Iranian State Actors Target Siemens and Rockwell ICS Devices
# Iranian State Actors Target Siemens and Rockwell ICS Devices
Energy and Utilities currently sits at #7 of 15 in our weekly targeting rankings. On the surface, the numbers aren't staggering—61 stories over the last seven days and 13 new incidents today. But the volume is a distraction. The nature of the activity is what matters.
We're seeing a shift in intent. The recent warnings from US federal agencies regarding Iranian nation-state actors aren't about data exfiltration or credential harvesting. They're targeting internet-facing operational technology (OT), specifically focusing on programmable logic controllers (PLCs) from Siemens, Schneider Electric, and Rockwell Automation.
This isn't a standard IT breach. It's an attempt to gain a foothold in the physical layer of infrastructure.
To understand this, we have to talk about the PLC. A PLC is essentially a ruggedized computer that tells a pump to turn on, a valve to close, or a circuit breaker to trip. They're the bridge between the digital command and the physical action. When an attacker targets a specific brand of PLC, they aren't looking for a database of emails. They're looking for the specific memory registers and protocols—like Modbus or Profinet—that allow them to manipulate physical hardware.
If you can send a "stop" command to a turbine or a "close" command to a cooling valve, you've moved from being a hacker to being a kinetic threat.
My confidence level here is moderate. I believe we're seeing "prepositioning"—the act of planting access for a future conflict—rather than active espionage. To move my confidence to high, I'd need to see evidence of "living-off-the-land" binaries specifically designed for OT environments or the discovery of custom firmware implants on those Siemens or Rockwell devices.
I distrust the immediate rush to call this "cyberwarfare." It's too easy to use that word to justify a budget increase. Most of the time, these intrusions are just loud, clumsy attempts to find a door that was left unlocked.
However, the specificity of the targeting suggests a level of tooling that isn't amateur. This rhymes with the Industroyer attacks in Ukraine back in 2016. That campaign didn't just hit the Windows servers managing the grid; it spoke the actual language of the electrical substations (the IEC 60870-5-104 protocol) to flip switches. The parallel breaks down in the current Iranian activity because we haven't yet seen a coordinated blackout. For now, they're just knocking on the doors.
It's not just state actors. We're seeing a broader vulnerability in the sector's data hygiene. Look at the recent breach at Origin Energy in Australia. While it's a data breach affecting customer records and financial info, it highlights a systemic weakness in the sector's perimeter.
The risk here is a convergence of threats. You have ransomware groups like Qilin—who've been active in other sectors this week—and nation-state actors both eyeing the same pipes. A ransomware group might encrypt a billing system for a payout, but a nation-state actor in the PLC layer can turn off the lights.
The real danger isn't the initial breach. It's the second-order effect.
Consider the insurance industry. Most cyber insurance policies have "War Exclusion" clauses. If an Iranian state actor triggers a blackout through a Rockwell PLC, the insurance provider might argue it's an act of war, not a cyber incident. This leaves the utility company—and by extension, the thousands of businesses and hospitals relying on that power—without a financial safety net for recovery. The downstream cost isn't just the lost electricity; it's the insolvency of the provider during a crisis.
Some will argue that this is just reconnaissance. They'll say the Iranians are just mapping the network to see what's there, and that the actual risk of a kinetic event is low because the "cost" of such an action is too high diplomatically.
I disagree. Prepositioning is the cost. By establishing persistence in the PLC layer now, the attacker creates a "turnkey" capability. They don't have to launch a complex attack during a crisis; they just have to send a single packet to a device they already control. The diplomacy doesn't matter when the switch is already in your hand.
Defenders in this sector are facing a brutal reality. They're managing legacy hardware that was never meant to be connected to the internet, running firmware that hasn't been updated since 2014, and trying to patch it while the system is running 24/7. You can't just reboot a power grid for a Tuesday morning patch cycle.
The attackers know this. They're not looking for a zero-day in every case; they're looking for the one Siemens controller that a technician left exposed to the public web for "easier remote management."
We should be watching for a specific shift in the telemetry: the appearance of "unauthorized logic changes" in PLC memory. If we start seeing reports of PLCs behaving erratically without a corresponding software crash, it means the prepositioning phase is over.
That's a scenario the sector isn't pricing in. They're worried about the data breach at the corporate level, while the actual threat is sitting in a controller in a substation three hundred miles away.
◼