CTIPilot

Siemens SIMATIC S7-1200

product · product:siemens-simatic-s7-1200 single-source-national-cert

Coverage timeline
3
first 2026-07-29 → last 2026-08-20
Peak priority
high
3 high
Sources cited
17
13 hosts
Sections touched
2
active-threats, deep-dive
Co-occurring entities
8
see Co-occurring entities below
ATT&CK techniques
17
pinned v19.2 · see below

ATT&CK techniques

17 techniques observed across 3 entries, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Reconnaissance TA0043

T1596.005Search Open Technical Databases: Scan Databases×1

Adversaries may search within public scan databases for information about victims that can be used during targeting. Various online services continuously publish the results of Internet scans/surveys, often harvesting information such as active IP addresses, hostnames, open ports, certificates, and even server banners.

Evidence: 2026-08-20/joint-advisory-active-threat-siemens-s7-plcs · ATT&CK page ↗

Resource Development TA0042

T1587.004Develop Capabilities: Exploits×1

Adversaries may develop exploits that can be used during targeting. An exploit takes advantage of a bug or vulnerability in order to cause unintended or unanticipated behavior to occur on computer hardware or software. Rather than finding/modifying exploits from online or purchasing them from exploit vendors, an adversary may develop their own exploits. Adversaries may use information acquired via Vulnerabilities to focus exploit development efforts. As part of the exploit development process, adversaries may uncover exploitable vulnerabilities through methods such as fuzzing and patch analysis.

Evidence: 2026-08-20/joint-advisory-active-threat-siemens-s7-plcs · ATT&CK page ↗

T1588.007Obtain Capabilities: Artificial Intelligence×1

Adversaries may obtain access to generative artificial intelligence tools, such as large language models (LLMs), to aid various techniques during targeting. These tools may be used to inform, bolster, and enable a variety of malicious tasks, including conducting Reconnaissance, creating basic scripts, assisting social engineering, and even developing payloads.

Evidence: 2026-08-20/joint-advisory-active-threat-siemens-s7-plcs · ATT&CK page ↗

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×2

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · 2026-07-29/minnesota-30-water-utilities-coordinated-ot-attack · ATT&CK page ↗

T1133External Remote Services×2

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · 2026-07-29/minnesota-30-water-utilities-coordinated-ot-attack · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-20/joint-advisory-active-threat-siemens-s7-plcs · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×2

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · 2026-07-29/minnesota-30-water-utilities-coordinated-ot-attack · ATT&CK page ↗

T1133External Remote Services×2

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · 2026-07-29/minnesota-30-water-utilities-coordinated-ot-attack · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×2

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · 2026-07-29/minnesota-30-water-utilities-coordinated-ot-attack · ATT&CK page ↗

Stealth TA0005

T1036Masquerading×1

Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names.

Evidence: 2026-08-20/joint-advisory-active-threat-siemens-s7-plcs · ATT&CK page ↗

T1070Indicator Removal×1

Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior.

Evidence: 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · ATT&CK page ↗

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×2

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · 2026-07-29/minnesota-30-water-utilities-coordinated-ot-attack · ATT&CK page ↗

Discovery TA0007

T1046Network Service Discovery×2

Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system.

Evidence: 2026-08-20/joint-advisory-active-threat-siemens-s7-plcs · 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · ATT&CK page ↗

Lateral Movement TA0008

T1021.004Remote Services: SSH×1

Adversaries may use Valid Accounts to log into remote machines using Secure Shell (SSH). The adversary may then perform actions as the logged-on user.

Evidence: 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · ATT&CK page ↗

Command and Control TA0011

T1572Protocol Tunneling×1

Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.

Evidence: 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · ATT&CK page ↗

Exfiltration TA0010

T1041Exfiltration Over C2 Channel×1

Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.

Evidence: 2026-07-29/minnesota-30-water-utilities-coordinated-ot-attack · ATT&CK page ↗

Impact TA0040

T1531Account Access Removal×2

Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts. Adversaries may also subsequently log off and/or perform a System Shutdown/Reboot to set malicious changes into place.

Evidence: 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · 2026-07-29/minnesota-30-water-utilities-coordinated-ot-attack · ATT&CK page ↗

T1561.002Disk Wipe: Disk Structure Wipe×1

Adversaries may corrupt or wipe the disk data structures on a hard drive necessary to boot a system; targeting specific critical systems or in large numbers in a network to interrupt availability to system and network resources.

