OFICIAL CISA News

CISA, FBI, EPA and U.S. Government Partners Update Warning of Iran-Affiliated Threat Actors Targeting Critical Infrastructure Programmable Logic Controllers

What happened
Based on CISA News · Jul 22, 2026

U.S. agencies updated a joint advisory warning of Iranian-affiliated cyber actors targeting industrial control systems, including Rockwell Automation, Schneider Electric, and Siemens PLCs, across critical infrastructure sectors.

CISA, FBI, EPA and U.S. Government Partners Update Warning of Iran-Affiliated Threat Actors Targeting Critical Infrastructure Programmable Logic Controllers
CISA News — CISA
Key points
·
WASHINGTON - The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Environmental Protection Agency (EPA) and other U.S.
·
CISA government partners published an update today to a joint Cybersecurity Advisory, originally published in April 2026, Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers (PLC) Across US Critical Infrastructure.
·
The update provides new guidance to detect malicious changes in reusable code modules used within Rockwell Automation PLC programs and adds more recommended mitigations.
·
It also broadens the manufacturer scope to include observed targeting of Schneider Electric, Siemens and possible other PLC manufacturers.

The Cybersecurity and Infrastructure Security Agency (CISA), FBI, EPA, and partners issued an updated advisory on Iranian-affiliated cyber threats targeting internet-connected programmable logic controllers (PLCs) in U.S. critical infrastructure. The update expands manufacturer scope to include Schneider Electric and Siemens, alongside Rockwell Automation, and provides new detection guidance for malicious code changes in PLC programs. Organizations are urged to restrict direct internet access to PLCs and implement recommended mitigations to reduce exposure to these threats.

The FBI emphasized its commitment to disrupting Iranian cyber activity, stating that timely intelligence sharing is essential for defenders to identify malicious activity and strengthen defenses. The advisory highlights the group’s attempts to manipulate human-machine interfaces and SCADA systems, which have disrupted operations and caused financial losses in sectors such as water, energy, and government facilities. The FBI’s Assistant Director Brett Leatherman underscored the importance of the advisory in providing actionable intelligence to protect critical services.

The EPA warned that cyber threats pose serious risks to drinking water and wastewater systems, which support communities, businesses, and essential services. Assistant Administrator Jess Kramer stressed the need for vigilance and adoption of cybersecurity best practices to safeguard these systems. The advisory targets multiple U.S. critical infrastructure sectors, including local municipalities, underscoring the broad scope of the threat and the urgency for enhanced security measures.

CISA Acting Executive Assistant Director Chris Butera reiterated the agency’s ongoing warnings about Iranian-affiliated threat actors exploiting unsecured internet-connected devices. The updated advisory includes additional mitigations and expands manufacturer targeting to emphasize the need for secure PLC deployment. CISA continues to collaborate with government and industry partners to provide actionable guidance, aiming to reduce risks to digital and physical infrastructure relied upon by Americans daily.

Original source → Deals on Clipraptor.com →