← All stories
● Covered by 9 sources · 20 reportsMedium impact15 negative5 neutral

Federal Agencies Broaden Alert on Iran-Linked OT Attacks Targeting More PLC Manufacturers

🔄 Updated 10d ago — new reporting from TechCrunch
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • US agencies expanded an alert on Iran-linked OT attacks.
  • Targeted PLCs now include Schneider Electric and Siemens.
  • Rockwell Automation and Allen-Bradley were previously identified.
  • Attacks involve malicious project files and data manipulation.
  • Incidents caused operational disruption and financial loss.
  • The initial advisory was published in April.
  • The updated advisory was published on July 22.
  • Targeted sectors include government services, energy, and water/wastewater.
  • The FBI, NSA, Department of Energy, and CISA issued the updated advisory.
  • Over 100 internet-exposed water systems were targeted in July 2026.
  • Attacks primarily used PLCs connected to cellular modems.
  • Attacks did not cause significant disruption.
  • At least 12 states were affected, including Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama.
  • CISA said attacks used AI tools to develop scripts for vulnerable Siemens PLCs.

Expanded Federal Warning on OT Attacks

Federal agencies, including CISA, the FBI, and the Environmental Protection Agency (EPA), broadened a warning initially issued in April concerning attacks on internet-facing operational technology (OT). The initial advisory focused on programmable logic controllers (PLCs) from Rockwell Automation and Allen-Bradley.

The revised alert now includes observed targeting of Schneider Electric, Siemens, and potentially other PLC manufacturers. This expansion reflects a wider scope of potential targets for Iran-affiliated hackers.

Targeted Technologies and Observed Incidents

The observed incidents involve malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays. These attacks have resulted in operational disruption and financial loss for targeted organizations.

PLCs are fundamental components for critical infrastructure sectors such as power utilities, wastewater treatment facilities, and manufacturing plants. Schneider and Siemens PLCs are widely used in the U.S. and globally.

Ongoing Threat to Critical Infrastructure

Officials anticipate that pressure from Iran-affiliated attackers will continue. The expanded targeting of additional manufacturers underscores the persistent threat to critical infrastructure systems.

The advisory does not name specific cyberthreat groups or attacks, noting that attribution of Iranian government-affiliated attacks can be challenging due to the regime's use of other groups as cover.

Recommendations for OT Owners

The federal agencies emphasized the importance for OT owners and operators to restrict direct internet access to their systems. They also advised ensuring secure PLC deployment practices to mitigate the risks posed by these attacks.

Updates

🕒 2026-08-26 · new reporting from TechCrunch
  • CISA said attacks used AI tools to develop scripts for vulnerable Siemens PLCs.
🕒 2026-08-26 · new reporting from SecurityWeek
  • Over 100 internet-exposed water systems were targeted in July 2026.
  • Attacks primarily used PLCs connected to cellular modems.
  • Attacks did not cause significant disruption.
  • At least 12 states were affected, including Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama.
🕒 2026-07-23 · new reporting from TechCrunch
  • The initial advisory was published in April.
  • The updated advisory was published on July 22.
  • Targeted sectors include government services, energy, and water/wastewater.
  • The FBI, NSA, Department of Energy, and CISA issued the updated advisory.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~15 min · 12 stories · Sep 05

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that over 100 internet-exposed systems in the U.S. water and wastewater sector were targeted by cyberattacks in July. These attacks primarily focused on programmable logic controllers (PLCs) from manufacturers like Rockwell, Schneider Electric, and Siemens, raising concerns about critical infrastructure cybersecurity.

The Cybersecurity and Infrastructure Security Agency (CISA) disclosed that over 100 internet-exposed water systems were targeted in cyberattacks in July 2026, primarily through programmable logic controllers (PLCs) connected to cellular modems. This information quantifies the scale of recent attacks on critical infrastructure and highlights the ongoing vulnerability of operational technology (OT) systems in the Water and Wastewater Systems (WWS) Sector.

Multiple water utilities in the United States have experienced cyberattacks since late last month, impacting facilities in at least seven states. While the U.S. government has not officially named a culprit, Iranian government-backed hackers are the primary suspects, raising concerns about an escalation in cyber warfare against critical infrastructure.

Water and wastewater facilities in New Jersey and Alabama have confirmed they were targeted in a cyberattack campaign that began in late July, bringing the total number of affected states to at least 12. The attacks, linked to Iranian hackers, primarily targeted operational technology (OT) and industrial control systems (ICS) but caused limited disruptions to services.