Evidence: 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · ATT&CK page ↗

T1565Data Manipulation×1

Adversaries may insert, delete, or manipulate data in order to influence external outcomes or hide activity, thus threatening the integrity of the data. By manipulating data, adversaries may attempt to affect a business process, organizational understanding, or decision making.

Evidence: 2026-07-29/minnesota-30-water-utilities-coordinated-ot-attack · ATT&CK page ↗

T1565.001Data Manipulation: Stored Data Manipulation×1

Adversaries may insert, delete, or manipulate data at rest in order to influence external outcomes or hide activity, thus threatening the integrity of the data. By manipulating stored data, adversaries may attempt to affect a business process, organizational understanding, and decision making.

Evidence: 2026-07-29/minnesota-30-water-utilities-coordinated-ot-attack · ATT&CK page ↗

Story timeline

  1. 2026-08-20Five US agencies warn of an active threat to Siemens S7 PLCs, AI-written Python tooling built on the standard S7 libraries, dressed as legitimate OT monitoring software
    active-threatsThe agencies say the targeting is not limited to Siemens, and that what they see is reconnaissance rather than confirmed manipulation
  2. 2026-08-09CERT Polska: a second Polish CHP plant was shut down on 29 December 2025 through the distribution operator's private APN, the first real-world use of that path into an OT network
    deep-diveA mobile-carrier private APN, shared by a wind farm and a heat plant, carried an attacker from a substation firewall to the turbine controls
  3. 2026-07-29Coordinated two-day cyberattack disrupts operational technology at 30+ Minnesota water and wastewater utilities; no authority has attributed it
    active-threatsMinnesota confirms a coordinated attack on field OT at more than 30 community water systems, days after a US advisory update on internet-exposed PLCs

Where this entity is cited

  • active-threats2
  • deep-dive1

Source distribution

  • bleepingcomputer.com2 (12%)
  • cert.pl2 (12%)
  • cisa.gov2 (12%)
  • securityweek.com2 (12%)
  • cbsnews.com1 (6%)
  • censys.com1 (6%)
  • cybersecuritydive.com1 (6%)
  • fbi.gov1 (6%)
  • other5 (29%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (17)

Entries about Siemens SIMATIC S7-1200 (3)

2026-08-20 · view entry permalink →

HIGHupdatedNATOB2

Five US agencies warn of an active threat to Siemens S7 PLCs, AI-written Python tooling built on the standard S7 libraries, dressed as legitimate OT monitoring software

The NSA, CISA, the FBI, the Department of Energy and the Environmental Protection Agency published a joint advisory on 2026-08-19 stating that "This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs)," and adding a scope caveat that matters more than the headline: "However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems" (BleepingComputer, 2026-08-19). The actively targeted devices are the S7-200, S7-300, S7-400, S7-1200 and S7-1500. The sectors the agencies name as most targeted are critical manufacturing, energy, water and wastewater systems, chemical, food and agriculture, and commercial facilities, and they note S7 controllers are also used in the defence industrial base.

The access path described involves no novel vulnerability. Actors find exposed controllers through internet-scanning services (Censys and ZoomEye are named) and then attack critical and high-severity vulnerabilities, outdated software and weak authentication (BleepingComputer, 2026-08-19). What is new is the tooling and how it presents itself: the advisory reports attackers using artificial intelligence to develop Python exploitation scripts built on the snap7.dll and python-snap7 libraries (the standard open-source means of speaking S7comm to a Siemens controller) and disguising those custom tools as legitimate OT monitoring software. Those tools can provide read and write access to PLC memory, configuration data and ladder-logic programs over S7comm, and the advisory's own behaviour mapping lists conducting read and write operations on data blocks among the actor activity it describes. That combination is the uncomfortable part for a defender: the protocol traffic is the protocol working as designed, the library is the one an integrator would legitimately use, and the process name claims to be a monitoring product.

The agencies' own characterisation of intent is careful and worth carrying precisely: the activity appears focused on persistent reconnaissance, potentially preparing attackers for disruption to critical infrastructure, including data theft, equipment damage, extended downtime or safety incidents (BleepingComputer, 2026-08-19). That is a statement about preparation, not about control-system manipulation having occurred, and an entry that blurred the two would misrepresent what five agencies were willing to say. The recommended actions are correspondingly unglamorous: inventory S7 controllers, install the latest security updates, block internet access to them, strengthen access controls, and monitor for unusual activity targeting these devices.

This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs),

However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems.

