HACK/PROJECT Daily Threat Intelligence
Threat feed live Updated — 28.07.2026 10:32 CET 51 dossiers MITRE ATT&CK mapping

Iranian-affiliated actors — CISA and partners joint advisory AA26-097A (updated 22 July 2026)high

Water and energy: the warning on Iranian-affiliated actors and internet-exposed PLCs

On 22 July 2026 CISA and partner agencies updated advisory AA26-097A on Iranian-affiliated actors targeting programmable logic controllers (PLCs) exposed directly to the internet across US critical infrastructure. Unlike the largely demonstrative 2023 campaign, this activity has caused confirmed operational disruption and financial loss. The update widens the scope from Rockwell Automation PLCs to Schneider Electric and Siemens, adds guidance to detect malicious changes in reusable code modules, and documents an exfiltration technique (T1041) using the vendor's own configuration software. Sectors hit: water, energy, government. The measure that matters is still taking those devices off the public internet.

The target isn't software, it's a brick

A programmable logic controller — a PLC — is the box that tells a pump when to spin, a valve when to open, a plant when to stop. It is not a server full of data: it is the piece that holds up the physical side of a water utility or a substation. On 22 July 2026 CISA and partner agencies updated advisory AA26-097A, first published on 7 April, on Iranian-affiliated actors targeting exactly these devices when they are reachable directly from the internet.

The difference with the past is the whole point of the story. A similar campaign in 2023 was largely demonstrative: change a device's screen, leave a message, little more. The agencies write that this activity, instead, has produced confirmed operational disruption and financial loss for some affected organisations. It is no longer graffiti on a panel: it is a plant grinding to a halt.

What the July update adds

The April advisory mapped techniques and indicators onto a narrow set of devices. The 22 July update widens the picture in three directions. It expands the observed targets: no longer only Rockwell Automation PLCs, but also Schneider Electric, Siemens and potentially other brands. It adds operational guidance to detect malicious changes in reusable code modules inside Rockwell PLC programs — the place where an attacker can hide hostile logic that survives a shallow check. And it documents one more exfiltration technique.

  1. 01
    PLC reachable from the internet
    the device is exposed with no network filter
  2. 02
    Default credentials
    passwords the integrator never changed
  3. 03
    Vendor configuration software
    used by the attacker to read and carry off the project files

On this last point the agencies are explicit and cite a precise MITRE ATT&CK identifier: T1041 (Exfiltration Over C2 Channel), in the form of using the vendor's configuration software, hosted on leased infrastructure, to steal the PLC project files. We report this ID because it is in the advisory. The other two entries at the head of this dossier — internet-accessible device and default credentials, in the ICS ATT&CK vocabulary — are instead our reasoned mapping of the behaviours described, not IDs copied from an official document: the distinction matters, and we state it.

Why the fake readings are the unsettling part

Some outlets that picked up the advisory report that the attackers, in cases involving Schneider and Siemens PLCs, manipulated the readings shown to operators — effectively "blinding" them with false values while the plant did something else. We treat this detail with caution: it is consistent with what the agencies describe, but its most vivid reconstruction comes from secondary sources, not from the text of the advisory we were able to read. If true, it is the kind of manipulation that makes a fault hard to diagnose in time: whoever watches the panel sees normal numbers.

2023
the previous campaign
largely demonstrative, no physical damage
2026
the current campaign
confirmed operational disruption and financial loss
3
PLC brands now named
Rockwell Automation, Schneider Electric, Siemens

Who is exposed, and what to do now

The through-line has been the same for years, and it is almost embarrassing in its simplicity: these devices should never be reachable directly from the internet. The agencies' recommendations follow from that. Take PLCs off public exposure, behind a trusted administrative network. Isolate the cellular-modem architecture, often the shortcut by which a remote plant ends up online. Change default passwords — the most trivial and most exploited way in. Validate project files before returning a device to run mode, so you do not reintroduce hostile logic. And inform service providers of the active threat, because the chain often runs through them.

A note on method, owed to the reader. Attribution here is the agencies': "Iranian-affiliated" actors, not a group with a name and a face. The exact set of victims is not public, and we do not invent it. What is verifiable — and enough to act on — is in the advisory at the top of the page: the affected devices, the techniques, and the indicator list updated in July 2026 to compare against your own logs. The rest, including the more cinematic reconstructions, should be held for what it is until a primary source confirms it. The part that needs no confirmation is the dullest and the most effective: a PLC holding up a water utility has no reason to answer anyone who happens by on the internet.

More dossiers