenance contractors, and internal engineers may require remote access to geographically distributed sites, while older equipment can lack modern identity and logging capabilities. Connections introduced during commissioning or emergency maintenance can remain in place after the original requirement has ended.

Project files can contain logic, configuration, tags, alarm settings, communications parameters, and details of how the physical process is expected to operate. An attacker able to obtain or modify them may not need comprehensive knowledge of the facility to interrupt an operator’s view, alter behaviour, or complicate recovery.

Manipulation of an HMI or SCADA display can create a gap between the physical process and the information available to an operator. Even where safety systems prevent dangerous changes, false indications can trigger shutdowns, delay intervention, or force a site into manual operation. Confidence and availability can be damaged without permanent control of the underlying process.

European operators can use the revised manufacturer list to support asset discovery, although exposure is not confined to the named products. Internet-facing controllers, unmanaged remote-access devices, engineering workstations, shared vendor accounts, and reusable project files need to be identified across sites and contractors.

External access should be removed wherever practical, with controlled jump hosts, multifactor authentication, and tightly restricted source networks used where remote connectivity remains necessary. Engineering files should be monitored and protected with the same care as other privileged operational assets.

Recovery planning also needs clean copies of controller logic, validated project files, tested methods for comparing running configurations, and clear authority for disconnecting remote links. Conventional IT backups do not always capture the state of embedded controllers or the versions held by integrators and maintenance suppliers.

The advisory records confirmed US activity rather than a new European campaign. The installed technology and remote-access practices described by the agencies are common across European infrastructure, leaving exposed controllers vulnerable to the same methods regardless of which actor reaches them first.

×