CISA Adds Siemens, Schneider to Iran PLC Advisory
The expansion from water-sector PLCs in 2023 to a three-vendor, cross-sector advisory signals CISA now treats Iranian OT targeting as a systematic campaign, not a niche concern.
TL;DR
CISA updated its April 2026 advisory on Iran-affiliated PLC exploitation to add Schneider Electric and Siemens alongside the originally named Rockwell Automation/Allen-Bradley, with "potentially other branded/manufactured PLCs" also in scope. The July 22 update adds detection guidance for malicious code injection in reusable modules. This is the third Iran-linked PLC advisory since December 2023, tracing an arc from sector-specific targeting of water systems to a multi-vendor, cross-sector threat picture across government services, water, and energy.
The update to AA26-097A, published July 22, is the third joint advisory on Iranian PLC exploitation in roughly two and a half years. Each has widened the aperture. The December 2023 advisory (AA23-335A) focused on IRGC-affiliated actors targeting water and wastewater systems, primarily Unitronics PLCs. The April 2026 advisory named Rockwell Automation/Allen-Bradley devices across government services, water, and energy sectors. Now Schneider Electric and Siemens join the list, with CISA noting "potentially other branded/manufactured PLCs" as well.
The pattern is no longer ambiguous. Iranian state-affiliated actors are systematically probing internet-connected OT devices across manufacturers and sectors, downloading malicious project files and manipulating HMI and SCADA displays. The result, per CISA, is "operational disruption and financial loss."
The new detection guidance focuses on a specific technique: malicious changes injected into reusable code modules within Rockwell Automation PLC programs. That's an attack vector with supply-chain implications. Compromise a module once, and every project file that imports it becomes a potential carrier. For the practitioner, this means code validation can't stop at the project file level; reusable module libraries need the same scrutiny.
CISA's updated mitigations are straightforward but operationally demanding: review manufacturer security guidance, strictly control network access to PLCs, validate project files for unauthorized changes, and ensure service providers know about the threat. The first and third items are the ones that'll eat engineering hours. Validating every project file across a fleet of PLCs for subtle code injection isn't a checkbox exercise.
The open question, which CISA doesn't answer in this advisory, is how many of these compromised organizations detected the intrusion themselves versus learning about it from law enforcement. The advisory's existence implies the latter for at least some cases. For critical infrastructure operators running internet-connected PLCs from any of the three named vendors, the clock for self-assessment started when the April advisory dropped. This update just made the to-do list longer.
Published ·Deep Fathom