Updated Cybersecurity Advisory

Last Updated: July 29, 2026

The initial Alert on this topic was issued April 7, 2026. It was updated on July 22, 2026, by the US Cybersecurity and Infrastructure Security Agency (CISA), based on most current information and recent developments. What follows is the updated Alert and should be evaluated by all waterworks with internet-connected operational technology (OT) devices including programmable logic controllers (PLCs).

Overview

The authoring agencies urgently warn U.S. organizations of ongoing Iranian-affiliated cyber targeting of internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs). These actions disrupted PLCs across several U.S. critical infrastructure sectors through malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss.

This update adds new guidance on detecting malicious changes in reusable code modules exploited within Rockwell Automation PLC programs. It also expands scope to include observed targeting of Schneider Electric, Siemens, and potentially other branded/manufactured PLCs, emphasizing the importance of restricting direct internet access and providing best practices for secure deployment.

Affected Products

Potentially all internet exposed PLCs, including Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and other branded/manufactured PLCs.

Recommended Actions

  • Install PLCs consistent with manufacturers’ guidelines and security best practices.
  • Remove PLCs from direct internet exposure via secure gateway and firewall; work with IT/OT team members and/or integrators to perform this action.
  • Query available logs for the provided indicators of compromise (IOCs) and check available logs for suspicious traffic on the ports associated with OT devices, including 44818, 2222, 102, and 502, especially traffic originating from foreign hosting providers.
  • For Rockwell Automation devices, place the physical mode switch on the controller into run position. If you suspect your organization was targeted, including against other branded PLC devices, contact the authoring agencies and PLC manufacturer for guidance.

Indicators of Compromise

For a downloadable copy of July 22, 2026 IOCs, see:

For a downloadable copy of historical April 7, 2026 IOCs, see:

For the full CISA report visit the CISA Iranian-Affiliated Cyber Actors Report

Remember- If you see something, say something:

Report suspicious activity and threats of violence, including online threats as appropriate to local law enforcement, FBI – Richmond Field Office, and the VSP Fusion Center. The VSP Fusion Center will take appropriate action and investigate reports of concern with appropriate state and federal partners. The EPA Incident Action Checklist for Cybersecurity also includes resources for preparation and recovery. 

Maintain vigilance to protect critical infrastructure.  Please ensure your workforce is aware of the potential threats and that they know to report any and all suspicious activity to the VSP Fusion Center.  Thank you for taking immediate action to harden assets and protect people and critical infrastructure.

Cybersecurity & Infrastructure Security Agency (CISA)
Incident Reporting Webpage
Email: report@cisa.gov
Phone: 1-844-Say-CISA (1-844-729-2472)
Virginia Fusion Center
Virginia Fusion Center: Incident Reporting Webpage
Phone: 877-4VA-TIPS (877-482-8477)

View the VDH-Office of Drinking Water Website for Waterworks Cybersecurity for more resources.