Forescout identified 4,407 internet-exposed Rockwell Automation programmable logic controllers (PLCs) globally, with 22 located in cities recently affected by cyberattacks on US water utilities. This exposure creates an unauthenticated path for potential attackers to identify or modify controller settings, which is relevant to recent incidents where attackers changed IP addresses and set passwords on reachable controllers.

Cyberattacks targeting water utilities have expanded to at least 12 states, including recent incidents in South Dakota and Georgia. These attacks, which federal agencies attribute to Iranian hackers, disrupt operational systems and have led to precautionary measures like boil water advisories. The incidents highlight a growing threat to critical infrastructure, prompting warnings from CISA about exposed operational technology.

A hacking campaign has targeted water and wastewater facilities in at least 12 US states, with the FBI confirming attacks on Rockwell Automation Micrologix PLCs. Attackers are tampering with device configurations, though no significant disruptions to drinking water safety have been officially reported.

Federal authorities reported that "malicious cyber actors" targeted water and wastewater facilities in at least seven US states, with Minnesota experiencing disruptions in 30 water systems. The attacks led to issues like low-pressure water flow and boil-water notices, prompting CISA to advise utilities to operate systems manually. The FBI has opened an investigation, and officials suspect Iran is responsible, though no public attribution has been made.

Cyberattacks targeting operational technology systems in the US water and wastewater sector have affected at least seven states, including Minnesota, Michigan, South Dakota, and Georgia. These incidents are reportedly aligned with previous hacking campaigns attributed to Iran, raising concerns about critical infrastructure security.

Water supply control systems in seven US states have reported cyberattacks, with officials suspecting Iranian involvement, though definitive proof is pending. These incidents have prompted some affected municipalities to switch to manual control, highlighting vulnerabilities in older internet-connected infrastructure. The attacks are significant as they target essential services within the US mainland, raising concerns about critical infrastructure security.

CISA issued an alert regarding increased targeting of internet-exposed programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) sector. Threat actors are modifying PLC passwords and changing IP addresses, leading to operational disruptions and boil-water notices. CISA recommends removing publicly exposed PLCs and implementing secure remote access methods.

The FBI and EPA issued a public service announcement warning that cyberattacks have affected water and wastewater utility companies in seven US states since July 27, 2026, leading to degraded water operations, including flooding and loss of water pressure. These incidents highlight a growing threat to critical infrastructure, with attackers targeting Programmable Logic Controllers (PLCs) to disrupt essential services and potentially compromise water safety.

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding a significant increase in malicious activity targeting water utilities, urging facilities to remove publicly exposed operational technology from the internet. This warning follows investigations into recent disruptions affecting over 30 Minnesota community water systems, which some reports link to Iran-backed hackers.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent alert regarding a rise in cyberattacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater sector. These attacks, which recently disrupted over 30 Minnesota water systems, involve hackers changing passwords and modifying IP addresses to disrupt operations. This development highlights critical infrastructure vulnerabilities and the need for immediate security measures to prevent widespread operational disruptions.

Over 30 water systems in Minnesota were targeted by cyberattacks on Sunday and Monday, prompting an investigation by state authorities and the FBI. These incidents occurred amidst recent warnings from federal agencies about Iranian hackers focusing on critical infrastructure, including water and wastewater systems.

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert urging water and wastewater system operators to protect operational technology (OT) from attacks targeting programmable logic controllers (PLCs). This warning follows a coordinated cyberattack that disrupted automated controls at over 30 water utilities in Minnesota, highlighting the vulnerability of critical infrastructure to such threats.

More than 30 community water systems in Minnesota experienced coordinated cyberattacks on their operational technology (OT) systems on July 26 and 27, affecting some automated control functions. While most operations remained functional, one city briefly took its water plant offline, highlighting the vulnerability of critical infrastructure to cyber threats.

The U.S. government has issued a warning that Iranian state-backed hackers are actively compromising and disrupting industrial control systems at American water and energy providers. This activity is causing outages and disruption, and is likely a response to ongoing geopolitical conflicts.

The US government updated a cybersecurity advisory, stating that Iranian state-sponsored hackers are targeting industrial control systems (ICS) from Siemens, Schneider Electric, and Rockwell Automation. These attacks aim to disrupt critical infrastructure by manipulating programmable logic controllers (PLCs) and disabling safety mechanisms, posing a significant threat to operational technology environments.

Federal agencies expanded an alert regarding Iran-affiliated hackers targeting internet-facing operational technology (OT). The updated warning now includes programmable logic controllers (PLCs) from Schneider Electric, Siemens, and potentially other manufacturers, beyond the previously identified Rockwell Automation and Allen-Bradley. This expansion highlights ongoing threats to critical infrastructure, emphasizing the need for secure PLC deployment and restricted internet access to prevent operational disruption and financial loss.