BleepingComputer, quoting the joint advisory

Identify any systems directly or indirectly accessible from untrusted networks

against backup gold copy

NSA, CISA, FBI, Department of Energy and Environmental Protection Agency, joint cybersecurity advisory (FBI mirror)
Updaterun 2026-08-21T0410Z-intelactionsevidencereferencessectorstechniquesbody

The earlier entry recorded the five agencies' warning, the targeted controller families, the AI-developed Python tooling built on the standard S7 libraries, and the assessment that the activity is focused on persistent reconnaissance potentially preparing for disruption. It was composed single-source from an outlet's reading of the advisory, because the advisory publishes as a PDF only and the agency's own page refuses every transport available here, and nothing in this environment could turn PDF bytes into text. That capability was added this run, so the primary has now been read. What follows is only what the earlier entry could not carry.

The advisory's scope note comes first, because it changes who should act. Its opening note states this advisory relates to an active threat to Siemens S7 Series programmable logic controllers, and then widens the frame: ongoing PLC targeting activity is broader than Siemens PLCs, all PLC owners and operators should apply relevant mitigations to reduce risk to their devices and systems, and the Siemens-specific content should be understood and applied as one subset of the wider threat landscape. An operator running a different vendor's controllers is inside the advisory's intended audience, not outside it.

Five named detection classes. The agencies direct defenders to hunt for anomalies across five specific axes, and each is a behaviour rather than an indicator:

  • Anomalous S7comm behaviour: connections from non-engineering workstations, unusual data block access patterns, and write operations outside change windows. The first of those three is the most valuable and the cheapest to implement, because the set of hosts that legitimately speak S7comm to a controller is small, known, and rarely changes.
  • Reconnaissance indicators: sequential IP scanning on port 102, repeated connection attempts with varying parameters, and enumeration of CPU properties.
  • Tool artefacts: use of the Snap7 library outside approved engineering workstations, Python scripts with S7comm functionality, and unauthorised monitoring-software installations. This is the detection counterpart to the tooling the earlier entry described: the same libraries that make the attacker's scripts work are the ones whose presence on an unexpected host is the signal.
  • Temporal anomalies: S7comm activity out of hours, connection patterns consistent with automated scripting rather than human operators, and configuration changes with no corresponding work order or change ticket.
  • Geographic anomalies: connections from countries or address ranges not associated with vendors or integrators.

The hardening sequence, in the order the agencies put it. First, an immediate inventory of all Siemens S7 Series PLCs: verify current firmware on every S7-200, S7-300, S7-400, S7-1200 and S7-1500 controller against a backup gold copy, identify any system directly or indirectly accessible from untrusted networks, and map all engineering workstations with TIA Portal, STEP 7 or S7 programming access. Second, patch as soon as possible, prioritising internet-facing or DMZ-resident controllers, bringing TIA Portal and STEP 7 to current versions, consulting Siemens ProductCERT advisories for known vulnerabilities and their workarounds, and testing every update in a development environment before production. Beyond that the advisory calls for ensuring PLCs are not reachable from the internet, strengthening access controls, monitoring for unauthorised activity, and hardening PLC services, including setting write protection and read/write protection levels on the devices themselves.

The instruction that is easiest to overlook is aimed at the supply chain: entities that rely on systems integrators or third-party managed service providers should share the advisory with those parties and request implementation of the mitigations. For a public-sector operator whose OT estate is maintained under contract, that is the action item, because none of the hardening above happens without the integrator doing it.

Triage: the discriminator running through all five detection classes is which host is speaking, when, and with what tooling, not the S7comm protocol itself, which is exactly what an engineering workstation is supposed to use. A programming session from an approved workstation inside a change window, matching a work order, is normal; the same protocol from a host with no engineering role, or outside a change window, or without a corresponding ticket, is the signal. The gold-copy firmware comparison is the one check that speaks to whether something has already happened rather than whether it is happening now.

