(TLP:CLEAR) CISA Updates Iranian-Affiliated PLC Targeting Advisory (AA26-097A)
Created: Wednesday, July 22, 2026 - 18:49
Categories: Cybersecurity, Federal & State Resources, OT-ICS Security
Summary: Today, CISA and its partner agencies updated the joint Cybersecurity Advisory (CSA) AA26-097A “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across U.S. Critical Infrastructure.” The original advisory was published on April 7, 2026, and warns of ongoing Iranian-affiliated state-sponsored targeting of internet-connected OT devices, including programmable logic controllers (PLCs). This updated advisory is being sent to members to draw awareness to the new information which may require utility action if not done already.
Most notably, utilities and integrators operating, maintaining, or providing support for PLCs from the manufacturers mentioned in this advisory are strongly recommended to remove PLCs from direct internet exposure via secure gateway and firewall. Utilities may need to work with IT/OT team members and/or integrators to perform this action.
The authoring agencies note that targeting has escalated, likely in connection with hostilities between Iran and the U.S. The advisory builds on the previously reported activity by the Iranian Revolutionary Guard Corps (IRGC)-affiliated group known as CyberAv3ngers.
Analyst Note:
What Changed in the July 22 Update
The updated advisory expands scope and adds new technical guidance. Notable additions members can review include:
- Broadened manufacturer scope. Beyond earlier reporting, the advisory now identifies observed targeting of Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens PLCs, and potentially other branded/manufactured devices with specific affected models named (e.g., Rockwell CompactLogix and Micro850, Schneider BMX P34/Modicon M340, Siemens S7-1200 series).
- New and updated TTPs and IOCs. The advisory adds a new MITRE ATT&CK® Exfiltration Technique (T1041) describing use of vendor configuration software on leased infrastructure to steal project files, update Initial Access and Command and Control details, and provides a fresh set of July 2026 IOCs for log review.
- Expanded mitigation guidance. New recommendations address strictly controlling network access to PLCs (removing them from direct internet exposure), isolating cellular modem architecture, changing default device passwords, validating project files before switching devices to run mode, and ensuring service providers are informed of active threats.
- New detection guidance for reusable code modules. The udpate adds guidance on identifying malicious changes to reusable logic, such as Add-On Instructions (AOIs) within Rockwell Automation programs, including validating project files and comparing running programs to known-good logic
Why This Matter for Utilities
Water and Wastewater Systems is specifically named among the targeted sectors, and internet-exposed PLCs remain a primary access point for this activity. A successful compromise could allow attackers to modify or delete control logic, disable critical shutdown and alarm functions, and allow systems to enter unsafe conditions without alerting operators.
Operational Considerations
Utilities and integrators responsible for PLCs may wish to review the Top 20 Secure PLC Coding Practices for relevant guidance on applying best practices. In relation to this advisory, the most relevant practices to consider are ones that involve integrity checking, input plausibility validation, and communication hardening.
WaterISAC strongly encourages members to review the full advisory, identify whether any affected or internet-exposed PLCs are present in their environments, query logs against the provided IOCs for signs of current or historical activity, and apply the mitigations in the advisory’s Mitigations section. WaterISAC also strongly suggests utilities and integrators using the named vendors’ PLCs to consult the vendor-specific hardening resources referenced in the advisory.
Additional Reading:
WaterISAC PIRs: 6-12
