Iranian Hackers Target U.S. Industrial Safety Systems

Recent reports indicate that Iranian-affiliated hackers are actively targeting internet-connected industrial controllers within critical U.S. infrastructure sectors, including water, energy, and government facilities. These cyber intrusions have led to operational disruptions and financial losses, as attackers manipulate control systems to interfere with essential processes.

The attackers focus on programmable logic controllers (PLCs), which are integral to managing industrial operations. By accessing exposed PLCs, they can alter project files and modify control logic, potentially leading to unsafe operating conditions. Notably, the hackers have been able to disable safety alarms and override shutdown protocols, allowing equipment to function beyond approved parameters without alerting operators.

In one documented case, a malicious project file retained sufficient legitimate ladder logic to keep downstream functions operational. However, it introduced instructions that bypassed safety-related functions, enabling equipment to operate outside established safety limits without immediate detection. Additionally, the attackers manipulated data displayed on human-machine interfaces (HMIs) and supervisory control and data acquisition (SCADA) systems, presenting normal readings to operators while underlying systems were compromised.

The Cybersecurity and Infrastructure Security Agency (CISA) has identified that these cyber actors are exploiting PLCs from multiple manufacturers, including Rockwell Automation’s CompactLogix and Micro850 devices, Schneider Electric’s Modicon M340, and Siemens’ S7-1200 controllers. The attackers gain access through internet-exposed devices, utilizing ports associated with industrial protocols and employing tools like Dropbear Secure Shell to establish remote connections.

To mitigate these threats, CISA recommends several measures:

  • Remove PLCs from direct internet exposure and implement monitored gateways or jump hosts for necessary remote access.
  • Review and compare controller project files against known-good versions, ensuring backups are verified before restoration.
  • Inspect connected modems, workstations, and operator interfaces for unauthorized changes.
  • Utilize physical mode switches on controllers to prevent remote modifications after legitimate work is completed.
  • Enforce strong, unique passwords and multifactor authentication for remote operational technology (OT) access.
  • Implement firewall restrictions and conduct regular log reviews to detect unusual activities.

These incidents underscore the critical need for robust cybersecurity practices within industrial environments. As cyber threats targeting critical infrastructure become more sophisticated, organizations must proactively secure their systems to prevent potential disruptions and ensure the safety of their operations.