Iranian hackers target Siemens and Schneider Electric systems in US infrastructure breaches
US agencies warn that Iranian state-backed hackers are disrupting American water and energy networks using industrial control systems made by European giants Siemens and Schneider Electric, raising urgent cybersecurity concerns for European manufacturers and critical infrastructure operators.
US federal agencies have warned that Iranian state-backed hackers are actively breaching and disrupting industrial control systems at American water and energy providers. The joint advisory from the FBI, NSA, Department of Energy and CISA highlights a direct threat to critical operational networks.
Crucially for European industry, the targeted equipment now explicitly includes programmable logic controllers manufactured by Germany’s Siemens and France’s Schneider Electric. While earlier attacks this year focused on Rockwell controllers, this expansion signals a broader campaign against widely used European industrial technology.
According to the advisory, these actors manipulate data on internet-connected operational networks to cause outages and disruption. The FBI noted that hackers successfully breached at least one critical infrastructure provider, altering programming logic to disable critical shutdown and alarm processes.
This manipulation allowed systems to enter unsafe conditions without notifying operators of the anomalies. The agencies cautioned that potentially all internet-exposed industrial control systems may be vulnerable to similar exploitation.
US authorities state the Iranian-backed actors are conducting this activity to cause disruptive effects within the United States. This escalation aligns with ongoing geopolitical tensions and the war involving Iran, the US and Israel that began in February.
Since February, Iranian proxies have executed severe attacks ranging from leaking the personal email of FBI director Kash Patel to destructive operations. For instance, the group Handala remotely wiped tens of thousands of devices at US medical technology company Stryker.
Handala also claimed responsibility for a June breach at California water provider Cal Water, alleging it could have disrupted the water supply. However, the provider stated it found no evidence of unauthorized access to the operational networks controlling its water systems.
For European markets and investors, the explicit naming of Siemens and Schneider Electric products raises immediate risk assessments for industrial cybersecurity. Companies operating critical infrastructure across Europe must urgently audit their internet-facing control systems, as the tactics deployed in the US are highly transferable to European networks.