Federal cybersecurity, law enforcement, and environmental regulators on Tuesday updated a joint advisory warning that Iranian-affiliated hackers continue to target internet-connected operational technology at U.S. critical infrastructure, expanding the scope of affected industrial control equipment and urging companies to tighten network access and validate the integrity of their control programs.
The new guidance builds on an April 2026 alert about intrusions against Rockwell Automation programmable logic controllers and now notes observed targeting of Schneider Electric, Siemens and possibly other PLC manufacturers. It also adds detection techniques to spot malicious changes in reusable code modules within Rockwell programs and includes additional recommended mitigations.
“CISA has consistently warned critical infrastructure stakeholders that Iranian-affiliated threat actors are conducting a range of targeted cyber activity to include compromise unsecure internet-connected accounts and devices,” said CISA Acting Executive Assistant Director for Cybersecurity Chris Butera. “CISA and our partners urge organizations to review this updated advisory and implement recommended actions to protect against this Iranian-affiliated threat activity.”
According to the agencies, the activity has disrupted PLCs across several sectors by attempting to download malicious project files and manipulate data on human-machine interface and supervisory control and data acquisition displays, causing operational disruption and financial losses. Targets have included Water and Wastewater Systems, Energy, and Government Services and Facilities, including local municipalities.
“Iranian cyber actors continue to target U.S. critical infrastructure, and the FBI is committed to identifying, disrupting, and imposing costs on those responsible,” said Assistant Director Brett Leatherman of the FBI’s Cyber Division. “Sharing timely, actionable intelligence is a critical part of that work. This advisory provides network defenders with the information they need to identify malicious activity, strengthen their defenses, and reduce opportunities for Iranian cyber actors to disrupt the essential services Americans rely on.”
“Cybersecurity threats are a serious concern for our nation’s drinking water and wastewater systems, and these threats pose a legitimate risk to the communities, businesses, hospitals, schools, and other critical sectors that rely on these lifeline services,” said EPA Assistant Administrator for Water Jess Kramer. “EPA is committed to ensuring safe water for all Americans, and strengthening cybersecurity is key. EPA encourages water systems to be vigilant, stay informed, and work to adopt cybersecurity best practices.”
The advisory urges owners and operators to restrict direct internet access to PLCs, follow manufacturers’ security guidance for OT deployments, validate PLC project files for unauthorized changes, and ensure service providers are aware of active threats to internet-connected PLC devices. The update, published by the Cybersecurity and Infrastructure Security Agency with the FBI, EPA and other federal partners, includes indicators of compromise, detection steps and mitigations, and is available on CISA’s website.





