Critical Infrastructure Advisory: CISA and FBI Warn Iran-Linked Cyber Actors Target Water and Energy PLCs
Executive Summary
On July 23, 2026, the Cybersecurity and Infrastructure Agency (CISA) and the Federal Bureau of Investigation (FBI) released an updated joint security advisory warning that Iran-affiliated threat actors have significantly expanded their operational target set against critical infrastructure industrial control systems (ICS). Having previously targeted Programmable Logic Controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley, Iran-linked state-sponsored hacktivists and cyber-saboteurs have now expanded campaign targeting to include operational technology (OT) devices from Schneider Electric, Siemens, and other major industrial vendors. These threat groups are actively scanning for internet-exposed PLCs deployed across municipal water treatment plants, electrical power distribution grids, and energy distribution sites to manipulate operational parameters, disrupt physical services, and execute destructive operations.
Deep-Dive Technical Analysis
Programmable Logic Controllers (PLCs) are specialized industrial computer systems that monitor inputs and automate electro-mechanical processes (e.g., controlling water pumps, chemical dosing valves, and power circuit breakers):
1. Target Expansion & Device Fingerprinting: Federal intelligence indicates that threat actors use shodan.io, Censys, and automated port-scanning tools to locate internet-exposed industrial devices operating default management ports (e.g., Modbus TCP/502, EtherNet/IP/44818, and Siemens S7comm/102). Rather than relying solely on default credentials, attackers exploit legacy firmware vulnerabilities, unauthenticated web management interfaces, and cleartext industrial protocols.
2. Operational Exploitation Techniques: Once access to a Schneider Electric or Siemens PLC is gained, threat actors utilize vendor programming suites or custom Modbus commands to overwrite ladder logic code, modify setpoints (such as raising chemical treatment levels or shutting off coolant pumps), or upload corrupt project files that force PLCs into fault states (Stop mode).
3. Improper Air-Gapping & Remote Access Misconfigurations: A major vulnerability factor identified by CISA and the FBI is the presence of poorly secured cellular modems, direct dual-homed network connections between IT and OT networks, and unencrypted Remote Desktop or VNC connections used by field engineers without multi-factor authentication.
Industry Impact and Mitigation Strategies
The expansion of Iranian cyber operations targeting critical infrastructure represents a direct threat to public health, municipal water safety, and power grid reliability:
* Eliminate Direct Internet Exposure for PLCs: Ensure all PLCs, Remote Terminal Units (RTUs), and Human-Machine Interfaces (HMIs) are completely disconnected from the public internet. Isolate OT networks behind industrial firewalls enforcing strict unidirectional data diodes or air-gaps.
* Require VPN and Multi-Factor Authentication: All remote engineering access to OT networks must pass through a secure VPN with mandatory phishing-resistant Multi-Factor Authentication (MFA).
* Change Default Credentials and Disable Unused Protocols: Enforce strong, unique passwords across all Schneider Electric, Siemens, and Rockwell PLCs, and disable insecure cleartext services (such as HTTP, Telnet, or FTP) in favor of encrypted management options.
* Audit and Validate PLC Logic Files: Regularly create out-of-band backups of PLC project logic files and compare active running logic against master baselines to detect unauthorized code changes or setpoint tampering.
References
* CISA, FBI warn that Iran-linked hackers are expanding target set for water, energy
* Large-Scale Cybersecurity Exercise Focuses on Operational Technology