Feds warn Iranian hackers now targeting Siemens, Schneider Electric gear

Advertisement

The Cybersecurity and Infrastructure Security Agency, FBI and five other federal partners have updated a joint advisory warning that Iranian-affiliated hackers are now targeting programmable logic controllers (aka PLCs) made by Siemens and Schneider Electric.

The July 22 update adds guidance for detecting malicious changes to reusable code modules in Rockwell Automation PLC programs and flags targeting of Schneider Electric’s Modicon M340 and Siemens’ S7-1200 series controllers, alongside Rockwell’s CompactLogix and Micro850 devices. The agencies said Iranian-affiliated actors have exploited internet-connected PLCs since at least March by altering project files and manipulating data on human-machine interface and supervisory control and data acquisition displays, causing operational disruption and financial loss at some victim organizations.

PLCs are used across healthcare in climate control and access control systems, according to the American Hospital Association, which flagged the update for hospital cybersecurity teams. Hospitals and health systems using affected brands are urged to remove the devices from direct internet exposure and review logs for the newly published indicators of compromise.

A spokesperson for Rockwell Automation, whose PLCs were first named in the April advisory, told Becker’s the “company takes seriously the security of its products and solutions and has been engaged with government agencies in connection with the joint Cybersecurity Advisory.” The company pointed to security advisories it published in 2021 and 2026 with recommendations for hardening operational technology deployments.

The advisory follows a wider pattern of Iranian-linked activity against U.S. healthcare-adjacent targets in 2026, including a March cyberattack on medical device maker Stryker.

Advertisement

Next Up in Cybersecurity

Advertisement