logo

Iranian Hackers Target Siemens and Schneider PLCs, Causing Operational Disruptions

ID: 2af0938f-e68c-582e-974b-e902e19f8d1c

STIX ID: report--2af0938f-e68c-582e-974b-e902e19f8d1c

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

...
...

CISA and the FBI warn that Iran-affiliated hackers, including the CyberAv3ngers, have expanded campaigns against U.S. critical infrastructure by targeting Siemens, Schneider Electric, and Rockwell Automation PLCs; attackers used legitimate software to falsify sensor data, exploited known vulnerabilities (notably CVE-2021-22681), and caused operational disruptions and financial losses across sectors such as water treatment and energy, with recommendations to strengthen access controls and validate project files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.