Key Takeaways
- CISA, FBI, EPA and other U.S. agencies updated the April advisory on Iranian‑affiliated cyber activity targeting programmable logic controllers (PLCs).
- The revision adds guidance on detecting and mitigating malicious changes in reusable code modules used in Rockwell Automation/Allen‑Bradley, Schneider Electric, Siemens and other PLCs.
- Iranian threat actors have compromised internet‑connected PLCs across water, wastewater, energy and government sectors, causing operational disruption and financial loss.
- Recommended mitigations include restricting direct internet access to PLCs, following manufacturer guidance, securing gateways, implementing isolated architectures, changing default passwords, monitoring project files and informing service providers of active threats.
- Agencies stress vigilance, timely intelligence sharing and adoption of cybersecurity best practices to protect critical infrastructure and essential services.
Advisory Update Overview
On Wednesday, the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the Environmental Protection Agency (EPA) and additional government partners released an updated joint advisory concerning Iranian‑affiliated cyber threats to operational technology. The original advisory, published in April, warned of Iranian actors exploiting internet‑connected programmable logic controllers (PLCs). The revised document expands the scope to include specific detection and mitigation techniques for malicious alterations in reusable code modules that reside within PLC programs from multiple vendors, notably Rockwell Automation/Allen‑Bradley, Schneider Electric and Siemens.
CISA Leadership Commentary
CISA Acting Executive Assistant Director for Cybersecurity Chris Butera emphasized the persistent nature of the threat, stating, “CISA has consistently warned critical infrastructure stakeholders that Iranian‑affiliated threat actors are conducting a range of targeted cyber activity to include compromise unsecure internet‑connected accounts and devices.” He urged organizations to review the updated advisory and implement the recommended actions to defend against this Iranian‑affiliated threat activity, reinforcing the agency’s commitment to safeguarding the nation’s critical systems.
Threat Actor Techniques and Impact
The advisory details how Iranian cyber actors have disrupted PLCs across numerous U.S. critical infrastructure sectors, including water and wastewater treatment, energy generation and distribution, and government facilities. Their newly identified tactics involve downloading malicious project files, manipulating data displayed on human‑machine interfaces (HMIs) and supervisory control and data acquisition (SCADA) screens, and exfiltrating files through remote, third‑party command‑and‑control channels—all while bypassing existing security alarms. These intrusions have led to tangible operational disruptions and financial losses for the affected organizations.
EPA Perspective on Water Sector Risks
EPA Assistant Administrator for Water Jess Kramer highlighted the particular danger to drinking water and wastewater systems, noting, “Cybersecurity threats are a serious concern for our nation’s drinking water and wastewater systems, and these threats pose a legitimate risk to the communities, businesses, hospitals, schools and other critical sectors that rely on these lifeline services.” Kramer affirmed the EPA’s commitment to ensuring safe water for all Americans and urged water utilities to remain vigilant, stay informed about emerging threats, and adopt cybersecurity best practices to protect essential services.
Updated Mitigation Recommendations
To reduce the risk of successful attacks, the agencies refreshed their mitigation list. Organizations are advised to: follow previously issued guidance from PLC manufacturers; strictly control network access to PLC devices; remove PLCs from direct internet exposure by placing them behind secure gateways and firewalls; consider implementing isolated network architectures; change default passwords on all PLCs and related equipment; continuously monitor project files for unauthorized or anomalous changes; and promptly inform service providers and trusted partners of any active threats observed against internet‑connected PLC devices.
FBI Commitment to Disruption
Assistant Director Brett Leatherman of the FBI’s Cyber Division reiterated the bureau’s resolve, saying, “Iranian cyber actors continue to target U.S. critical infrastructure, and the FBI is committed to identifying, disrupting and imposing costs on those responsible.” He stressed that sharing timely, actionable intelligence is a core component of that effort, and that the updated advisory equips network defenders with the knowledge needed to detect malicious activity, strengthen defenses, and limit opportunities for Iranian actors to disrupt essential services relied upon by the American public.
Conclusion and Call to Action
The updated joint advisory serves as a critical resource for owners and operators of operational technology, particularly those managing PLC‑based systems in water, wastewater, energy and government facilities. By heeding the guidance—limiting internet exposure, enforcing strict access controls, monitoring for code tampering, and collaborating with vendors and federal partners—organizations can significantly reduce their vulnerability to Iranian‑affiliated cyber campaigns. Continued vigilance, proactive information sharing, and adherence to cybersecurity best practices remain essential to preserving the reliability and safety of the nation’s critical infrastructure.

