Iranian hackers breach US water and energy systems, agencies warn

US water and energy operators are facing a fresh wave of Iranian cyber threats after federal agencies reported that state-linked hackers have already breached control systems and altered their programming to bypass safety mechanisms. The joint advisory from CISA, the FBI, NSA, and the Department of Energy confirms that actors affiliated with Iran have gained access to programmable logic controllers (PLCs) that run pumps, valves, and alarms in critical infrastructure. Once inside, they manipulate human-machine interfaces and SCADA displays, sometimes rewriting controller logic to disable shutdown and alarm functions, leaving systems operating in unsafe states without operators noticing.
A widening campaign with familiar tactics
This isn’t the first alert about Iranian activity in industrial networks. In April, the same agencies flagged attacks on Rockwell Automation controllers. The updated advisory now includes Schneider Electric and Siemens equipment, widening the potential attack surface. Attackers typically access exposed devices via OT ports (44818, 2222, 102, 502) or modem connections over SSH (port 22), then exfiltrate PLC project files using vendor tools such as Studio 5000, EcoStruxure Control Expert, and TIA Portal. They modify or delete project logic, including Add-On Instructions, before pushing malicious updates back to the controllers.
What defenders should do right now
Agencies recommend taking exposed PLCs off the public internet by routing traffic through secure gateways and firewalls. They also advise monitoring logs for indicators of compromise on OT ports and reviewing vendor security best practices. Rockwell users are urged to set controllers to Run mode, while any suspected victim should immediately contact both the vendor and federal agencies. The advisory stresses that any internet-exposed industrial control system could be in the crosshairs.
Why it matters
These intrusions go beyond espionage. By altering control logic to override safety parameters, attackers can turn routine operations into hazards without triggering alarms. The fact that agencies updated their guidance to include multiple vendors shows this is a scalable threat, not an isolated incident. For plant operators and utilities, the takeaway is clear: if your PLCs are reachable from the public internet, assume you’re a target—and act accordingly.
Read the full advisory from CISA
Source: Security Affairs. AI-assisted editorial synthesis — TechnoExpress.

