Back to Insights
Regulation4 min read23 July 2026

Iranian State Hackers Target Siemens, Schneider, and Rockwell PLCs: What the Federal Advisory Actually Says

A refreshed CISA-led warning names the exact attack techniques used against programmable logic controllers in water treatment, energy, and manufacturing facilities across the United States.

t2s
train2secure NewsdeskSecurity awareness team
A wide-angle photoreal editorial photograph of an industrial control room at dusk, banks of physical control panels with

US federal agencies have issued an updated advisory confirming that hackers linked to the Iranian government are actively targeting industrial control systems built by Siemens, Schneider Electric, and Rockwell Automation, with programmable logic controllers at the centre of the campaign.

What is a PLC and why are attackers targeting it?

A programmable logic controller is a ruggedised, dedicated computer bolted directly to industrial machinery. It sends real-time commands to pumps, valves, motors, and circuit breakers. Control one, and you can direct physical processes that affect people far beyond any corporate network.

That last point is what separates PLC attacks from ordinary data breaches. A stolen database hurts. A compromised PLC inside a water-treatment plant can interrupt the chemical dosing that makes tap water safe to drink. The same logic applies to electrical substations, pharmaceutical production lines, and natural-gas distribution systems. The blast radius is physical, not just digital.

Which manufacturers are named in the advisory?

The advisory specifically identifies equipment from Siemens, Schneider Electric, and Rockwell Automation as being under active attack. All three companies supply PLCs and related industrial control hardware to critical-infrastructure operators worldwide. The warning does not identify a single breach date; agencies treat this as a sustained, ongoing threat rather than a one-time intrusion.

Named VendorCommon PLC LinesPrimary Sectors at Risk
SiemensSIMATIC S7 seriesEnergy, manufacturing, water
Schneider ElectricModicon seriesEnergy, building automation
Rockwell AutomationAllen-Bradley seriesManufacturing, food, pharma

How are the attackers getting in?

The advisory describes the specific techniques used once a PLC is reachable from the open internet. Two weaknesses appear repeatedly in incidents of this type: devices exposed directly to the internet without a firewall sitting in front of them, and devices still running factory-default credentials, the username-and-password combinations that manufacturers set before a device ships and that are published in product manuals that anyone can download.

Default credentials are a chronic, industry-wide failure. The Verizon Data Breach Investigations Report consistently finds that stolen or default credentials are involved in a majority of system intrusions year after year. Operational technology environments lag behind corporate IT in credential hygiene, partly because PLCs were designed for reliability and longevity, not for frequent password rotations or modern authentication schemes.

What does CISA say operators should do?

The Cybersecurity and Infrastructure Security Agency is the federal body coordinating this warning. Its baseline guidance for industrial control system operators centres on three immediate actions: remove PLCs and related devices from direct internet exposure, change all default credentials before deployment and audit any devices already in the field, and apply available firmware patches from the named vendors.

The advisory also sits inside a growing regulatory picture. The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) will eventually require critical-infrastructure operators to report significant cyber incidents within tight deadlines. Final rulemaking is still pending, but advisories like this one signal what regulators consider material threats. Operators who ignore the warning today may find themselves scrambling under mandatory timelines tomorrow.

Which controls failed here?

Two failures stand out. First, network segmentation: PLCs visible to the open internet represent a configuration failure that should not exist in any well-managed operational technology environment. A firewall or air gap between the industrial network and any external connection is a basic, decades-old control. Second, credential management: factory-default passwords are the equivalent of a front door left unlocked because the builder never handed over the key. Both failures are preventable with standard hardening procedures that NIST SP 800-82, the Guide to Operational Technology Security, has recommended for years.

There is a third, subtler failure worth naming: human awareness. Many OT environments operate with engineering teams who are skilled at keeping machinery running but have had limited exposure to adversarial thinking. Recognising a suspicious remote-access attempt, knowing when to escalate an unexpected login alert, understanding why a vendor should not be given standing remote credentials, these are awareness gaps. Security-awareness training that extends beyond the corporate IT department and reaches shift supervisors, plant engineers, and control-room operators can close that gap before an attacker exploits it. Exploring how that kind of targeted training works in practice is a reasonable first step for any facility operator reading this advisory.

What security-awareness practitioners observe in OT environments

In our experience working with organisations that span both IT and operational technology, awareness of social-engineering risk tends to drop sharply once you leave the office floor and enter the plant floor. Simulated phishing campaigns that catch a reasonable share of corporate staff often go completely untested in engineering departments. Shift workers and plant supervisors rarely receive the kind of tailored scenario training that mirrors the actual lures used against them: vendor impersonation, fake firmware update notifications, and urgent requests for remote-access credentials framed as maintenance calls.

The Iranian campaign described in this advisory does not rely purely on zero-day exploits. It looks for open doors: exposed devices, unchanged passwords, and operators who may not question an unfamiliar remote connection. That combination of technical and human vulnerability is exactly what well-designed security-awareness programmes are built to address.

What should facility operators do right now?

Start with an asset inventory. If you cannot name every PLC on your network and confirm it is not reachable from the internet, that gap is your most urgent risk. Next, audit credentials on every named-vendor device and change any factory defaults. Then apply available patches from Siemens, Schneider Electric, and Rockwell Automation, and monitor vendor security bulletins going forward.

For leadership, the advisory is a prompt to review incident-response plans specifically for OT environments. A plan built around data exfiltration looks very different from one built around physical process disruption. Both scenarios need to be on the table.

How stronger awareness training protects OT environments

  • Extend phishing-simulation programmes beyond corporate IT to include plant engineers, shift supervisors, and control-room operators who are rarely tested.
  • Use vendor-impersonation and fake-maintenance-request scenarios that mirror the lures Iranian threat actors actually use against OT staff.
  • Ensure all personnel who interact with remote-access systems understand how to recognise and escalate suspicious connection requests.

Train2Secure's awareness programme can be scoped to cover operational technology roles, not just office workers.

Start free, no card required

Frequently asked questions

Which PLC manufacturers are targeted by Iranian hackers according to the federal advisory?

The advisory names Siemens, Schneider Electric, and Rockwell Automation as the manufacturers whose programmable logic controllers are under active attack by Iranian state-linked hackers.

How do attackers break into industrial control systems like PLCs?

The most common entry points are PLCs left directly exposed to the internet without a firewall, and devices still running factory-default credentials that manufacturers publish in publicly available product manuals.

What is CIRCIA and does it apply to this threat?

CIRCIA, the Cyber Incident Reporting for Critical Infrastructure Act of 2022, will require critical-infrastructure operators to report significant cyber incidents within mandatory deadlines once final rulemaking is complete; advisories like this one define what regulators consider a material threat.

What immediate steps should a facility operator take after reading this advisory?

Operators should audit all PLCs from the three named vendors, remove any that are directly internet-facing, change factory-default credentials, and apply available firmware patches from each vendor.

Ready to Reduce Your Human Cyber Risk?

Sign up and start training your team in minutes. No sales calls, no demos — just pick a plan and go. Phishing simulations, video courses, and certificates from day one.

train2secure analytics dashboard showing training completion stats and user progress