1. Executive summary
On 22 July 2026, CISA, FBI, EPA and U.S. government partners published an update to a joint Cybersecurity Advisory (originally released April 2026) warning of ongoing Iran-affiliated cyber activity targeting internet-connected operational technology (OT) devices — specifically Programmable Logic Controllers (PLCs). The update expands the manufacturer scope beyond Rockwell Automation to include Schneider Electric and Siemens, and provides new guidance on detecting malicious changes in reusable code modules within PLC programs. Attribution to "Iran-Affiliated Threat Actors" is unconfirmed — this actor grouping has no MITRE ATT&CK profile in the verified reference data. EMEA financial services clients with OT-dependent facilities (data centres, building management systems, physical security infrastructure) should assess exposure of PLCs and HMI/SCADA systems to internet-facing access.
2. Regulatory framing
No specific DORA/NIS2 article is directly engaged by this item. The advisory describes a threat campaign targeting OT/PLC infrastructure in U.S. critical infrastructure sectors. While DORA Art. 24 (digital operational resilience testing) and Art. 28 (ICT third-party risk) could theoretically apply to financial institutions with OT dependencies, the trigger facts are not distinctive to this item — they would be true of any security advisory recommending access restriction and configuration validation. Clients with material OT dependencies should assess under their existing resilience frameworks but no article-specific obligation is newly triggered.
3. Technical analysis & attack chain
Attribution caveat: The advisory attributes this activity to "Iran-Affiliated Threat Actors." This grouping has no MITRE ATT&CK profile in the verified reference data; attribution should be treated as unconfirmed. The advisory is single-sourced (U.S. government joint advisory); no corroboration from independent vendor research is available in the provided material.
Attack chain (confirmed from advisory text)
- Target selection: Actors identify internet-connected PLC devices across critical infrastructure sectors. Confirmed targeting spans Water and Wastewater Systems, Energy, and Government Services and Facilities (including local municipalities). Manufacturer scope confirmed as Rockwell Automation, Schneider Electric, and Siemens, with possible additional manufacturers.
- Initial access: Actors exploit internet-exposed PLC devices. The advisory emphasises "unsecure internet-connected accounts and devices" as the attack surface. No specific CVE, vulnerability mechanism, or exploit detail is provided in the source material.
- Malicious project file deployment: Actors attempt to download malicious project files to PLCs. The advisory's updated guidance focuses on detecting malicious changes in reusable code modules used within Rockwell Automation PLC programs — indicating the actors modify or replace legitimate project code.
- HMI/SCADA manipulation: Actors manipulate data on Human Machine Interface (HMI) and Supervisory Control and Data Acquisition (SCADA) displays.
- Observed impact: Operational disruption and financial loss at affected organisations. The advisory states PLCs have been disrupted across "several U.S. critical infrastructure sectors."
Technical gaps in source material: The advisory does not provide specific CVE identifiers, CVSS scores, exploit mechanisms, malware family names, C2 infrastructure, persistence techniques, or file system artefacts. No CISA-KEV exploitation state is documented for any specific vulnerability in the verified reference data. The activity is described at the campaign/behavioural level rather than with technical exploit detail.
4. Mitigation & containment
P1 — within 24 hours
- Identify internet-facing PLCs: Inventory all PLC devices across the estate (Rockwell Automation, Schneider Electric, Siemens, and any other manufacturers). Cross-reference against external attack surface scans. Any PLC with direct internet exposure is a critical finding.
- Block direct internet access to PLCs: Enforce network segmentation to isolate OT/PLC networks from the internet. Implement jump-host architecture for any required remote access. Apply deny-all firewall rules to PLC management interfaces except from explicitly authorised internal management subnets.
- Notify OT service providers: Inform any third-party OT maintenance or service providers of the active threat targeting internet-connected PLC devices, per the advisory's recommendation.
P2 — within 72 hours
- Validate running project files: Audit all PLC project files currently deployed against known-good baselines. The advisory specifically calls for validating project files running PLCs for unauthorised changes. For Rockwell Automation environments, apply the updated detection guidance for malicious changes in reusable code modules referenced in the advisory.
- Review manufacturer guidance: Review and implement security guidance previously issued by Rockwell Automation, Schneider Electric, and Siemens for OT deployment security.
- Assess HMI/SCADA exposure: Verify that HMI and SCADA systems are not internet-accessible and that display data integrity monitoring is in place.
P3 — within 7 days
- Implement continuous monitoring: Deploy OT-aware network monitoring to detect unauthorised project file downloads, PLC configuration changes, and anomalous HMI/SCADA traffic patterns.
- Establish PLC change management: Implement a formal change control process for all PLC project file modifications, including code review of reusable modules and cryptographic integrity verification of deployed projects.
- Tabletop exercise: Conduct an OT incident response tabletop focused on PLC compromise scenarios, including HMI/SCADA manipulation and operational disruption response procedures.
5. Indicators of compromise
No indicators of compromise available in the source material. The advisory references IOCs and detection guidance but does not include specific atomic indicators in the provided text.
Behavioural indicators
| Behaviour | Where to observe | Confidence |
|---|---|---|
| Unauthorised project file downloads to PLCs | OT network traffic, PLC audit logs, engineering workstation logs | High — confirmed in advisory |
| Malicious modifications to reusable code modules in Rockwell Automation PLC programs | PLC programming software (e.g., RSLogix/Studio 5000), project file comparison against baseline | High — confirmed in advisory update |
| Data manipulation on HMI/SCADA displays | HMI application logs, SCADA historian anomaly detection, operator reports of display inconsistencies | High — confirmed in advisory |
| Unauthorised access to internet-connected PLC devices | Firewall logs, network perimeter logs, PLC authentication logs | High — confirmed in advisory |
6. Detection
Insufficient indicators to author detection rules. The source material describes behavioural patterns (unauthorised project file downloads, reusable code module modifications, HMI/SCADA data manipulation) but does not provide specific file names, file paths, registry keys, command-line strings, mutex names, network signatures, or other artefacts suitable for YARA or Sigma rule construction. Clients should implement behavioural detection based on the indicators in §5 — specifically, alerting on unplanned PLC project file writes, diff-based comparison of reusable code modules against known-good baselines, and HMI display data integrity monitoring.
7. Sources
- CISA / FBI / EPA / U.S. Government Partners, "CISA, FBI, EPA and U.S. Government Partners Update Warning of Iran-Affiliated Threat Actors Targeting Critical Infrastructure Programmable Logic Controllers," https://www.cisa.gov/news-events/news/cisa-fbi-epa-and-us-government-partners-update-warning-iran-affiliated-threat-actors-targeting, published 2026-07-22.
8. Adverse Trace position
This is a credible, government-confirmed OT targeting campaign with operational impact, though attribution to Iran-affiliated actors is unconfirmed (no MITRE ATT&CK profile) and the advisory is single-sourced. The threat is directly relevant to EMEA financial services clients that operate OT-dependent facilities — data centres with building management systems, physical access control systems, and HVAC/chiller plant controls frequently use the same PLC families (Rockwell, Schneider, Siemens) named in this advisory. The core risk is not financial data theft but operational disruption to facilities that support trading floors, data centres, and critical business operations. We assess the immediate exposure for most EMEA financial clients as moderate (OT networks are typically segmented), but clients with any internet-facing PLC or HMI/SCADA exposure should treat this as a high-priority finding. Adverse Trace will monitor for the release of the full advisory text with technical IOCs and detection guidance, and will issue a follow-up note if specific CVEs, malware families, or atomic indicators are published.
Published via PulseTrace — Adverse Trace threat intelligence.