IC Technology & Cyber — 2026-08-02

CISA Issues Emergency Directive to Remove Internet-Exposed PLCs After Iran-Linked CyberAv3ngers Attacks Expand to Seven States

BLUFExfiltrated PLC project files give attackers a blueprint for precision follow-on strikes against water infrastructure, while formal federal attribution within 60 days remains unlikely.

CISA's advisory AA26-097A, originally published April 7 and updated July 22 and again in late July, warned that Iranian-affiliated actors are exploiting internet-exposed programmable logic controllers across the water and wastewater sector 1. Minnesota IT Services reported that a coordinated attack disabled OT systems at more than 30 community water utilities on July 26 and 27 by modifying operator passwords and reassigning controller IP addresses, with Braham's water plant taken fully offline and restored within about two hours, and Maple Plain, Plymouth, and South St. Paul also affected 2. The FBI confirmed utilities in at least seven states have reported PLC-related incidents, and CISA said the exploited devices now include Schneider Electric and Siemens hardware in addition to Rockwell Automation controllers, with attackers stealing PLC project files for the first time 2. No agency has formally attributed the Minnesota intrusions to a specific actor 2.

Analysis
Attackers now hold exfiltrated PLC project files across at least seven states, enabling follow-on intrusions tailored to each plant's actual control logic rather than opportunistic default-credential access. Formal federal attribution to CyberAv3ngers or Iran within 60 days is unlikely, since Minnesota officials and CISA have withheld attribution despite ongoing forensic work; the intrusions may instead reflect opportunistic exploitation of long-known default-credential weaknesses by financially motivated or unaffiliated actors rather than a coordinated state campaign. Moderate confidence reflects a single primary CISA advisory corroborated by state-level incident reporting but no independent signals or human-source access to attacker identity. Confirmed device scope has widened from Rockwell controllers alone to include Schneider Electric and Siemens hardware. Formal attribution to Iran, if it comes, would shift the federal response from utility-level OT-hardening guidance to a state-actor deterrence posture, triggering sanctions consideration and coordinated defense across all seven affected states.
3 sources
  1. CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs - SecurityWeek
  2. CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks - Security Affairs
  3. Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure (AA26-097A) - CISA

View in full brief →

UNCLASSIFIED // OPEN SOURCE