Updated Cybersecurity Advisory

The initial Alert on this topic was issued April 7, 2026. It was updated on July 22, 2026, by the US Cybersecurity and Infrastructure Security Agency (CISA), based on most current information and recent developments. What follows is the updated Alert and should be evaluated by all waterworks with internet-connected operational technology (OT) devices including programmable logic controllers (PLCs).

Overview

The authoring agencies urgently warn U.S. organizations of ongoing Iranian-affiliated cyber targeting of internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs). These actions disrupted PLCs across several U.S. critical infrastructure sectors through malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss.

This update adds new guidance on detecting malicious changes in reusable code modules exploited within Rockwell Automation PLC programs. It also expands scope to include observed targeting of Schneider Electric, Siemens, and potentially other branded/manufactured PLCs, emphasizing the importance of restricting direct internet access and providing best practices for secure deployment.

Affected Products

Potentially all internet exposed PLCs, including Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and other branded/manufactured PLCs.

Recommended Actions

  • Install PLCs consistent with manufacturers’ guidelines and security best practices.
  • Remove PLCs from direct internet exposure via secure gateway and firewall; work with IT/OT team members and/or integrators to perform this action.
  • Query available logs for the provided indicators of compromise (IOCs) and check available logs for suspicious traffic on the ports associated with OT devices, including 44818, 2222, 102, and 502, especially traffic originating from foreign hosting providers.
  • For Rockwell Automation devices, place the physical mode switch on the controller into run position. If you suspect your organization was targeted, including against other branded PLC devices, contact the authoring agencies and PLC manufacturer for guidance.

Indicators of Compromise

For a downloadable copy of July 22, 2026 IOCs, see:

For a downloadable copy of historical April 7, 2026 IOCs, see:

For the full CISA report visit the CISA Iranian-Affiliated Cyber Actors Report

Remember- If you see something, say something:

Report suspicious activity and threats of violence, including online threats as appropriate to local law enforcement, FBI – Richmond Field Office, and the VSP Fusion Center. The VSP Fusion Center will take appropriate action and investigate reports of concern with appropriate state and federal partners. The EPA Incident Action Checklist for Cybersecurity also includes resources for preparation and recovery. 

Maintain vigilance to protect critical infrastructure.  Please ensure your workforce is aware of the potential threats and that they know to report any and all suspicious activity to the VSP Fusion Center.  Thank you for taking immediate action to harden assets and protect people and critical infrastructure.

Cybersecurity & Infrastructure Security Agency (CISA)
Incident Reporting Webpage
Email: report@cisa.gov
Phone: 1-844-Say-CISA (1-844-729-2472)
Virginia Fusion Center
Virginia Fusion Center: Incident Reporting Webpage
Phone: 877-4VA-TIPS (877-482-8477)

View the VDH-Office of Drinking Water Website for Waterworks Cybersecurity for more resources.

Iranian Affiliated Cyber Actors Threat

Overview

The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and Environmental Protection Agency (EPA) are urgently warning U.S. organizations of ongoing cyber exploitation of internet-connected operational technology (OT) devices, including Rockwell Automation/Allen-Bradley-manufactured programmable logic controllers (PLCs), across multiple U.S. critical infrastructure sectors.

Recommended Actions

EPA recommends water and wastewater systems review the tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) in this advisory for indications of current or historical activity on their networks, and apply the recommended immediate steps to prevent the attack:

  • Limit PLC exposure to the public-internet
  • Ensure PLCs are in run mode to prevent remote modification
  • Replace all default passwords on PLCs and OT with strong, unique passwords

Water systems are encouraged to review and implement the additional follow-up steps included in the advisory to further strengthen their cybersecurity posture.

Technical Assistance

If you have questions about any of the information in this alert, including assistance with the mitigation steps, submit a request to EPA’s Cybersecurity Technical Assistance Program for the Water Sector.

Report an Incident

Organizations are encouraged to report information concerning suspicious or criminal activity to FBI Internet Crime Complaint Center (IC3) at IC3.gov or to CISA via CISA’s Incident Reporting System.

Access Advisory Here

CISA and Partners Release Guidance for Ongoing Global Exploitation of Cisco SD-WAN Systems – 2/25/26

CISA and partners have observed malicious cyber actors targeting and compromising Cisco SD-WAN systems of organizations, globally. These actors have been observed exploiting a previously undisclosed authentication bypass vulnerability, CVE-2026-20127, for initial access before escalating privileges using CVE-2022-20775 and establishing long-term persistence in Cisco SD-WAN systems.

Click here to visit a link to the CISA alert.

Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure

The FBI, CISA, NSA assess pro-Russia hacktivist groups are conducting less sophisticated, lower-impact attacks against critical infrastructure entities, compared to advanced persistent threat (APT) groups. These attacks use minimally secured, internet-facing virtual network computing (VNC) connections to infiltrate (or gain access to) OT control devices within critical infrastructure systems. Pro-Russia hacktivist groups—Cyber Army of Russia Reborn (CARR), Z-Pentest, NoName057(16), Sector16, and affiliated groups—are capitalizing on the widespread prevalence of accessible VNC devices to execute attacks against critical infrastructure entities, resulting in varying degrees of impact, including physical damage. Targeted sectors include Water and Wastewater Systems, Food and Agriculture, and Energy.

More information on this alert can be found here.

BRICKSTORM Backdoor CISA Alert

The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and Canadian Centre for Cyber Security (Cyber Centre) assess People’s Republic of China (PRC) state-sponsored cyber actors are using BRICKSTORM malware for long-term persistence on victim systems. CISA, NSA, and Cyber Centre are releasing this Malware Analysis Report to share indicators of compromise (IOCs) and detection signatures based off analysis of eight BRICKSTORM samples. CISA, NSA, and Cyber Centre urge organizations to use the IOCs and detection signatures to identify BRICKSTORM malware samples.

More information on the alert can be found on the CISA website here.

Microsoft Sharepoint Vulnerabilities

The U.S. EPA is issuing this alert to inform water and wastewater system owners and operators of the need for increased vigilance surrounding the use of Microsoft SharePoint.  While the scope and impact continue to be assessed, the chain, publicly reported as “ToolShell,” provides unauthenticated access to systems and authenticated access through network spoofing, respectively, and enables malicious actors to fully access SharePoint content, including file systems and internal configurations, and execute code over the network.  See a full update regarding this release on the CISA’s Webpage.