Iranian state-backed hackers are actively breaking into US water and energy control systems modifying the logic that runs physical equipment and in some cases deleting it entirely. The FBI and CISA confirmed the campaign in a joint advisory published as CISA advisory AA26-097a, warning that the attacks have already caused operational disruptions and financial losses at affected facilities.
This is not reconnaissance. The attackers are reaching the engineering layer of industrial control systems and making changes that affect how physical processes behave.
What the Attackers Are Actually Doing Inside These Systems
The entry point is straightforward and entirely avoidable, exposed OT ports and modems reachable over SSH. No zero-days are involved. Once inside, the attackers are targeting Rockwell Automation and Allen-Bradley programmable logic controllers along with engineering environments including Studio 5000, Schneider Electric’s EcoStruxure Control Expert and Siemens TIA Portal.
The specific actions documented in CISA’s advisory go well beyond typical intrusion behaviour. Attackers are modifying and deleting Add-On Instructions, the reusable logic blocks that define how a PLC controls physical equipment. They are manipulating HMI and SCADA displays meaning operators may be looking at instrument readings that do not reflect real process conditions. They are also disabling shutdown and alarm functions removing the automated safeguards that exist precisely to prevent equipment damage and safety incidents.
Disabling alarms before making process changes is a deliberate tactic. It extends the window in which an operator has no indication that anything is wrong.
The Advisory Comes from CISA and FBI, Not a Vendor
The sourcing here matters. CISA advisory AA26-097a is a government document, not a vendor threat report with a commercial angle. The FBI co-signed it. TechCrunch confirmed the advisory’s publication and quoted the US government’s characterisation of the activity directly.
Attribution to Iranian state-backed actors comes from CISA and the FBI not from a private security firm that discovered the campaign and issued a press release within 48 hours. That does not make attribution a legal certainty but it carries significantly more weight than the typical vendor announcement. The advisory stops short of naming a specific Iranian APT group and I would not push further than the government’s own framing on that point.
Cybersecurity Dive reported separately that the FBI and CISA are warning the attackers are expanding their target set beyond the facilities already affected.
The Fundamental Problem Is That OT Systems Are Exposed to the Internet at All
Every tactic in this campaign depends on one precondition, the target’s OT environment is reachable over the public internet via SSH. That is a configuration failure, not a sophisticated attack capability. Rockwell Automation, Schneider Electric and Siemens did not design these systems to sit on internet-facing networks. They ended up there through a combination of remote access shortcuts, legacy modem installations and IT-OT convergence projects that were never properly segmented.
The fact that a state-backed actor can walk into a water treatment facility’s control network through an exposed SSH port in 2026 reflects an OT security posture that has not kept pace with the threat environment. No patch will fix that.
Steps Operators Need to Take Now
The immediate priority is network exposure. Audit every device in your OT environment for internet-facing ports particularly SSH. Any device reachable directly from the public internet without a VPN and multi-factor authentication is a candidate for compromise today regardless of whether you have seen indicators of intrusion.
Verify your PLC logic. If you run Rockwell Allen-Bradley controllers, Studio 5000 projects or engineering configurations in EcoStruxure Control Expert or TIA Portal, compare current project logic against your last known-good backup. Specifically check Add-On Instructions and any custom function blocks. If you do not have a recent verified backup to compare against, that is the first problem to solve.
Check your alarm and shutdown configurations independently of the HMI display. If an attacker has manipulated SCADA screen data, the display cannot be trusted to confirm that alarms are active. Verify alarm states at the controller level.
CISA’s advisory AA26-097a contains the full list of indicators of compromise and recommended mitigations. Read it directly rather than through a vendor summary.
References
- Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers
- US Government Says Iran-Linked Hackers Are Disrupting American Water and Energy Providers
- Iran-linked Hackers Target Water, Energy in US, FBI and CISA Warn
- CISA, FBI Warn That Iran-linked Hackers are Expanding Target Set for Water, Energy
- Iran-Linked Actors Breach Are Targeting US Water and Energy Control Systems
This post is also available in: