Key Takeaways
- CISA, FBI, and EPA have refreshed a joint advisory warning that Iran‑linked cyber actors are exploiting programmable logic controllers (PLCs) in U.S. critical infrastructure.
- The update adds new indicators of compromise, expands the advisory’s scope beyond Rockwell Automation to include Schneider Electric, Siemens, and other PLC makers, and stresses the need to limit direct internet access to OT devices.
- Affected sectors include water and wastewater, energy, local municipalities, and other government services, where threat actors have disrupted operations and caused financial losses.
- Recommended mitigations: consult vendor guidance, tightly restrict PLC network access, verify project files for unauthorized changes, and keep service providers informed of active threats.
- Federal officials emphasized the ongoing Iranian threat, urged organizations to adopt the advisory’s guidance, and highlighted cybersecurity’s vital role in protecting drinking‑water and wastewater systems.
- Beyond the PLC advisory, CISA has released guidance on coordinated vulnerability disclosure, shared lessons from an internal AWS GovCloud key leak, formed the Alliance of National Councils for Homeland Operational Resilience‑Critical Infrastructure, and issued alerts on Russian phishing campaigns.
- The 2026 Homeland Security Summit (Nov. 12) will convene government and industry leaders to discuss AI, cyber defense, border security, and operational capabilities, offering a platform to address these evolving threats.
Overview of the Updated Advisory
The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Environmental Protection Agency (EPA) issued an update to their joint cybersecurity advisory on April 2024, now revised to reflect ongoing Iranian cyber activity targeting programmable logic controllers (PLCs). The advisory warns that threat actors linked to Iran are compromising internet‑connected OT devices, manipulating reusable code modules, and attempting to alter data displayed on human‑machine interfaces (HMIs) and supervisory control and data acquisition (SCADA) systems. By providing fresh indicators of compromise and detection guidance, the update aims to help defenders spot malicious PLC code changes before they cause operational harm. CISA stresses that the advisory is a living document, intended to evolve alongside the tactics observed in the wild.
Expanded Scope of Manufacturers
While the original advisory focused primarily on Rockwell Automation PLCs, the revised version broadens its reach to cover additional vendors. CISA explicitly notes that Schneider Electric, Siemens, and other PLC manufacturers have also been observed as targets of the Iran‑affiliated campaign. This expansion underscores a systemic vulnerability: many OT environments rely on a heterogeneous mix of hardware, and attackers are not limiting themselves to a single brand. Consequently, organizations using any of these platforms must review their specific vendor hardening guides and apply the mitigations outlined in the advisory. The wider scope also reinforces the message that securing OT is not a vendor‑specific problem but a sector‑wide imperative.
Impact on Critical Infrastructure Sectors
According to the advisory, the Iranian cyber actors have successfully disrupted PLCs across several U.S. critical infrastructure sectors, leading to measurable operational interruptions and financial losses for affected entities. The reported intrusions have targeted water and wastewater treatment facilities, energy generation and distribution assets, local municipal networks, and various government services and facilities. In many cases, threat actors attempted to download malicious project files onto PLCs and alter data presented on HMIs and SCADA displays, which could cause incorrect process readings, unauthorized valve movements, or shutdowns. The advisory highlights that even brief disruptions in these sectors can cascade, threatening public safety, economic stability, and essential services relied upon by hospitals, schools, and businesses.
New Mitigation Recommendations
To counter the observed tactics, the updated advisory prescribes a set of additional mitigation steps beyond standard OT hygiene. Organizations are urged to: (1) consult the hardening guidance published by their PLC manufacturers to ensure deployments align with vendor best practices; (2) tightly restrict network access to PLC devices, ideally isolating them from the public internet and employing strict segmentation; (3) routinely examine project files stored on PLCs for any unauthorized modifications, using integrity‑checking tools or version‑control comparison; and (4) keep third‑party service providers informed of active threats targeting internet‑connected PLCs so they can apply patches or adjust monitoring rules. These actions collectively reduce the attack surface, improve visibility into anomalous code changes, and enable faster response when malicious activity is detected.
Statement from CISA Acting Executive Assistant Director Chris Butera
Chris Butera, CISA’s acting executive assistant director for cybersecurity, reiterated that the agency has repeatedly warned critical‑infrastructure stakeholders about Iranian actors exploiting poorly secured, internet‑connected accounts and devices. He called on organizations to read the updated advisory, implement the recommended actions, and treat PLC security as an ongoing priority rather than a one‑time fix. Butera emphasized that the advisory’s new detection guidance and indicators of compromise are designed to empower network defenders to spot early signs of compromise, thereby preventing escalation to disruptive or destructive outcomes.
Statement from FBI Assistant Director Brett Leatherman
Brett Leatherman, assistant director of the FBI’s cyber division, noted that Iranian cyber actors remain persistently focused on U.S. critical infrastructure and that the bureau continues to work aggressively to identify and disrupt their operations. He described the advisory as a practical toolkit for defenders, providing the information needed to recognize malicious activity, strengthen defenses, and diminish opportunities for adversaries to interrupt essential services. Leatherman highlighted the collaborative nature of the effort, stressing that timely sharing of indicators and mitigation steps between government and industry is vital to staying ahead of evolving threats.
Statement from EPA Assistant Administrator Jess Kramer
Jess Kramer, EPA assistant administrator for water, warned that cyberthreats pose a significant risk to the nation’s drinking‑water and wastewater systems, given the extensive reliance of communities, businesses, hospitals, and schools on these services. She urged water‑system operators to remain vigilant, stay current on emerging threat intelligence, and embed cybersecurity best practices into routine operations. Kramer pointed out that many water utilities operate legacy OT equipment that may lack modern security controls, making adherence to the advisory’s mitigations especially critical for protecting public health and environmental safety.
Other Recent CISA Initiatives
Beyond the PLC advisory update, CISA has pursued several complementary initiatives to fortify critical‑infrastructure security and bolster government‑industry cooperation. The agency, together with four international cybersecurity partners, released guidance to help software manufacturers and online service providers establish coordinated vulnerability disclosure programs that facilitate constructive engagement with security researchers. CISA also shared lessons learned from a May incident in which internal AWS GovCloud keys and other data were inadvertently exposed to a public repository, using the case to improve internal safeguards and incident‑response procedures. Additionally, CISA launched the Alliance of National Councils for Homeland Operational Resilience‑Critical Infrastructure to expand information sharing and strengthen collaboration across sectors. In May, CISA and the FBI jointly issued an alert about a Russian phishing campaign targeting users of a commercial messaging application, further demonstrating the agency’s broad focus on emerging cyber threats.
Conclusion and Forward Look
The updated Iran‑linked PLC advisory serves as a timely reminder that operational technology remains an attractive target for state‑sponsored actors seeking to undermine essential services. By expanding the manufacturer scope, delivering fresh indicators of compromise, and prescribing concrete mitigations, CISA, FBI, and EPA aim to equip defenders with the tools needed to detect, prevent, and respond to these threats. Complementary CISA efforts—ranging from vulnerability‑disclosure guidance to cross‑sector alliances—underscore a holistic strategy that blends technical guidance, information sharing, and partnership building. As the 2026 Homeland Security Summit approaches on November 12, stakeholders will have an opportunity to discuss how emerging technologies such as AI can further enhance cyber defense, border security, and overall operational resilience, ensuring that the nation’s critical infrastructure remains robust against evolving adversarial tactics.