Builds on: 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · 2026-08-13/cve-2026-58115-simatic-iot2050-node-red-unauth-root

threat20 Aug 06:48Zsingle-source · national CERTOpen finding ↗

2026-07-29 · view entry permalink →

HIGHexploitedupdatedNATOB1

Coordinated two-day cyberattack disrupts operational technology at 30+ Minnesota water and wastewater utilities; no authority has attributed it

The confirmed facts are narrow and worth stating precisely. Minnesota's technology bureau announced on 2026-07-28 that more than 30 communities had their water and wastewater utilities disrupted by a coordinated cyberattack on 26 and 27 July (StateScoop, 2026-07-28), a two-day event rather than a single-utility incident (Cybersecurity Dive, 2026-07-28). Where individual utilities described impact, it fell on field equipment rather than treatment processes: Plymouth stated the attack was limited to equipment connected via cellular communications at two water towers and multiple lift stations, and disconnected that equipment from the network to stop the attack and avoid retargeting during reconfiguration; Braham's water plant went offline, and the city later stated the outage was the result of a malicious cyberattack of computerised operating systems by unknown actors (StateScoop, 2026-07-28). Braham did ask residents to minimise water use while its tower held a limited quantity, and a later notice reported the plant back online (StateScoop, 2026-07-28), a real if temporary consumption instruction. Separately, authorities in South St. Paul said they identified a cyberattack on Monday that impacted certain automated controls, and after implementing contingency procedures confirmed no major impact to drinking and wastewater treatment operations (Cybersecurity Dive, 2026-07-28). Multiple utilities stated water remained safe and no treatment-quality impact has been reported. Minnesota IT Services coordinated a response alongside the FBI, CISA and the EPA, with its chief information security officer describing a whole-of-government response that helped prevent more serious impacts (StateScoop, 2026-07-28).

What is not established matters as much. No authority has named an actor. The Center for Internet Security's senior director of threat intelligence stated the Minnesota attacks have not yet been attributed to any particular party and that it is unclear whether the programmable logic controllers CISA had warned about were involved, and separately noted that of the nation-state attacks on US water facilities in recent years, none has documented major downstream health impacts (StateScoop, 2026-07-28). The FBI confirmed only that it is aware and in contact with victims (Cybersecurity Dive, 2026-07-28). The reason Iran appears in coverage of this event is timing: the attack landed days after federal officials warned of state-linked groups targeting a wider set of industrial devices (Cybersecurity Dive, 2026-07-28), a juxtaposition, not a finding. Treating it as attribution would be reading the calendar as evidence.

The transferable content sits in that separate advisory, and it is why this belongs in front of European water and energy operators despite the victims being American. AA26-097A documents actors using leased third-party infrastructure and the vendors' own engineering software (Rockwell Studio 5000 Logix Designer, Schneider EcoStruxure Control Expert, Siemens TIA Portal) to reach misconfigured, internet-facing controllers and pull down device project files, then re-upload files with modified or deleted logic (CISA and partners, 2026-07-22). At one victim the FBI observed a malicious project file downloaded to a PLC that retained ladder logic for downstream function but added logic overriding the instruction sets responsible for maintaining safe operating parameters, and the changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators (CISA and partners, 2026-07-22). CISA is explicit that this represents no new vulnerability in the named products; it is opportunistic targeting of misconfiguration. The affected controller families are the same Rockwell, Schneider and Siemens lines that run European water, wastewater and district-energy plants, and in one instance access came through Dropbear SSH on a victim's modem, which is precisely the class of device Plymouth found affected.

Triage: engineering software connecting to a PLC and writing a project file is exactly what commissioning and maintenance look like, so the activity class is not the signal. The discriminators the advisory's own mechanics supply are provenance and timing: a project-file write originating from outside the engineering network or from leased hosting rather than an engineering workstation; a controller left in program or remote mode outside a change window rather than in RUN; and a logic change with no corresponding maintenance record. On the network side, protocol functions that modify programs or change controller mode are the ones to surface; connection attempts to controller-associated ports are ubiquitous background noise, whereas a mode change or program write is a discrete, auditable act.

Analysis indicated the project file retained ladder logic for downstream function but added logic that overrode specific instruction sets responsible for maintaining safe operating parameters in the victim's environment.

the changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators of the anomalies.

CISA, FBI, NSA, EPA, DOE, CNMF and Treasury (joint advisory AA26-097A) 2026-07-22

The two-day attack comes days after federal officials warned of state-linked threat groups targeting a wider set of industrial devices.

Cybersecurity Dive 2026-07-28

Since 27 July 2026, Water and Wastewater Sector (WWS) utility companies in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations.

After remotely accessing internet-facing devices, the actors changed the IP addresses and passwords, resulting in a loss of monitoring and control functionality.

At least one organization reported modified PLC project files after noticing ladder logic discrepancies across several sites.

FBI and EPA (joint Public Service Announcement) 2026-07-30

Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses. This activity has resulted in boil water notices and sustained manual operations.

