Dominic Jainy stands at the forefront of the modern digital battlefield, bridging the gap between sophisticated information technology and the gritty, physical world of industrial automation. With a deep background in artificial intelligence and blockchain, he has spent years analyzing how emerging technologies can both fortify and accidentally expose the critical systems that keep our lights on and our water flowing. As international tensions spill over into the cyber domain, Jainy’s insights into the recent waves of targeting against global industrial giants provide a necessary perspective on why our utility grids are more vulnerable than ever. This conversation explores the strategic shifts in adversarial tactics, the technical manipulation of the logic governing our infrastructure, and the urgent steps required to protect public safety.
The landscape of industrial threats seems to be widening, with major players like Schneider Electric and Siemens now firmly in the crosshairs. How has the targeting of these industrial systems evolved from simple probes to the sophisticated campaigns we see today?
We are witnessing a profound shift where Iranian adversaries have moved past opportunistic scanning to a highly calculated offensive against the backbone of American infrastructure. Initially, the focus was largely centered on Rockwell Automation and its Allen-Bradley line, but the US Cybersecurity and Infrastructure Security Agency has now confirmed that these advanced persistent threat actors have expanded their reach to include Siemens S7-1200 series and Schneider’s Modicon M340 and BMX P34 models. This is no longer just about making a statement; it is a systematic effort to achieve operational disruption and inflict real financial loss. By downloading malicious project files directly into programmable logic controllers, these actors are proving they can navigate diverse proprietary environments with alarming ease. It is a cold, strategic expansion that treats every internet-exposed industrial component as a potential doorway to paralyzing a city’s vital services.
When we talk about manipulating programmable logic controllers or overriding ladder logic, what does that actually look like in a real-world operational environment?
The technical reality is quite chilling because it involves rewriting the very “brain” of the machinery to ignore safety protocols while the human operators remain largely in the dark. These actors use configuration software to insert malicious logic that overrides the specific instruction sets responsible for maintaining safe operating parameters, such as pressure limits or temperature controls. While the PLC is being forced to perform dangerous actions, the attackers simultaneously manipulate the data on human-machine interface and SCADA displays so that everything appears normal to the technician on the floor. It creates a sensory disconnect where the digital readout shows a stable system, but the physical hardware is being pushed toward a catastrophic failure. This level of deception, which we’ve seen from groups like CyberAv3ngers, demonstrates a terrifying mastery of how industrial reusable code modules can be weaponized against their owners.
It is particularly striking that these actors are using the industry’s own specialized configuration tools to facilitate these breaches. How are they turning legitimate software into a weapon of exfiltration?
This is perhaps the most clever aspect of the current campaign, as the attackers are leveraging the same tools that engineers use for maintenance—like Rockwell’s Studio 5000 Logix Designer, Schneider’s EcoStruxure Control Expert, and Siemens’ TIA Portal. They deploy these applications on leased, third-party hosted infrastructure to blend in with legitimate traffic while they exfiltrate device project files from the controllers to their own command servers. By pulling these files, they gain a blueprint of the victim’s entire operational logic, allowing them to tailor their attacks with surgical precision. It essentially turns a facility’s own technical documentation and management software into a roadmap for its destruction. This method bypasses traditional detection because the traffic often mimics standard engineering workflows, making it incredibly difficult for security teams to spot the theft until the malicious changes have already been implemented.
Given that the energy, water, and wastewater sectors are being specifically hit, what particular hardware vulnerabilities are making these facilities such attractive targets for groups like the IRGC?
The vulnerability often boils down to the simple fact that many of these devices, specifically models like the Allen-Bradley CompactLogix and the Siemens S7-1200, were never intended to be directly exposed to the open internet. In sectors like water and wastewater, the need for remote monitoring has led many organizations to bypass secure gateways, leaving ports like 44818, 2222, 102, and 502 wide open to malicious actors. These specific ports are the lifeblood of industrial communication, and by gaining access to them, groups like the Shahid Kaveh Group or Storm-0784 can gain total control over the flow of resources. The FBI and CISA have noted that once these actors find an internet-exposed PLC, they can rapidly deploy their logic overrides because the hardware often lacks the robust, multi-layer authentication we see in standard IT environments. It is the intersection of legacy hardware and modern connectivity that has created this perfect storm for critical infrastructure providers.
For the organizations currently managing these critical systems, what are the most immediate and impactful actions they can take to stop these intrusions before they result in physical damage?
The first and most non-negotiable step is to immediately remove all PLCs from direct internet exposure by placing them behind a secure gateway or a robust firewall. For those running Rockwell Automation hardware, a very simple but effective physical action is to place the physical mode switch on the controller into the “run” position, which prevents remote logic changes from being finalized without physical intervention. Organizations must also become obsessive about their logs, specifically hunting for indicators of compromise on the common OT ports like 502 for Modbus or 102 for Siemens S7comm traffic. Finally, it is vital to follow the manufacturer’s security best practices to the letter, as many of these “hacks” are actually the exploitation of default settings and reusable code modules that haven’t been properly secured. It is about returning to the fundamentals of air-gapping and physical hardware control to negate the advantages these remote APT actors currently enjoy.
What is your forecast for the future of industrial control system security over the next few years?
I expect we will see a mandatory shift toward “secure-by-design” regulations where the industry can no longer rely on the user to flip a physical switch to protect their infrastructure. As we see more persistent campaigns from actors like Bauxite and the Cyber-Electronic Command, the pressure will mount for PLC manufacturers to integrate hardware-level encryption and immutable audit logs that cannot be manipulated by configuration software. We are entering an era where the digital and physical worlds are so intertwined that a breach in a water treatment plant will be treated with the same severity as a kinetic military strike. Consequently, the role of AI in these systems will evolve from simple automation to active defense, using machine learning to detect anomalous ladder logic changes in real-time before they can ever be executed. The “set it and forget it” mentality of industrial technology is dead; the future is one of constant, automated vigilance.
