On July 22, 2026, a joint advisory from the FBI, CISA, NSA, EPA, DOE, U.S. Cyber Command (CNMF), and the Department of the Treasury expanded a prior April 2026 warning to explicitly include Siemens S7-1200 and Schneider Electric Modicon M340 PLCs alongside previously identified Rockwell Automation CompactLogix and Micro850 systems. Iranian-affiliated APT actors are actively targeting internet-exposed programmable logic controllers (PLCs) in U.S. critical infrastructure, with observed attacks in the Government Services, Water and Wastewater Systems, and Energy sectors causing operational disruptions and financial losses.

The TTPs are particularly insidious: attackers are leveraging legitimate vendor engineering tools — Rockwell Studio 5000 Logix Designer, Schneider EcoStruxure Control Expert, and Siemens TIA Portal — to download malicious project files to targeted PLCs. This causes attacker activity to blend with normal engineering traffic, making detection substantially harder. Once malicious project files are executed, attackers override safe operating parameters, manipulate HMI and SCADA displays, and disable critical shutdown and alarm logic. The advisory provides updated detection guidance for identifying malicious changes in reusable code modules within Rockwell PLC programs.

The advisory strongly recommends: restricting direct internet access to PLCs, implementing isolated OT architectures, validating all project files before deployment, securing cellular modems used for remote access, and auditing for unauthorized modifications to PLC logic going back to at least January 2026.

Sources

Commentary

This advisory marks a significant escalation in the publicly acknowledged scope of Iranian OT targeting. Expanding from Rockwell to include Siemens and Schneider — which together account for the majority of PLC deployments in global industrial infrastructure — means the attack surface is essentially the entire OT space. The technique of using legitimate engineering software to push malicious project files is a maturation of the campaign: it bypasses most signature-based detection and requires defenders to build behavioral analytics around engineering workflow patterns they may never have instrumented before.

For defenders in water, energy, and government facilities, the immediate priority is air-gapping or strictly firewalling any PLC that currently has internet exposure. The advisory’s recommendation to validate project files is sound but operationally challenging — few OT environments have robust file integrity monitoring on PLC project stores. This is the moment to build it. The attacker’s goal isn’t espionage here; it’s disruption, which means the risk isn’t just data loss — it’s physical safety incidents and infrastructure failure.

By Allan