Skip to content

Security12 publishers3 min readPublished

Five agencies call Siemens S7 PLCs an active target, then tell every PLC owner it applies to them

NSA, CISA, FBI, DOE and EPA describe AI-generated exploit scripts disguised as monitoring tools, and say the Siemens-specific guidance is one subset of a broader PLC problem.

The Watch · Security desk

What happened

  • Advisory AA26-097A was authored by the FBI, CISA, NSA, EPA, Department of Energy, US Cyber Command - Cyber National Mission Force (CNMF), and the Department of the Treasury.
  • The authoring agencies updated the advisory on July 22, 2026, to add new guidance on detecting malicious changes in reusable code modules leveraged within Rockwell Automation PLC programs.
  • The July 22, 2026 update also expands the manufacturer scope to include observed targeting of Schneider Electric, Siemens, and potentially other branded/manufactured PLCs, emphasizing the importance of restricting direct internet access and providing best practice resources for secure deployment.
  • The advisory was originally published on April 7, 2026, to provide tactics, techniques, and procedures and indicators of compromise related to ongoing cyber exploitation of internet-connected operational technology devices by Iranian-affiliated APT actors.
  • The agencies warn of ongoing cyber exploitation of internet-connected OT devices including PLCs manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and potentially other manufactured PLCs, across multiple US critical infrastructure sectors.

Compiled by The WatchSomething wrong?How this is made

Why it matters

The seven agencies behind advisory AA26-097A revised it on July 22, 2026, adding guidance on detecting malicious changes in reusable code modules used inside Rockwell Automation PLC programs and expanding the manufacturer scope to include observed targeting of Schneider Electric, Siemens, and potentially other branded PLCs [1][2][3]. The advisory first went out on April 7, 2026 with TTPs and indicators for ongoing exploitation of internet-connected operational technology devices by Iranian-affiliated APT actors [4], which means any asset owner who built an April response plan around a single vendor's product line now has a scoping error to fix, 106 days later [13].

The authoring agencies are the FBI, CISA, NSA, EPA, the Department of Energy, US Cyber Command's Cyber National Mission Force, and the Treasury [1]. Their warning covers PLCs manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and potentially other manufactured PLCs across multiple US critical infrastructure sectors [5]. The named sectors are Government Services and Facilities, including local municipalities, Water and Wastewater Systems, and Energy [8].

The observed effects are worth reading closely, because they are not ransomware-shaped. Organizations experienced disruptions through malicious interactions with PLC project files and through manipulation of the data shown on HMI and SCADA displays [6]. In a few cases, the activity caused operational disruption and financial loss [7]. Manipulating what an operator sees on a screen is a different detection problem from encrypting a file server, and it is the reason the new guidance on reusable code modules matters more than its low-key placement in an update note suggests: a plant can pass an inventory check, a firmware check, and a network check while the logic running on the controller has been altered.

The agencies assess that a group of Iranian-affiliated APT actors is conducting this activity to cause disruptive effects within the United States [9]. They have previously reported similar PLC-targeting activity by CyberAv3ngers, also called the Shahid Kaveh Group, a threat actor affiliated with the IRGC's Cyber Electronic Command [10]. In a comparable campaign beginning in November 2023, those actors targeted US-based PLCs and HMIs and compromised at least 75 devices, focusing on Unitronics PLC devices with an integrated HMI used across sectors including water and wastewater [11]. The same group is tracked in industry reporting as Hydro Kitten, Storm-0784, APT Iran, Bauxite, Mr. Soul, Soldiers of Solomon, and UNC5691 [12].

Operationally, the July update is not a re-read of the same document. It ships a fresh IOC package as STIX XML and JSON dated July 22, kept separate from the historical April 7 indicators [14], so hunts that ran once in April against the original set need to run again against the new one. The advisory asks organizations to urgently review the TTPs and IOCs for indications of current or historical activity and to apply the mitigations [15], and it emphasizes restricting direct internet access to these devices [3]. If an affected internet-accessible device turns up, the agencies say additional technical measures may be needed to evaluate compromise risk, and they direct owners to engage incident response plans and contact both the agencies and the applicable vendors through existing support channels [16].

What to watch: whether the scope widens a third time, given that the agencies already allow for "potentially other" brands [5]; whether Schneider Electric and Siemens publish matching customer guidance for their own product families; and whether the reusable-code-module detection advice gets extended beyond Rockwell programs, since the technique is not vendor-specific in principle [3].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories