U.S. Government Expands Warning on Iranian Cyberattacks Targeting Critical OT Infrastructure
The U.S. federal government has broadened its alert regarding Iranian-affiliated cyberattacks on internet-facing Operational Technology (OT) systems. Initially focused on specific PLC manufacturers, the revised advisory now includes a wider range of industrial control systems, emphasizing the continued threat to critical infrastructure.
The U.S. federal government has significantly expanded its warning concerning cyberattacks on internet-facing Operational Technology (OT) by threat actors affiliated with the Iranian regime. First issued in April, the initial advisory focused on **Programmable Logic Controllers (PLCs)** from **Rockwell Automation** and **Allen-Bradley**.
### Broadening the Scope of Targeted OT
On Wednesday, the **Cybersecurity and Infrastructure Security Agency (CISA)**, in conjunction with the **FBI** and the **Environmental Protection Agency (EPA)**, issued a revision that broadens the scope of targeted manufacturers. According to a CISA news release, the updated alert now βexpands the manufacturer scope to include observed targeting of **Schneider Electric**, **Siemens** and possible other PLC manufacturers.β Both Schneider and Siemens PLCs are extensively deployed in critical infrastructure sectors across the U.S. and globally.
### Observed Attack Methods and Impact
The observed incidents include βmalicious project file interactions and manipulation of data on **Human Machine Interface (HMI)** and **Supervisory Control and Data Acquisition (SCADA)** displays.β These attacks have resulted in βoperational disruption and financial lossβ for targeted organizations. PLCs are fundamental components of critical infrastructure, underpinning operations in power utilities, wastewater treatment facilities, and manufacturing plants.
### Persistent Threat and Mitigation Recommendations
Officials anticipate the pressure from Iran-affiliated attackers to persist. The advisory underscores the critical need for OT owners and operators to implement robust security measures, specifically advising them to βrestrict direct internet access and ensure secure PLC deployment.β
### Attribution Challenges and Geopolitical Context
While the federal advisory does not name specific cyber threat groups, attribution of Iranian government-affiliated attacks remains complex. Researchers note that the regime often employs ransomware gangs or other groups as a smokescreen to obscure its activities. For instance, a pro-Iranian hacktivist group that targeted a Los Angeles transit agency was later identified by researchers as an arm of the countryβs intelligence services.
This expanded warning comes amidst heightened geopolitical tensions. Former President Donald Trump recently issued a threat to target Iranian critical infrastructure, including bridges or power plants, should Tehran continue to target ships in the Strait of Hormuz.