According to OffSeq.com's threat radar, US officials have warned of Iranian hackers actively targeting industrial control systems from Siemens, Schneider Electric, and Rockwell Automation. The advisory names specific vulnerable models: Rockwell CompactLogix and Micro850, Schneider Modicon M340 (BMX P34), and Siemens S7-1200 series.
The attackers established connections over ports 44818, 2222, 102, 502, and 22 using leased third-party infrastructure—a tactic that complicates attribution and geographic blocking. The threat intelligence reflects what the source describes as advancing Iranian ICS attack capabilities against critical infrastructure targets.
Why this matters: These PLCs control real-world systems. Siemens S7 series manage water treatment, power distribution, and manufacturing. Rockwell and Schneider devices run similar functions across North America. Unlike ransomware that encrypts files, ICS compromise could allow attackers to manipulate physical processes—valve positions, pressure settings, flow rates—without triggering alarms if access is subtle enough.
The advisory provides detection techniques and indicators of compromise (IoCs) but does not mention available patches or fixes. This gap is significant: defenders have detection signatures but no clear remediation path yet. Organizations running these systems face a detection-only window until vendor patches arrive—if they arrive.
What to watch: Monitor vendor advisory channels (Siemens ProductCERT, Rockwell Security, Schneider CyberSecurity) for patch releases in the coming days. If patches remain unavailable, expect organizations to shift toward network segmentation, increased monitoring of the named ports, and potential temporary operational changes. The use of common industrial protocols (Modbus on port 502, S7 on 102) makes these attacks scalable across customer bases.
This is active threat intelligence, not historical analysis. The advisory was first logged July 24, 2026. Asset owners running these specific PLC models should prioritize network visibility into east-west traffic on the flagged ports and consider whether their ICS environment can tolerate the operational friction of enhanced isolation measures.