CISA (with EPA and FBI) 2026-07-30

Censys ARC identified 4,117 Internet-exposed hosts that fingerprint as Siemens SIMATIC S7-1200. Exposure concentrates heavily in southern and central Europe: Greece, Spain, Italy, and Austria together account for 86.0% of the total, each dominated by that country's leading mobile carrier rather than fixed-line or hosting providers.

Censys Research 2026-07-30

After the devices are accessed remotely, the actors change the passwords and remove the ability of officials to monitor and control the devices.

The Record (Recorded Future News) 2026-08-05

caused reduced water pressure in parts of the county

the CCWA issued a precautionary boil water advisory as a safety measure

CBS News Atlanta 2026-08-04

federal agencies have declined to publicly attribute the attacks

The Record (Recorded Future News) 2026-08-05

Querying the Shodan search engine on August 3, 2026 returns 4,407 devices exposing port 44818.

Although we cannot confirm these particular assets were compromised in this campaign, they had some interesting characteristics

19 of the 22 hosts (86%) were on the same mobile carrier network, connected via cellular routers

Exposing EtherNet/IP to the internet creates an unauthenticated path that, depending on device configuration, can allow attackers to obtain information about exposed assets or even write configurations on them.

Forescout 2026-08-05

We're seeing things like [programmable logic controllers] that are open and accessible on the internet with either no password set or default password set

For us, we're not doing anything with attribution right now

Nextgov/FCW 2026-08-06
Updaterun 2026-08-01T0409Z-intelactionsaffected_productsevidenceregionssourcestagstechniquesbody

The coordinated attack on Minnesota water utilities is now the visible part of a wider campaign, and three federal bodies have put names and mechanics to what was previously an unattributed disruption with an unclear vector.

The FBI and EPA issued a joint Public Service Announcement on 2026-07-30 stating that "since 27 July 2026, Water and Wastewater Sector (WWS) utility companies in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations" (FBI and EPA, 2026-07-30). The same announcement names the targeted hardware as Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series controllers, while cautioning that "while the FBI has only observed this behavior with the referenced Rockwell PLCs, similar considerations should also be made with other branded PLCs" (FBI and EPA, 2026-07-30). The prior entry recorded the vector as an open question; the announcement closes it: "after remotely accessing internet-facing devices, the actors changed the IP addresses and passwords, resulting in a loss of monitoring and control functionality" (FBI and EPA, 2026-07-30). No CVE is involved; the access is unauthenticated exposure plus credential control, not a software flaw.

Two details go beyond the disruption itself. First, integrity: "at least one organization reported modified PLC project files after noticing ladder logic discrepancies across several sites" (FBI and EPA, 2026-07-30), meaning at least one operator's control logic, not just its access, was touched. Second, a shared-supplier multiplier: the FBI notes that "across several victims, similarities in network setup provided by third parties may provide MCA the opportunity to multiply successes when vulnerable network and hardware setups exist across customers" (FBI and EPA, 2026-07-30). CISA's parallel alert adds the consequence at sector scale, stating the activity "has resulted in boil water notices and sustained manual operations", and singles out cellular modems installed by operators, vendors or system integrators as a common blind spot because those connections may be undocumented and excluded from routine attack-surface scans (CISA, 2026-07-30). On the physical side, the FBI records that reported operational effects "have included loss of pressure and flooding", and that "pressure loss in water systems could potentially allow untreated ground water to seep into pipes" (FBI and EPA, 2026-07-30).

The European relevance is now quantified rather than assumed. A Censys internet scan dated 2026-07-30 found 4,148 exposed Rockwell/Allen-Bradley EtherNet/IP hosts, 71.0% of them in the United States, with combined cellular carriers accounting for 59.0% of that total, but also 4,117 hosts fingerprinting as Siemens SIMATIC S7-1200, where "exposure concentrates heavily in southern and central Europe: Greece, Spain, Italy, and Austria together account for 86.0% of the total, each dominated by that country's leading mobile carrier rather than fixed-line or hosting providers" (Censys Research, 2026-07-30). That carrier concentration is the same cellular-modem exposure class CISA flags as the routinely-unscanned blind spot, sitting on a different vendor's controllers in EU member states. Censys also counts 2,072 hosts fingerprinting as Schneider Electric hardware but states explicitly that this query "has no PLC-model or protocol filter" and "should not be read as Schneider Electric PLC exposure specifically" (Censys Research, 2026-07-30). The whole scan is framed as "an exposure characterization only: it does not confirm that any specific host is a victim of the activity CISA describes" (Censys Research, 2026-07-30).

