Published · 2d agoSecurity3 min read
Iran-linked PLC advisory widens past Rockwell, adds code-module tampering checks
CISA and six partner agencies updated AA26-097A on July 22, extending the vendor scope beyond Rockwell and adding detection guidance for tampered reusable code modules.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- Advisory AA26-097A was authored by the FBI, CISA, NSA, EPA, Department of Energy, US Cyber Command - Cyber National Mission Force (CNMF), and the Department of the Treasury.
- The authoring agencies updated the advisory on July 22, 2026, to add new guidance on detecting malicious changes in reusable code modules leveraged within Rockwell Automation PLC programs.
- The July 22, 2026 update also expands the manufacturer scope to include observed targeting of Schneider Electric, Siemens, and potentially other branded/manufactured PLCs, emphasizing the importance of restricting direct internet access and providing best practice resources for secure deployment.
- The advisory was originally published on April 7, 2026, to provide tactics, techniques, and procedures and indicators of compromise related to ongoing cyber exploitation of internet-connected operational technology devices by Iranian-affiliated APT actors.
- The agencies warn of ongoing cyber exploitation of internet-connected OT devices including PLCs manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and potentially other manufactured PLCs, across multiple US critical infrastructure sectors.
Compiled by The WatchSomething wrong?How this is made
Why it matters
The seven agencies behind advisory AA26-097A revised it on July 22, 2026, adding guidance on detecting malicious changes in reusable code modules used inside Rockwell Automation PLC programs and expanding the manufacturer scope to include observed targeting of Schneider Electric, Siemens, and potentially other branded PLCs [1][2][3]. The advisory first went out on April 7, 2026 with TTPs and indicators for ongoing exploitation of internet-connected operational technology devices by Iranian-affiliated APT actors [4], which means any asset owner who built an April response plan around a single vendor's product line now has a scoping error to fix, 106 days later [13].
The authoring agencies are the FBI, CISA, NSA, EPA, the Department of Energy, US Cyber Command's Cyber National Mission Force, and the Treasury [1]. Their warning covers PLCs manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and potentially other manufactured PLCs across multiple US critical infrastructure sectors [5]. The named sectors are Government Services and Facilities, including local municipalities, Water and Wastewater Systems, and Energy [8].
The observed effects are worth reading closely, because they are not ransomware-shaped. Organizations experienced disruptions through malicious interactions with PLC project files and through manipulation of the data shown on HMI and SCADA displays [6]. In a few cases, the activity caused operational disruption and financial loss [7]. Manipulating what an operator sees on a screen is a different detection problem from encrypting a file server, and it is the reason the new guidance on reusable code modules matters more than its low-key placement in an update note suggests: a plant can pass an inventory check, a firmware check, and a network check while the logic running on the controller has been altered.
The agencies assess that a group of Iranian-affiliated APT actors is conducting this activity to cause disruptive effects within the United States [9]. They have previously reported similar PLC-targeting activity by CyberAv3ngers, also called the Shahid Kaveh Group, a threat actor affiliated with the IRGC's Cyber Electronic Command [10]. In a comparable campaign beginning in November 2023, those actors targeted US-based PLCs and HMIs and compromised at least 75 devices, focusing on Unitronics PLC devices with an integrated HMI used across sectors including water and wastewater [11]. The same group is tracked in industry reporting as Hydro Kitten, Storm-0784, APT Iran, Bauxite, Mr. Soul, Soldiers of Solomon, and UNC5691 [12].
Operationally, the July update is not a re-read of the same document. It ships a fresh IOC package as STIX XML and JSON dated July 22, kept separate from the historical April 7 indicators [14], so hunts that ran once in April against the original set need to run again against the new one. The advisory asks organizations to urgently review the TTPs and IOCs for indications of current or historical activity and to apply the mitigations [15], and it emphasizes restricting direct internet access to these devices [3]. If an affected internet-accessible device turns up, the agencies say additional technical measures may be needed to evaluate compromise risk, and they direct owners to engage incident response plans and contact both the agencies and the applicable vendors through existing support channels [16].
What to watch: whether the scope widens a third time, given that the agencies already allow for "potentially other" brands [5]; whether Schneider Electric and Siemens publish matching customer guidance for their own product families; and whether the reusable-code-module detection advice gets extended beyond Rockwell programs, since the technique is not vendor-specific in principle [3].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Advisory AA26-097A was authored by the FBI, CISA, NSA, EPA, Department of Energy, US Cyber Command - Cyber National Mission Force (CNMF), and the Department of the Treasury.
ReportedView cited source - [2]
The authoring agencies updated the advisory on July 22, 2026, to add new guidance on detecting malicious changes in reusable code modules leveraged within Rockwell Automation PLC programs.
ReportedView cited source - [3]
The July 22, 2026 update also expands the manufacturer scope to include observed targeting of Schneider Electric, Siemens, and potentially other branded/manufactured PLCs, emphasizing the importance of restricting direct internet access and providing best practice resources for secure deployment.
ReportedView cited source - [4]
The advisory was originally published on April 7, 2026, to provide tactics, techniques, and procedures and indicators of compromise related to ongoing cyber exploitation of internet-connected operational technology devices by Iranian-affiliated APT actors.
ReportedView cited source - [5]
The agencies warn of ongoing cyber exploitation of internet-connected OT devices including PLCs manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and potentially other manufactured PLCs, across multiple US critical infrastructure sectors.
ReportedView cited source - [6]
Organizations from multiple US critical infrastructure sectors experienced disruptions through malicious interactions with PLC project files and the manipulation of data displayed on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays.
ReportedView cited source
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.



