Close Menu
    Facebook X (Twitter) Instagram
    Thursday, July 30
    • Home
    • About Us
    • Contact Us
    • Submit Your Story
    • Terms of Use
    • Privacy Policy
    Facebook X (Twitter) Instagram
    Fortune Herald
    • Business
    • Finance
    • Politics
    • Lifestyle
    • Technology
    • Property
    • Business Guides
      • Guide To Writing a Business Plan UK
      • Guide to Writing a Marketing Campaign Plan
      • Guide to PR Tips for Small Business
      • Guide to Networking Ideas for Small Business
      • Guide to Bounce Rate Google Analyitics
    Fortune Herald
    Home»Business»Iranian Hackers Targeting ICS Devices Expand Attacks to Siemens and Schneider Electric
    Iranian hackers targeting ICS
    Business

    Iranian Hackers Targeting ICS Devices Expand Attacks to Siemens and Schneider Electric

    Funke AdeyemiBy Funke Adeyemi30/07/2026No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Iranian hackers targeting ICS devices across America’s critical infrastructure have widened their list of victims beyond Rockwell Automation, with a CISA advisory updated on 22 July 2026 now naming Siemens and Schneider Electric hardware as active targets alongside the controllers first flagged in April.

    The advisory, originally published on 7 April 2026 and carrying the reference AA26-097A, is co-authored by eight agencies: CISA, the FBI, the NSA, the Environmental Protection Agency, the Department of Energy, the Cyber National Mission Force, and, in a first for a cyber advisory of this type, the Department of the Treasury. Treasury’s inclusion reflects the financial-sector exposure that OT disruption can trigger, a dimension the agencies are treating with increasing seriousness.

    According to the advisory, Iranian-affiliated advanced persistent threat actors have been conducting exploitation activity targeting internet-facing operational technology devices since at least March 2026. Victim organisations span government services and facilities, water and wastewater systems, and the energy sector. Some experienced operational disruption and financial loss.

    Iranian Hackers Targeting ICS Devices: What the Updated Advisory Adds

    The July update is not merely an expansion of the vendor list. SecurityWeek reports that the advisory now identifies specific device models under attack: Rockwell’s CompactLogix and Micro850 controllers, Schneider Electric’s BMX P34 and Modicon M340, and Siemens’ S7-1200 series. Inbound malicious traffic has been observed on ports 44818 and 2222 for Rockwell devices, port 102 for Siemens, port 502 for Modbus and Schneider equipment, and port 22 on connected cellular modems.

    The agencies warn that ‘potentially all internet exposed’ industrial control systems may be affected. The hackers manipulated data displayed on human-machine interfaces and supervisory control and data acquisition systems, and disabled the shutdown and alarm logic that operators rely on when something goes wrong. At one critical infrastructure provider, the FBI confirmed, the attackers changed programmable logic controller programming to disable processes handling critical shutdowns and alarms, allowing ‘systems to enter unsafe conditions without notifying operators of the anomalies.’

    The July update also introduces guidance on a new exfiltration technique. IOActive’s analysis of the revised advisory notes that the actors are using vendors’ own legitimate engineering software to steal PLC project files from victim environments, a method catalogued under MITRE ATT&CK technique T1041. The update also adds new guidance on detecting malicious changes in reusable code modules within Rockwell Automation PLC programmes.

    Handala’s Wider Campaign and the Cal Water Question

    The advisory sits within a broader pattern of Iranian state-linked cyber activity since the start of the Iran-US war in February. The Iranian hacking group Handala has been among the most active, taking credit for remotely wiping tens of thousands of employee devices at US medical technology company Stryker. The group also claimed responsibility for a breach at California Water Service, known as Cal Water, which serves two million people across 100 communities in California.

    On 11 June 2026, research firm Dataminr spotted Handala publishing five gigabytes of data from Cal Water, with leaked files exposing network infrastructure across seven distinct operational areas including Bakersfield, Chico, Salinas, Stockton, Visalia, San Mateo, and a regional engineering segment, according to HackRead. SecurityWeek’s reporting confirmed Cal Water’s Chico District as a victim, with the leaked data indicating the group likely accessed a customer billing database and Cal Water’s internal RTKBase application. The RTKBase instance had been running for approximately 783 continuous hours at the time of access.

    Handala also claimed it could have disrupted the water supply, though it offered no supporting evidence. Cal Water’s own investigation, detailed by SecurityWeek, found that the threat actor accessed one active customer’s online account using stolen credentials and reached an external third-party GPS location correction tool. The investigation found no evidence of activity within Cal Water’s operational technology environment, which controls the physical water supply.

    The distinction matters. Billing databases and OT networks are separated by design, and the evidence so far suggests Handala did not cross that line at Cal Water. Whether the same holds for the unnamed critical infrastructure provider where controllers were reprogrammed to suppress alarms is a different question entirely, and one the agencies have not yet answered publicly.

    The agencies urged critical infrastructure owners to audit all internet-exposed devices immediately. With the advisory now explicitly warning that ‘conducting this activity to cause disruptive effects within the United States’ is the stated objective, the question for operators is how long any internet-connected controller can remain unpatched before it becomes the next case study in the next update.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Funke Adeyemi

    Funke Adeyemi spent a decade in corporate banking and fintech before moving to business journalism. She started in trade finance at a major UK bank, moved to a payments company scaling into African markets, and spent her last role leading partnerships at a cross-border remittance platform. She writes about business strategy, fintech, digital banking, and the corporate news that moves markets. She is interested in how companies actually make money rather than how they describe making money in investor presentations. Funke lives in South London. She reads earnings calls the way other people listen to podcasts, and finds them about as reliable.

    Related Posts

    Experts Challenge Kimi K3 Distillation Claims as Chip Smuggling Takes Centre Stage

    29/07/2026

    ServiceNow Backs $40m BusinessNext Investment to Drive AI Banking Push

    29/07/2026

    IBM Mainframe Business Decline Wipes $67bn in Market Value in Single Day

    29/07/2026
    Leave A Reply Cancel Reply

    Fortune Herald Logo

    Connect with us

    FortuneHerald Logo

    Home   About Us   Contact Us   Submit Your Story   Terms of Use   Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.