US agencies expand the Iranian PLC-intrusion advisory (AA26-097A) to Schneider Electric and Siemens controllers, with new project-file tampering detection
Iran-linked PLC intrusions now hit Schneider and Siemens gear; the fix is exposure and integrity checking, not a patch
Defender actions
- Baseline the running logic and Add-On Instructions on any internet-reachable Rockwell, Schneider Modicon M340 or Siemens S7-1200 PLC against a known-good copy, and alert on unauthorised changes; the actors disable shutdown/alarm interlocks so HMI displays mask unsafe states.
Analysis
Seven US federal agencies (CISA, FBI, NSA, EPA, the Department of Energy, US Cyber Command's Cyber National Mission Force and the Treasury) updated joint advisory AA26-097A on 22 July 2026, first published in April 2026 on Iranian-affiliated exploitation of internet-connected, misconfigured programmable logic controllers (CISA, 2026-07-22). The update's substance is a widened scope and new detection guidance: targeting previously centred on Rockwell Automation/Allen-Bradley CompactLogix and Micro850 controllers is now confirmed to include Schneider Electric Modicon M340 and Siemens S7-1200 series controllers, both with large installed bases across European water and energy utilities (CISA News, 2026-07-22). There is no underlying software CVE: the actors scan common ICS ports (44818/2222 EtherNet/IP, 102 Siemens S7comm, 502 Modbus TCP, and 22 for Dropbear SSH on victim modems), then connect using the manufacturers' own engineering software (Rockwell Studio 5000, Schneider EcoStruxure Control Expert, Siemens TIA Portal) run from leased infrastructure with credentials obtained from weakly-protected devices, and pull down device project files (Trend Micro, 2026-07-23). The current campaign manipulates control logic directly and has produced confirmed operational disruption and financial loss: the actors modify or delete PLC logic (including reusable Add-On Instructions) and manipulate HMI/SCADA display data to disable shutdown and alarm logic, letting systems enter unsafe states without operator notification (CISA News, 2026-07-22).
Cited evidence
The Iranian-affiliated activity outlined in this advisory has disrupted PLCs across several U.S. critical infrastructure sectors by attempting to download malicious project files and manipulate data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss for affected organizations.
Review project files running on PLCs for unauthorized changes. Use vendor-provided integrity checking tools and visually compare the running program to known good logic.
Sources3
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.