Federal agencies broaden alert on Iran-linked OT attacks
The U.S. government is widening its alert about ongoing cyberattacks targeting operational technology (OT) systems by Iranian-linked hackers. The initial warning focused on Rockwell Automation and Allen-Bradley PLCs, and now includes Schneider Electric and Siemens, highlighting the increasing risk to critical infrastructure sectors like power utilities and manufacturing.
The U.S. government has expanded its warning regarding cyberattacks targeting operational technology (OT) systems, specifically focusing on attacks originating from Iran. The initial advisory, issued in April, centered on programmable logic controllers (PLCs) manufactured by Rockwell Automation and Allen-Bradley. A recent update, released on Wednesday, significantly broadened the scope of affected manufacturers, now including Schneider Electric and Siemens, alongside the potential targeting of other PLC manufacturers. These attacks involve malicious project file interactions and manipulation of data displayed on human machine interface (HMI) and supervisory control and data acquisition (SCADA) systems, leading to operational disruptions and financial losses for targeted organizations. PLCs are fundamental components of critical infrastructure, including power utilities, wastewater treatment facilities, and various manufacturing plants. Federal agencies, including CISA, the FBI, and the EPA, anticipate continued pressure from Iran-affiliated attackers. Attribution of these attacks is complex, as the Iranian regime sometimes utilizes ransomware gangs or other groups as proxies. A pro-Iranian hacktivist group that previously targeted a Los Angeles transit agency was, in fact, a component of Iran’s intelligence services. The advisory stresses the importance of restricting direct internet access and ensuring secure PLC deployment to mitigate these risks.
