logo

Hackers Exploit Industrial PLCs and Manipulate HMI Displays to Hide Attacks

ID: 6801ac52-111e-51bc-9986-7f7fbf9bc986

STIX ID: report--6801ac52-111e-51bc-9986-7f7fbf9bc986

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-07-25

Date Updated: 2026-07-25

Author: Eswar

...
...

Six U.S. federal agencies warn that Iranian-affiliated APT actors are actively exploiting internet-exposed PLCs (including Rockwell/Allen-Bradley, Siemens, Schneider, Unitronics) to modify controller logic and falsify HMI displays, causing operational disruption and financial loss; the advisory includes observed IOCs and ports (22, 102, 502, 2222, 44818), expands detection guidance for tampered reusable logic modules, and recommends immediate mitigations such as removing PLCs from direct internet exposure, routing remote access through MFA-protected gateways, setting physical mode switches appropriately, enabling vendor programming protections, and maintaining offline backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.