Attribution is not merely open; the investigating bodies have declined to offer one. SecurityWeek, relaying the Associated Press, reports that the FBI "has not publicly identified a culprit and a spokesperson declined to say Thursday who the bureau thought might be responsible", and that "Minnesota IT Services said state officials had yet to identify who was behind the attacks" (SecurityWeek / AP, 2026-07-31). Neither the FBI/EPA announcement nor the CISA alert names an actor. The Iran framing in circulation has two separate origins, neither of which is an attribution of this activity: a prior multi-agency advisory warning that Iranian actors target the water and wastewater sector generally, the advisory tracked as AA26-097A, which this pipeline covered on 2026-07-24 and which the Censys report cited here names in its own subtitle (Censys Research, 2026-07-30), and an outside expert quoted by the same AP report, a former FBI cyber deputy assistant director now in the private sector, advising defenders to "treat it like it's Iran until proven otherwise" (SecurityWeek / AP, 2026-07-31). BleepingComputer's account of the CISA alert likewise names no actor (BleepingComputer, 2026-07-31). This entry carries no attribution and registers no actor entity.

Triage: an engineer legitimately changes a controller's IP address and sets a password during commissioning or a modem swap, so the events themselves are not the signal. The discriminators are provenance and sequence: the change arrives from outside the engineering-workstation address range or over the cellular path rather than the engineering VLAN, it lands outside a change window with no corresponding work order, and the password set is one operations cannot subsequently authenticate with, a lockout rather than a rotation. A project-file or ladder-logic checksum that moves without a matching download record from a known engineering host is the higher-confidence version of the same test, and the FBI's account of discrepancies noticed "across several sites" suggests comparing logic across a fleet rather than device by device.

Updaterun 2026-08-06T0411Z-intelevidencesourcesbody

Two things changed in the week since the FBI and EPA confirmed water and wastewater utilities in at least seven US states had reported programmable-logic-controller lockouts. The count has grown; water utilities in at least twelve states have now reported cyberattacks on their operational technology, with South Dakota and Georgia announcing incidents and several facilities in Michigan among those remediating, a figure originating with ABC News and relayed by The Record (The Record, 2026-08-05); SecurityWeek reports the same expansion and names Georgia's confirmation as following a pump-station disruption (SecurityWeek, 2026-08-05).

More useful than the count is the second change: a named utility has publicly confirmed a distribution-side consequence as its own. Clayton County Water Authority believes unauthorised cyber activity may have affected its systems in late July, and the incident caused reduced water pressure in parts of the county; the authority issued a precautionary boil-water advisory as a safety measure, and service was restored within hours once testing determined the water was safe (CBS News Atlanta, 2026-08-04). Consequences of that class were not new to the wave; the FBI has said some affected water systems experienced pressure loss and flooding as a result of the activity (CBS News Atlanta, 2026-08-04), and the original entry already carried CISA's statement that it had produced boil-water notices and sustained manual operations. What changes is attribution: those effects were previously federal aggregate reporting, and this is a single identified operator describing what happened on its own network, which is a materially different evidentiary object for anyone arguing an exposure case internally.

The mechanism is unchanged and remains the reason this belongs in a European brief. The FBI's description is that after the devices are accessed remotely, the actors change the passwords and remove the ability of officials to monitor and control the devices (The Record, 2026-08-05). There is no vulnerability in the chain, so there is nothing to patch: the entry condition is reachability plus control of a credential, which is exactly the condition the Censys scan cited in the original entry quantified for Europe, thousands of internet-exposed controllers concentrated in a handful of EU countries and reached predominantly through mobile-carrier connectivity rather than corporate address space. Attribution remains open: federal agencies have declined to publicly attribute the attacks, and no authority has tied the Clayton County incident to any actor (The Record, 2026-08-05).

Updaterun 2026-08-10T0411Z-intelevidencesourcestagsbody

The water-sector controller-lockout campaign has been tracked here through its growth to at least twelve US states and the FBI's naming of the targeted controller families. What was missing was a measurement of the exposed estate. Forescout has now published one (Forescout, 2026-08-05).

