Updated July 22, 2026 · Active Federal Advisory

The Iranian PLC Advisory Was Just Updated. It Is Not Over.

Seven federal agencies reissued advisory AA26-097A on July 22, 2026. The Iranian-affiliated campaign against internet-exposed programmable logic controllers has expanded past Rockwell to Schneider Electric and Siemens, and the agencies added new detection guidance. This is current activity, not a 2023 story.

Product ID AA26-097A  ·  Originally April 7, 2026  ·  Last updated July 22, 2026  ·  FBI · CISA · NSA · EPA · DOE · CNMF · Treasury

What Changed on July 22, 2026

The original advisory landed April 7. This update makes clear the threat grew rather than faded.

Expanded scope

Not just Rockwell anymore

The agencies now confirm targeting of Schneider Electric and Siemens PLCs, and potentially other brands, on top of the Rockwell Automation / Allen-Bradley devices in the original advisory. Effectively, any internet-exposed PLC is in scope.

New detection guidance

Malicious reusable code modules

The update adds guidance for detecting malicious changes hidden inside reusable code modules (Add-On Instructions and similar) within Rockwell PLC programs, a place defenders rarely inspect.

Confirmed impact

Disruption and financial loss

Actors manipulated PLC project files and altered what operators saw on HMI and SCADA displays. In multiple U.S. critical-infrastructure sectors this caused real operational disruption and financial loss.

Who is targeted

Water, energy, and local government

Named sectors are Government Services and Facilities (including local municipalities), Water and Wastewater Systems, and Energy. Small utilities and towns are explicitly in the blast radius.

The Threat Is Current. That Is the Whole Point.

The actors are Iranian-affiliated APT operators. The authoring agencies previously tracked this activity under CyberAv3ngers (also called the Shahid Kaveh Group), tied to Iran's IRGC Cyber Electronic Command. In a related November 2023 campaign, these actors compromised at least 75 devices, replacing valid ladder logic on Unitronics PLCs and HMIs with malicious code that was still being observed long after.

What the July 22 update signals is that this is not a closed 2023 incident. It is a live, expanding campaign. The government's core recommendation remains blunt: get your PLCs off the public internet. If a controller answers on the open internet today, it is reachable by the same actors this advisory describes.

If you own or integrate OT, the agencies ask you to urgently review the TTPs and IOCs, check your environment for current or historical activity, and engage your incident response plan and vendor if you find an affected internet-accessible device.

Read the primary sources

Key Actions the Advisory Asks For

Straight from AA26-097A. If you run PLCs, these are the moves.

Who Is At Risk

If a PLC in your environment can be reached from the internet, you are in scope.

Water & Wastewater

Municipal water systems, wastewater plants, lift stations, and remote SCADA sites, a named sector in the advisory.

Energy & Utilities

Electric cooperatives, distribution operators, and generation sites running exposed controllers and RTUs.

Local Government

Towns and county facilities, called out explicitly. Small operators with little OT security oversight are prime targets.

Manufacturing & Facilities

Any plant, building system, or process running Rockwell, Schneider, Siemens, or other PLCs reachable from the internet.

How RedEye Helps You Answer This

A focused OT threat hunt built around exactly the exposure and IOCs this advisory describes. Zero operational impact.

1

Exposure Check

We find every PLC, RTU, and HMI reachable from the internet, and which protocols they answer.

2

Passive Monitoring

Non-intrusive capture of ICS traffic on ports like 44818, 502, and 102. We baseline normal.

3

Threat Hunt

We hunt the AA26-097A IOCs, unexpected changes in PLC logic and reusable modules, and foreign-sourced access.

4

Report

Executive summary, technical findings, and a prioritized fix list, mapped to the advisory and CISA goals.

Is One of Your Controllers Answering the Internet Right Now?

Free scoping call. We check your exposure against this exact advisory, hunt for the IOCs, and show you what an assessment covers. Federal grants may cover the cost.

Schedule Free Scoping Call