
ON 23 July 2026 US authorities issued an updated warning that Iranian-linked hackers are actively attacking programmable logic controllers that manage essential services across the country according to a recent report.
The joint advisory notes that no new common vulnerabilities have been assigned to these intrusions but attackers are altering the ladder logic inside the controllers to change safe operating parameters. Rockwell Automation, Schneider Electric and Siemens devices have been specifically named as targets in the latest update as noted by SecurityWeek.
Investigators say the actors first scan for PLCs that are reachable directly from the internet, then use default or weak credentials to gain a foothold. Once inside they upload modified code that can start or stop processes, alter sensor readings or trigger false alarms.
The activity was first detected in early April 2026 and the July update shows the campaign is still ongoing, with the threat actor tracked as Cyber Av3ngers. Victims include water treatment facilities, power distribution sites and manufacturing plants, where the altered logic has caused operational hiccups and safety concerns.
The incident highlights how internet‑exposed operational technology remains an attractive target for state‑sponsored groups seeking to create physical effects. While no physical damage has been reported so far, the ability to manipulate core control logic demonstrates a clear path to sabotage if defenders do not act.
Network engineers should immediately block any direct internet path to PLCs, placing the devices behind segregated firewalls or virtual LANs. Strong, unique passwords must replace default credentials and multi‑factor authentication should be added wherever remote access is required. Continuous monitoring of controller logs for unexpected program uploads or logic changes is essential to spot the intrusion early.
Defenders are encouraged to consult the joint advisory published by the IC3 for detailed detection rules and mitigation guidance. Vendor hardening guides for Rockwell, Schneider and Siemens should be applied, and integrity checks on firmware and project files performed regularly. Sharing indicators of compromise with sector‑specific ISACs helps build a collective defence against future waves of this type of targeting.