"Querying the Shodan search engine on August 3, 2026 returns 4,407 devices exposing port 44818", the EtherNet/IP engineering protocol used by the Rockwell Automation and Allen-Bradley families the joint federal advisory named. "The vast majority (65%) are located in the U.S., followed by Canada (12%) and Spain (3%)." Forescout also notes the exposed population has fallen substantially from its 2020 peak, so the trend is downward even as the absolute number stays material.

The finding worth carrying into a European estate is not the headline count but what Forescout found inside it. Of the devices located in cities the campaign targeted, "Although we cannot confirm these particular assets were compromised in this campaign, they had some interesting characteristics", and the first of those is that "19 of the 22 hosts (86%) were on the same mobile carrier network, connected via cellular routers." That is a connectivity path, not an IT-network path: controllers reachable through a mobile carrier do not appear in a scan of an organisation's own address space, do not sit behind its perimeter, and are frequently owned operationally by an integrator rather than by the utility. Separately, and confusingly sharing the same ratio, "Approximately 86% (19 of 22) hosts observed in the affected cities were susceptible to this CVE based on firmware versions", referring to CVE-2017-16740, which Forescout names but does not describe further. These are two different observations about the same 22 devices and should not be read as one.

Forescout is careful about what that CVE means here, and the care is worth preserving: "Exploitation would require Modbus TCP to be enabled, which was not confirmed", and "There is no confirmation of any CVE exploited in this campaign". The vulnerability is a patch-currency signal on devices that were already exposed and already targeted; the point being that controllers left on the public internet in attacked cities were also running eight-year-old firmware. The exposure itself needs no vulnerability at all: "Exposing EtherNet/IP to the internet creates an unauthenticated path that, depending on device configuration, can allow attackers to obtain information about exposed assets or even write configurations on them."

CISA's acting director, interviewed on the sidelines of Black Hat, described what the agency keeps finding: "We're seeing things like [programmable logic controllers] that are open and accessible on the internet with either no password set or default password set" (Nextgov/FCW, 2026-08-06). Asked about attribution he was equally direct ("For us, we're not doing anything with attribution right now") with the agency's focus on assisting affected operators instead.

Builds on: 2026-07-24/cyberav3ngers-plc-aa26-097a-schneider-siemens-expansion

incident29 Jul 05:45Zmulti-sourceOpen finding ↗

2026-08-09 · view entry permalink →

HIGHNATOA2

CERT Polska: a second Polish CHP plant was shut down on 29 December 2025 through the distribution operator's private APN, the first real-world use of that path into an OT network

CERT Polska published a follow-up analysis on 2026-08-08 of the coordinated 29 December 2025 attacks on Poland's energy sector, adding a victim its January report did not carry: a smaller combined heat and power plant supplying heat to roughly 50,000 residents, whose industrial control systems came under attack at about 07:00 that morning (CERT Polska, 2026-08-08). The analysis took more than three months, which is why the case was held back from the initial report published on 30 January 2026 (CERT Polska, 2026-08-08). The head of CERT Polska, Marcin Dudek, presented the case at DEF CON in parallel with publication (CERT Polska, 2026-08-08). The report carries no actor attribution.

The finding that generalises beyond Poland is the access path. Substations that connect renewable generation to the distribution grid commonly carry cellular routers whose SIM cards sit in a private APN, a carrier-operated private mobile network the distribution system operator uses to reach the remote terminal unit at each site, in this case over DNP3.0 (CERT Polska, 2026-08-08). The operator's requirements covered the serial path to the RTU but said nothing about the router's own administrative interface, so the Teltonika RUTX50 at the compromised wind farm sat with its serial link to the RTU on one interface and an Ethernet link into a VLAN behind the already-compromised central firewall on the other (CERT Polska, 2026-08-08). CERT Polska states this is the first instance it knows of in which a private APN was the route into an OT network, made possible by a configuration that let arbitrary devices inside the APN talk to one another, a configuration its surveys found common in Poland and which it believes is widely deployed in other countries (CERT Polska, 2026-08-08).

The chain ran as follows. Every compromised wind-farm substation in the original wave (more than 30 grid connection points) used a FortiGate as both VPN concentrator and firewall, with the VPN interface reachable from the internet and accepting accounts defined on the device itself without multi-factor authentication; the attacker held administrative privileges on the device and likely used them to obtain a VPN account with reach across all network segments (CERT Polska, 2026-08-08). From inside, the attacker logged into the Teltonika router over SSH repeatedly during December 2025 and tunnelled from it into the private APN; how the router password was obtained could not be determined, and whether a flaw in the device was used is likewise unresolved (CERT Polska, 2026-08-08). From 18 December the attacker scanned the APN for VNC and HTTP services and for the S7 and Modbus industrial protocols, and found a WAGO PFC200 controller exposing a web administration interface on its WAN side, reachable from the APN and still on the default credentials for the admin account; SSH was not enabled on that interface by default, and the sequence in the carrier's logs indicates the attacker enabled it through the web interface before tunnelling onward into the heat plant's OT network, to which the controller had connectivity for both the SCADA systems and the segments holding process-control devices (CERT Polska, 2026-08-08).

