FBI, NSA & CISA warns: Iranian hackers hit critical US infrastructure & safety systems
US federal agencies have issued a joint warning regarding Iranian-backed hackers targeting critical infrastructure, specifically water and energy systems. The attackers are manipulating industrial control systems to disrupt operations and cause financial damage.
US federal cyber agencies have issued an urgent joint warning, claiming that Iranian state-backed hackers are actively breaching and tampering with industrial control systems at US water and energy providers. In an updated security advisory, the Federal Bureau of Investigation (FBI), the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the Department of Energy warned that “potentially all internet-exposed” industrial control systems across critical US infrastructure could be vulnerable to attack.‘Tampering with safety alarms and emergency shutdowns’According to federal investigators, the Iranian-backed hackers are targeting programmable logic controllers, which are the specialised digital computers that govern physical machinery, valves, and power switches across utility networks.As per the warning, by altering display data and programming logic, the attackers have forced systems into dangerous operational states without alerting human supervisors. CISA and partner agencies are calling on all critical infrastructure operators to immediately audit their operational technology, disconnect industrial control systems from the public internet, and enforce strict multi-factor authentication.Read the updated warning by FBI, NSA and CISAThe authoring agencies urgently warn U.S. organizations of ongoing Iranian-affiliated cyber targeting of internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs). These actions disrupted PLCs across several U.S. critical infrastructure sectors through malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss.Last Update DescriptionThis update adds new guidance on detecting malicious changes in reusable code modules exploited within Rockwell Automation PLC programs. It also expands scope to include observed targeting of Schneider Electric, Siemens, and potentially other branded/manufactured PLCs, emphasizing the importance of restricting direct internet access and providing best practices for secure deployment.Affected ProductsPotentially all internet exposed PLCs, including Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and other branded/manufactured PLCs.Key Actions Install PLCs consistent with manufacturers' guidelines and security best practices.Remove PLCs from direct internet exposure via secure gateway and firewall; work with IT/OT team members and/or integrators to perform this action.Query available logs for the provided indicators of compromise (IOCs) and check available logs for suspicious traffic on the ports associated with OT devices, including 44818, 2222, 102, and 502, especially traffic originating from foreign hosting providers.For Rockwell Automation devices, place the physical mode switch on the controller into run position. If you suspect your organization was targeted, including against other branded PLC devices, contact the authoring agencies and PLC manufacturer for guidance.Get the latest technology news and updates. Download the TOI App.
Get the full story
Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.
Create free accountAlready have an account? Sign in