Published by Emerging Technologies Laboratory · via ETL Newswire
Security· 

CISA Expands Iranian PLC Advisory to Cover Schneider Electric and Siemens Devices

A July 22 update to a joint federal advisory adds new target hardware, detection guidance for tampered code modules, and confirms operational disruptions across water, energy, and government sectors.

By Renée Kovac, Correspondent · Security Desk

Federal agencies updated a joint cybersecurity advisory yesterday to warn that Iranian-affiliated threat actors have broadened their campaign against industrial control systems, reaching hardware from Schneider Electric and Siemens in addition to the Rockwell Automation/Allen-Bradley programmable logic controllers named in the original April 7 filing.

The updated advisory, published July 22 and reviewed directly from the CISA advisory page, is a product of CISA, the FBI, NSA, EPA, DOE, U.S. Cyber Command's Cyber National Mission Force, and the Department of the Treasury. <cite index="19-2">That interagency roster signals this isn't a routine product-specific patch notice.</cite>

<cite index="15-4">The Iranian-affiliated activity has disrupted PLCs across several U.S. critical infrastructure sectors by attempting to download malicious project files and manipulate data on human machine interface and SCADA displays, resulting in operational disruption and financial loss for affected organizations.</cite> <cite index="15-5">Confirmed sectors include Water and Wastewater Systems, Energy, and Government Services and Facilities, including local municipalities.</cite>

The July revision adds two meaningful analytic updates. <cite index="14-4,14-5">Agencies added new guidance on detecting malicious changes in reusable code modules within Rockwell Automation PLC programs, and expanded the manufacturer scope to include observed targeting of Schneider Electric, Siemens, and potentially other branded PLCs.</cite> That expansion of scope is worth taking seriously: it shifts the threat from a single-vendor problem to a broader OT hardware posture problem.

<cite index="14-1">Since at least March 2026, agencies identified, through engagements with victim organizations, an Iranian-affiliated APT group that has disrupted the function of PLCs.</cite> The advisory ties current activity to a pattern: <cite index="18-5">during a similar campaign beginning in November 2023, IRGC CEC-affiliated cyber threat actors known as CyberAv3ngers targeted U.S.-based PLCs and HMIs, causing disruptive effects.</cite> <cite index="18-6,18-7">Private industry and open sources also track this group as Hydro Kitten, Storm-0784, APT Iran, Bauxite, and the Shahid Kaveh Group, among other aliases.</cite>

The root access vector hasn't changed from the April version. <cite index="13-5">The advisory warns specifically of insecure remote access pathways, credential compromise, and limited visibility into legacy or hybrid environments.</cite> <cite index="6-4">Legacy industrial control systems, built for reliability rather than security, remain hard to patch, poorly segmented, and difficult to monitor.</cite> That structural condition is what makes advisories like this one repeat with similar findings across years.

One context point that the CISA press release doesn't surface: <cite index="16-2">under the current administration, the United States has experienced cuts to key agencies including CISA and ODNI, funding losses for information-sharing centers and state and local authorities, and an anticipated scaling down of federal cybersecurity funding, with CISA expected to lose another $707 million in cuts.</cite> Issuing an expanded advisory against an active Iranian OT campaign while the agency absorbing that campaign is itself under budget pressure is a structural tension the advisory does not acknowledge.

For operators, the recommended mitigations are specific. <cite index="17-4,17-5,17-6">The advisory directs removing PLCs from direct internet exposure via secure gateway and firewall, querying available logs for the provided indicators of compromise, and checking logs for suspicious traffic on ports associated with OT devices, including 44818, 2222, 102, and 502, especially traffic originating from overseas hosting providers.</cite>

Attribution confidence in the advisory is moderate. The agencies use the phrase "Iranian-affiliated" throughout rather than asserting direct IRGC command authority, which is an accurate hedge given how Iranian cyber operations have historically blended state direction with contractor and proxy execution. Calling it definitively IRGC-directed would require more than this advisory provides publicly.

Sources cited:
- CISA Joint Advisory AA26-097A (July 22, 2026) (https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a)
- CISA Press Release, July 22, 2026 (https://www.cisa.gov/news-events/news/cisa-fbi-epa-and-us-government-partners-update-warning-iran-affiliated-threat-actors-targeting)
- CSIS, The Iranian Cyber Threat to U.S. Critical Infrastructure (https://www.csis.org/analysis/iranian-cyber-threat-us-critical-infrastructure)
- SC Media, Critical Infrastructure Facing Cyber Surge in OT and Supply Chains in 2026 (https://www.scworld.com/feature/critical-infrastructure-facing-cyber-surge-in-ot-and-supply-chains-in-2026)
- Manufacturing Business Technology, CISA Updates Advisory on Iranian Cyber Actors Exploiting PLCs (https://www.mbtmag.com/cybersecurity/news/22971106/cisa-updates-advisory-on-iranian-cyber-actors-exploiting-plcs)

Reporting by Renée Kovac, Correspondent, for the Security desk · ETL Newswire staff
Read more at the source

This release was originally distributed via ETL Newswire. Visit CISA Joint Advisory AA26-097A (July 22, 2026) for the full story, related releases, and contact information.

Visit CISA Joint Advisory AA26-097A (July 22, 2026) →