The US Cybersecurity and Infrastructure Security Agency (CISA) has expanded the scope of its alert on attacks by Iranian-affiliated hackers targeting critical infrastructure. Originally focused on programmable logic controllers (PLCs) from Rockwell Automation/Allen-Bradley, the update now includes devices from Schneider Electric, Siemens, and other manufacturers. This shift shows that threat actors are not limited to a specific brand but seek any exposed equipment that allows them to cause disruption. Since March, authorities have detected an increase in intrusions against PLCs used in water, energy, and other essential industrial processes.
PLCs are the brains of industrial automation: they control motors, valves, sensors, and safety systems. An attack that modifies their logic can have catastrophic consequences, from contaminant spills to explosions. CISA reported that attackers, identified as CyberAv3ngers or Shahid Kaveh Group, linked to Iran's Islamic Revolutionary Guard Corps (IRGC), exploit open ports, especially port 22 using Dropbear SSH software, to gain remote access. Once inside, they extract PLC project files and alter or delete control logic. In one documented case, they disabled emergency stop logic and alarms, allowing systems to operate in unsafe conditions without notifying operators.
The expansion of focus to equipment from Schneider and Siemens indicates that hackers are scanning the internet for any accessible PLC, regardless of manufacturer. This underscores the urgent need for organizations to review their attack surfaces. CISA-recommended measures include disconnecting PLCs from the internet, implementing isolated network architectures (e.g., using VPNs or DMZs), controlling physical and logical access, periodically verifying project file integrity, changing default passwords, and ensuring service providers are aware of these threats.
In this growing risk scenario, critical infrastructure companies cannot rely solely on reactive measures. They need a proactive, multi-layered approach spanning perimeter security to continuous monitoring. This is where the expertise of a company like Q2BSTUDIO becomes crucial. With a strong track record in cybersecurity for industrial and OT environments, Q2BSTUDIO helps organizations identify security gaps, design custom defenses, and respond effectively to incidents. Their engineers conduct security audits, penetration testing, and vulnerability assessments specific to PLC environments.
Beyond traditional security, artificial intelligence plays an increasingly important role in early threat detection. AI agents can analyze real-time data streams, identify anomalous patterns in network traffic or PLC logic, and generate alerts before an attack materializes. Q2BSTUDIO develops custom AI solutions that integrate with existing control systems, enabling proactive monitoring without replacing entire infrastructure.
The cloud also offers significant advantages for industrial cybersecurity. Migrating certain services to platforms like AWS or Azure allows centralized identity management, advanced security policies (such as encryption and virtual network segmentation), and secure backups outside the operational environment. Q2BSTUDIO provides cloud computing services specialized in industrial settings, ensuring high availability, regulatory compliance, and reduced operational costs.
Another key tool is Business Intelligence applied to security. With Power BI, companies can create dashboards that visualize key metrics: number of unauthorized access attempts, PLC status, firmware versions, configuration changes, etc. These dashboards enable security teams and management to make informed and rapid decisions. Q2BSTUDIO offers BI and Power BI services tailored to the industrial sector, integrating data from multiple sources for a holistic view of the security posture.
Finally, custom software development is essential to address specific needs that standard solutions do not cover. For example, a tailored PLC asset management tool that automates file integrity verification, change logging, and compliance reporting. Q2BSTUDIO designs and develops custom software for security process automation, using modern technologies and adapting to each client's environment. This allows organizations to improve operational efficiency and reduce risk exposure.
The Iranian threat to PLCs is not an isolated incident. It is part of a global trend of attacks on critical infrastructure by state actors and sponsored groups. Companies must act urgently: review their security posture, invest in staff training, update equipment and firmware, segment networks, and have technology partners like Q2BSTUDIO to implement robust and adaptive defenses. The combination of traditional cybersecurity, artificial intelligence, cloud, BI, and custom software creates a solid barrier against these advanced threats.
In conclusion, the expansion of Iranian hackers' targets to Schneider and Siemens PLCs demands an immediate and strategic response. Organizations that integrate innovative technologies with strong security practices will be better prepared to protect their critical assets and ensure business continuity. Q2BSTUDIO, as a technology partner, offers the capabilities needed to navigate this complex environment with confidence.





