Iranian-Linked Hackers Expand PLC Targeting to Siemens and Schneider Electric Devices
A July update to CISA advisory AA26-097A widens the scope of a confirmed IRGC-affiliated campaign against U.S. water, energy, and municipal systems, as NBC News reports the same actors have hit telecom and energy networks in recent weeks.
IRGC-affiliated cyber actors tracked under the CyberAv3ngers persona have broadened their targeting of internet-exposed programmable logic controllers beyond Rockwell Automation hardware to include Schneider Electric and Siemens devices, according to a joint advisory updated July 22 by the FBI, CISA, NSA, EPA, Department of Energy, and U.S. Cyber Command's Cyber National Mission Force.
The original advisory, AA26-097A, first published April 7, covered active exploitation of Rockwell Automation Allen-Bradley PLCs across U.S. water, energy, and government facilities. The July update, reviewed by ETL Newswire directly on CISA's advisory page, adds new guidance for detecting malicious changes in reusable code modules within Rockwell PLC programs and, critically, flags observed targeting of Schneider Electric BMX P34/Modicon M340 devices and Siemens S7-1200 series hardware. Port-scanning activity, per the advisory, suggests the group's interest in OT vendors is opportunistic and not bounded by those three manufacturers.
The operational technique warrants careful description. According to the CISA advisory, at one confirmed U.S. victim the actors downloaded a malicious project file to a targeted PLC using standard configuration software. Analysis showed the file retained legitimate ladder logic for downstream functions but added logic that overrode specific instruction sets responsible for maintaining safe operating parameters. In at least one instance, per CPO Magazine's review of the advisory, attackers disabled critical alarms so that the PLC could fail without alerting operators.
That's not a generic intrusion. Disabling safety logic inside a PLC is a step toward physical consequence, even if the threshold for actual harm hasn't been crossed in any confirmed case. Attribution confidence here is moderate-to-high: the advisory ties the group formally to Iran's Islamic Revolutionary Guard Corps Cyber Electronic Command (IRGC-CEC), and the July update did not walk back that attribution, though IOActive's analysis of the update correctly flags that the new content refers to "an Iranian-affiliated APT group" without reasserting the CyberAv3ngers name directly. CISOs should treat that as a drafting precision question, not a material attribution change.
Also worth noting: the Department of the Treasury joined as a co-authoring agency on the July update. That addition has not been widely flagged. Treasury's inclusion is consistent with financial-sector exposure to the same OT device classes, and it complicates the framing of this as a water-and-energy-only problem.
Separately, NBC News reported September 2 that Iranian hackers have in recent weeks targeted not only U.S. water systems but also telecommunications, energy, and other infrastructure, citing four people with access to government and industry threat information. NBC reported the attempts have so far been unsuccessful but that an Iranian hacking group warned that "unexpected and critical events" would soon target American infrastructure. ETL Newswire has not independently confirmed the specific sectors cited in the NBC account; treat that claim as low-to-moderate confidence pending corroborating sourcing.
Context matters here. Per analysis published by Dataminr, the escalating campaign tracks against the broader cyber component of U.S.-Iran tensions that sharpened in early 2026. The authoring agencies in AA26-097A assess the activity is consistent with anticipated retaliatory cyber operations tied to those heightened tensions.
For defenders, CISA's recommendation is direct: review the advisory's TTPs and indicators of compromise for signs of current or historical activity, and treat any internet-exposed PLC as a candidate for immediate network segmentation review. The sectors at highest exposure remain water and wastewater systems, energy, and municipal government facilities. The expansion to Schneider and Siemens hardware widens the addressable attack surface considerably, given those manufacturers' prevalence across industrial environments far beyond water utilities.
Sources cited:
- CISA Advisory AA26-097A (updated July 22, 2026) (https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a)
- NBC News, September 2, 2026 (https://www.nbcnews.com/politics/national-security/iran-attempted-cyberattacks-range-us-infrastructure-sources-say-rcna595424)
- IOActive analysis of AA26-097A, July 27, 2026 (https://www.ioactive.com/iranian-affiliated-actors-expand-plc-targeting-to-siemens-and-schneider-electric-what-cisas-updated-advisory-means-for-cni/)
- CPO Magazine, August 3, 2026 (https://www.cpomagazine.com/cyber-security/feds-warn-about-iranian-hackers-expanding-the-list-of-targeted-plcs-to-compromise-critical-infrastructure/)
- Dataminr analysis, July 29, 2026 (https://www.dataminr.com/resources/blog/implications-of-recent-cisa-disclosures-on-iranian-ot-targeting/)
This release was originally distributed via ETL Newswire. Visit CISA Advisory AA26-097A (updated July 22, 2026) for the full story, related releases, and contact information.
Visit CISA Advisory AA26-097A (updated July 22, 2026) →