Reconnaissance inside the plant ran from 18 to 25 December. Repeated attempts to reach the firewall's LAN-side web interface using the account names admin, user and a username belonging to the company that deploys telecontrol systems at renewable sites all failed, and were retried three days later without success (CERT Polska, 2026-08-08). On Sunday 21 December, eight days before the attack, the attacker scanned for S7 on 102/TCP, Modbus on 502/TCP, CODESYS on 11740/TCP and RTSP on 554/TCP alongside RDP, VNC and web services, and in one subnet the scan began at the address of the SCADA system itself, which CERT Polska reads as evidence of earlier reconnaissance having already identified the high-value targets (CERT Polska, 2026-08-08). On Christmas Day the attacker established successful S7 connections to three Siemens PLCs, most plausibly to prepare the destructive step (CERT Polska, 2026-08-08).

On 29 December activity inside the plant network ran from about 05:30 to about 10:10, meaning the operator's recovery work beginning around 07:30 started while the attacker was still present (CERT Polska, 2026-08-08). The first action after tunnelling through the WAGO controller was to open the SCADA server's web interface, then reach an S7-300 over the S7 protocol, repeating the sequence against an S7-1200 and an S7-1500 (CERT Polska, 2026-08-08). According to statements from plant personnel the PLCs were switched to STOP mode and protected with a password blocking both operating-state changes and control-logic modification, shutting down the steam turbine and the process-water treatment system and interrupting cogeneration; prompt operator response held it to a short outage with no interruption to customer heat or electricity supply (CERT Polska, 2026-08-08). The attacker also reconfigured seven Moxa serial device servers and three Moxa switches (factory reset, password changed, addresses moved to unreachable values such as 127.0.0.1) and the timing of the HTTP requests supports a high-confidence assessment that this was automated (CERT Polska, 2026-08-08). Connections to two ABB ACS variable frequency drives were observed with no determinable effect, and attempts against Schneider Electric ATV 6xx drives failed because the attacker targeted 80/TCP while those interfaces listened elsewhere (CERT Polska, 2026-08-08).

Two recovery lessons sit in the anti-forensics. The attacker corrupted the partition table of the WAGO controller used as the gateway, and the operator's own factory reset did not repair it, leaving the device unbootable and its logs unrecoverable; the Teltonika router was factory-reset about thirty minutes after the last plant activity and its address set to 127.0.0.1, and the FortiGate was factory-reset last of all, destroying the logs from the initial entry point (CERT Polska, 2026-08-08). The investigation only recovered router evidence because RutOS versions before 7.07 keep the event database through a factory reset (CERT Polska, 2026-08-08). On the plant side, restoring the Siemens controllers to factory settings and reloading logic backups shortened the outage but deleted the controllers' own logs, and Siemens ProductCERT confirmed they could not be recovered (CERT Polska, 2026-08-08).

Triage: an engineering contractor doing legitimate remote maintenance also logs into a cellular router and reaches PLCs over S7, so neither event alone separates the two. The discriminators here are direction and sequence, the session enters from the APN side of a device whose administrative interface was never meant to face it, port scanning precedes the PLC access by days, and the run-state change is followed within minutes by configuration writes to unrelated serial servers and switches. This plant's operators initially read the shutdown as contractor error during scheduled maintenance and reported it for information only; CERT Polska opened an investigation anyway because it knew of similar events, which is what turned an unexplained failure into a confirmed intrusion (CERT Polska, 2026-08-08).

To the best of our knowledge, the use of a private APN to gain access to the OT network was the first instance of this attack vector being observed in a real-world cyberattack.

The attack was made possible, among other factors, by a misconfiguration that allowed arbitrary devices within the private APN network to communicate with one another.

Surveys conducted among organizations using similar solutions indicated that this configuration was commonly encountered in Poland.

CERT Polska (NASK) 2026-08-08
incident09 Aug 04:42Zsingle-source · national CERTOpen finding ↗