Iranian-affiliated cyber actors exploit programmable logic controllers across U.S. critical infrastructure
Agencies are urgently warning U.S. organizations of ongoing Iranian-affiliated cyber targeting
of internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs).
These actions disrupted PLCs across several U.S. critical infrastructure sectors through
malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss.
An IC3 update adds new guidance on detecting malicious changes in reusable code modules exploited within Rockwell Automation PLC programs. It also expands scope to include observed targeting of Schneider Electric, Siemens and potentially other branded/manufactured PLCs, emphasizing the importance of restricting direct internet access and providing best practices for secure deployment.
Read more at IC3