CISA updated advisory AA26-097a on July 22, confirming that Iranian-affiliated cyber actors have expanded their campaign against internet-exposed industrial control systems beyond Rockwell Automation targets to include PLCs manufactured by Schneider Electric and Siemens. The advisory, originally published April 7, 2026, now reflects CISA and FBI’s assessment that actors are actively targeting devices across multiple manufacturers as part of a persistent effort directed at US water, energy, and government infrastructure. FBI assesses the actors’ stated intent as causing disruptive effects within the United States.
Context
The original April advisory documented exploitation of Rockwell Allen-Bradley CompactLogix and Micro850 PLCs accessible directly from the internet. Attackers used legitimate engineering software — Studio 5000 Logix Designer — to read and modify PLC ladder logic and HMI display data. The campaign was attributed to Iranian-affiliated actors consistent with previous Cyber Avengers (CyberAv3ngers) activity, assessed as linked to the Islamic Revolutionary Guard Corps (IRGC).
The July 22 update expands the advisory’s scope materially. Schneider Electric PLCs (including Modicon series) and Siemens PLCs (S7 series and related SIMATIC HMIs) are now confirmed targets. The expansion indicates the campaign has broadened from a targeted set of exposed Rockwell devices to a wider opportunistic exploitation effort against any internet-exposed industrial control system with weak or default credentials. The use of legitimate vendor engineering tools in each case means PLC write operations may not generate obvious anomalies in environments without established OT behavioural baselines.
Sector Exposure
Water and wastewater operators face the highest immediate exposure. Many utilities maintain internet-facing SCADA or HMI systems for remote operational monitoring, often with default or unchanged vendor credentials. Prior incidents in this campaign — including documented manipulation of chlorination controls — establish the actors’ willingness to affect physical processes.
Energy operators using Schneider Electric equipment in generation, transmission, and distribution operations should treat the July 22 update as a direct targeting signal. Schneider Modicon PLCs are widely deployed in substation automation and renewable generation control.
Manufacturing and industrial facilities running Siemens S7 PLCs across production lines are now within scope. The breadth of Siemens deployment across sectors — petrochemical, pharmaceutical, food and beverage — means the campaign’s potential reach is substantially wider than the original advisory indicated.
UK operators should note that while this advisory is US-authored, the advisory references globally deployed hardware, and NCSC has previously highlighted Iranian threat actor targeting of UK CNI. UK water and energy operators using any of the named manufacturers should review this advisory and apply the recommended mitigations.
Recommended Actions
Remove all PLCs, HMIs, and engineering workstations from direct internet exposure. There is no operational justification for placing PLCs on the public internet. Remote access should route through a VPN, jump server, or industrial DMZ with enforced authentication at every boundary.
Audit credentials on all named devices. Default vendor usernames and passwords must be changed. Credential inventories for OT devices are frequently incomplete — treat this as a mandatory audit exercise rather than an assumption check.
Enable authentication on all engineering software access to PLC programming ports. Studio 5000 and Siemens TIA Portal configurations permitting unauthenticated connections to PLCs on the OT network should be reconfigured.
Review PLC ladder logic and HMI displays for unauthorised modifications. The actors have demonstrated willingness to modify control logic and display values. A point-in-time backup comparison against a known-good baseline will identify tampering.
Report any indicators of compromise to CISA at report.cisa.gov. The advisory includes known indicators and recommends organisations with evidence of intrusion contact CISA directly for incident response support.