Skip to content
Data Breach

Iranian Hackers Are Disabling Industrial Safety Alarms and Hiding It From Operators

Iranian-affiliated hackers are targeting internet-connected industrial controllers used across critical infrastructure in the United States. Their activity can disrupt essential processes in water, energy, and government environments, where even a small change to control logic can create serious rea...

· Jul 27, 2026 · 5 min read · 👁 0 views
Iranian Hackers Are Disabling Industrial Safety Alarms and Hiding It From Operators

Iranian-affiliated hackers are targeting internet-connected industrial controllers used across critical infrastructure in the United States.

Their activity can disrupt essential processes in water, energy, and government environments, where even a small change to control logic can create serious real-world consequences.

The attackers are gaining access to publicly exposed programmable logic controllers, or PLCs, then interacting with the project files that run them.

They have also altered information shown on operator screens, making it harder for staff to see when systems are behaving abnormally.

Analysts from CISA noted that the campaign has expanded beyond one manufacturer and now includes devices from several major industrial automation providers.

The agency said the activity has caused operational disruption and financial losses at affected organizations.

CISA said in a report shared with Cyber Security News (CSN) that Iranian-linked actors used third-party hosted infrastructure and industrial programming software to reach poorly secured systems.

The warning highlights how exposed industrial equipment can become a direct entry point for attackers looking to interrupt physical operations.

Iranian Hackers Are Disabling Industrial Safety Alarms

The most concerning part of this campaign is the manipulation of safety controls. Investigators found that attackers could modify or remove PLC project logic, including reusable code components that help maintain safe operating limits inside industrial processes.

In one observed incident, a malicious project file retained enough legitimate ladder logic to keep downstream functions working.

However, it added instructions that overrode safety-related functions, allowing equipment to continue operating outside approved parameters without immediately drawing attention.

The attackers also manipulated data presented through human-machine interface and supervisory control screens.

This means an operator could see normal-looking values while the underlying controller has been altered, creating a dangerous gap between what is happening in the field and what staff believe is happening.

That risk is especially severe in sectors where alarms and shutdown logic are designed to stop equipment before conditions become unsafe.

The campaign reinforces concerns raised in recent industrial control system advisories, where exposed devices and weak remote-access controls continue to create avoidable risk.

CISA said the actors targeted CompactLogix and Micro850 devices, as well as Schneider Electric Modicon M340 and Siemens S7-1200 PLCs.

The agency also warned that other internet-facing controllers may be vulnerable to similar opportunistic activity.

Exposed PLCs Create an Opening

The threat actors accessed PLCs that were directly reachable from the internet, using ports commonly associated with industrial protocols.

They also reportedly used Dropbear Secure Shell software on compromised modems to establish remote access through port 22.

After reaching a device, the group could extract project files, study the operating environment, and upload altered logic.

This gives attackers a way to tailor changes for a victim’s process rather than relying on a one-size-fits-all disruption method.

Operators should remove PLCs from direct public internet exposure and route necessary remote access through a monitored gateway or jump host.

The approach aligns with secure connectivity principles for OT, which stress controlled access, logging, network separation, and isolation plans.

Organizations should also review controller project files against known-good versions, verify backups before restoring them, and inspect connected modems, workstations, and operator screens for signs of unauthorized changes.

For controllers with a physical mode switch, placing it in the run position can prevent remote modifications after legitimate work is complete.

Strong, unique passwords, multifactor authentication for remote OT access, firewall restrictions, and regular log reviews are also essential.

Security teams should look closely at unusual connections to industrial ports, unexpected programming activity, and login attempts originating from foreign hosting providers.

The incident also shows why industrial teams need accurate asset inventories and clear ownership of remote connections.

As Iran-linked PLC attacks continue, defenders should treat every externally reachable controller as a high-priority exposure until it is secured or removed from public access.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
IP address185.82.73.175Actor association: September 2025 to February 2026
IP address141.11.164.153Actor association: January 2026 to June 2026
IP address175.110.121.42Actor association: February 2026 to March 2026
IP address175.110.121.39Actor association: February 2026 to March 2026
IP address175.110.121.41Actor association: February 2026 to March 2026
IP address175.110.121.107Actor association: February 2026 to February 2026
IP address192.142.54.79Actor association: May 2026 to June 2026
IP address84.200.205.165Actor association: May 2026 to June 2026
IP address185.225.17.225Actor association: June 2026 to July 2026
IP address79.133.46.209Actor association: July 2026 to July 2026
IP address88.80.150.199Actor association: July 2026 to July 2026
IP address88.80.150.200Actor association: July 2026 to July 2026
IP address88.80.150.202Actor association: July 2026 to July 2026
IP address185.82.73.162Actor association: January 2025 to March 2026
IP address185.82.73.164Actor association: January 2025 to March 2026
IP address185.82.73.165Actor association: January 2025 to March 2026
IP address185.82.73.167Actor association: January 2025 to March 2026
IP address185.82.73.168Actor association: January 2025 to March 2026
IP address185.82.73.170Actor association: January 2025 to March 2026
IP address185.82.73.171Actor association: January 2025 to March 2026
IP address135.136.1.133Actor association: March 2026 to March 2026

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Related Articles

Recommended for you