Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Vatican Click to Pray App API Flaw Exposes 700,000 User Records
July 27, 2026
Claude Opus 5 AI Identifies Software Vulnerabilities, Cannot Create Exploits
July 27, 2026
Iranian Hackers Disable Industrial Safety Alarms in Critical Infrastructure
July 27, 2026
Home/Threats/Iranian Hackers Disable Industrial Safety Alarms in Critical Infrastructure
Threats

Iranian Hackers Disable Industrial Safety Alarms in Critical Infrastructure

Key Takeaways Iranian-backed threat actors are actively targeting internet-exposed industrial control systems (ICS) across critical infrastructure in the U.S. The attackers are manipulating...

Emy Elsamnoudy
Emy Elsamnoudy
July 27, 2026 4 Min Read
2 0

Key Takeaways

  • Iranian-backed threat actors are actively targeting internet-exposed industrial control systems (ICS) across critical infrastructure in the U.S.
  • The attackers are manipulating Programmable Logic Controllers (PLCs) to disable safety alarms and alter operational data, creating severe risks of physical disruption and equipment damage.
  • The campaign affects devices from multiple major vendors, including Rockwell Automation, Schneider Electric, and Siemens.
  • Poorly secured, publicly accessible PLCs are the primary entry point for these attacks.

A persistent cyber campaign linked to Iranian state-sponsored groups is targeting internet-connected industrial controllers within critical infrastructure sectors across the United States. These malicious activities pose a significant threat to essential services such as water, energy, and government operations, where even minor alterations to control logic can lead to severe real-world consequences.

Table Of Content

  • Key Takeaways
  • Iranian Hackers Manipulating Industrial Safety Alarms
  • Exposed PLCs Provide Initial Access
  • What You Should Do

The attackers are exploiting publicly exposed Programmable Logic Controllers (PLCs), gaining unauthorized access to and manipulating the project files that dictate their operations. This intrusion allows them to alter the information displayed on operator screens, effectively blinding staff to abnormal system behaviors and potential dangers.

According to analysts from the Cybersecurity and Infrastructure Security Agency (CISA), this campaign has expanded beyond a single manufacturer, now encompassing devices from several prominent industrial automation providers. CISA has indicated that the ongoing activity has already resulted in operational disruptions and financial losses for affected organizations.

In a report shared with Cyber Security News (CSN), CISA said in a report that Iranian-linked actors leverage third-party hosted infrastructure and industrial programming software to infiltrate vulnerable systems. This advisory underscores the critical risk presented by exposed industrial equipment, which serves as a direct gateway for threat actors aiming to interrupt physical operations.

Iranian Hackers Manipulating Industrial Safety Alarms

The most alarming aspect of this campaign is the documented manipulation of safety controls. Investigators have discovered that attackers are capable of modifying or entirely removing PLC project logic, including critical reusable code components designed to maintain safe operating limits within industrial processes.

In one specific incident, a malicious project file was observed to retain enough legitimate ladder logic to keep downstream functions operational. However, it also incorporated additional instructions that specifically overrode safety-related functions, allowing equipment to continue running outside approved parameters without immediately triggering alerts or drawing operator attention.

Furthermore, the attackers have been manipulating data presented through human-machine interface (HMI) and supervisory control screens. This sophisticated tactic means that an operator might observe seemingly normal values on their display, while the underlying controller has been compromised and altered. This creates a dangerous disparity between the actual conditions in the field and what personnel perceive, increasing the risk of catastrophic failure.

Such a risk is particularly severe in sectors where alarms and shutdown logic are specifically engineered to halt equipment before conditions escalate to unsafe levels. This ongoing campaign reiterates concerns previously highlighted in various industrial control system advisories, emphasizing how exposed devices and inadequate remote-access controls continue to create avoidable vulnerabilities within critical infrastructure.

CISA specifically identified targeted devices as Rockwell Automation CompactLogix and Micro850, Schneider Electric Modicon M340, and Siemens S7-1200 PLCs. The agency also cautioned that other internet-facing controllers could be susceptible to similar opportunistic attacks.

Exposed PLCs Provide Initial Access

The threat actors gained access to PLCs that were directly accessible from the public internet, utilizing ports commonly associated with industrial protocols. Reports also indicate their use of Dropbear Secure Shell software on compromised modems to establish remote access via port 22.

Once a device was compromised, the group was able to extract project files, thoroughly analyze the operating environment, and upload their modified logic. This capability allows attackers to customize their changes specifically for a victim’s unique industrial process, moving beyond generic disruption methods to highly targeted sabotage.

What You Should Do

  • Remove PLCs from Direct Internet Exposure: Ensure all PLCs are isolated from the public internet. Implement secure remote access solutions, such as monitored gateways or jump hosts, for any necessary external connectivity.
  • Implement Secure Connectivity Principles: Adhere to secure connectivity principles for Operational Technology (OT), emphasizing controlled access, robust logging, network segmentation, and comprehensive isolation plans.
  • Regularly Review Project Files and Backups: Periodically compare current controller project files against known-good versions. Verify the integrity of all backups before restoration and inspect connected modems, workstations, and operator screens for any unauthorized modifications.
  • Utilize Physical Mode Switches: For controllers equipped with a physical mode switch, set it to the “run” position after legitimate work is complete to prevent unauthorized remote modifications.
  • Strengthen Authentication and Access Controls: Enforce strong, unique passwords and multi-factor authentication (MFA) for all remote OT access. Implement strict firewall rules and conduct regular reviews of network logs.
  • Monitor for Suspicious Activity: Actively monitor for unusual connections to industrial ports, unexpected programming activity, and login attempts originating from unfamiliar or foreign hosting providers.
  • Maintain Accurate Asset Inventories: Develop and maintain precise asset inventories for all industrial control systems. Clearly define ownership and responsibility for all remote connections.
  • Prioritize External-Facing Controllers: Treat every externally reachable controller as a high-priority exposure. Isolate or secure these devices immediately if they are accessible from the public internet.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Wrench Attacks Force Crypto Wallet Unlocks, Bypassing Encryption

Next Post

Claude Opus 5 AI Identifies Software Vulnerabilities, Cannot Create Exploits

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Microsoft Windows Enterprise Activation Moves to Hardware Verification
July 27, 2026
Anthropic Claude Opus 5 on AWS boosts cybersecurity capabilities
July 27, 2026
Critical WalletService Flaw (CVE-2024-XXXX) Lets Attackers Control Windows Systems
July 27, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us