Iranian State Actors Are Disabling U.S. Critical Infrastructure Safety Systems
CISA, FBI, EPA, and U.S. government partners issued updated advisory AA26-097A on July 22, 2026: Iranian-affiliated APT actors are actively targeting internet-facing programmable logic controllers across U.S. critical infrastructure sectors including water and wastewater systems, energy, government facilities, and municipalities.
Targeted PLCs include Rockwell Automation/Allen-Bradley CompactLogix and Micro850, as well as Siemens and Schneider Electric devices. Attackers reach PLCs left open on the internet with default or weak credentials, modify and delete project file logic including Add-On Instructions (AOIs), disable critical shutdown and alarm logic, and feed operators false readings – allowing systems to enter unsafe conditions without operator notification.
The campaign has escalated since at least March 2026, assessed as likely in response to hostilities between Iran, the United States, and Israel. Federal Civilian Executive Branch agencies were ordered to apply fixes by August 1, 2026. That deadline has passed.
This is sabotage preparation, not espionage
Disabling shutdown logic and feeding false sensor data are not reconnaissance moves. They are pre-positioning for destructive attacks.
A PLC controls physical processes – pumps, valves, motors, chemical feeds, temperature regulation. Shutdown logic is the automated safety system that stops a process when sensors detect unsafe conditions: pressure too high, temperature too low, flow rate outside tolerances, chemical concentration dangerous. Alarm logic alerts human operators when something is wrong.
If an attacker disables both and feeds the operator false readings showing everything is normal, the process can enter catastrophic failure conditions without anyone knowing until physical damage occurs. A water treatment plant can overdose chlorine. A power substation can overload transformers. A pipeline can overpressure and rupture.
This is not theft of data. This is preparation to cause physical harm at scale.
The point of failure
U.S. critical infrastructure operators deployed internet-facing PLCs with default or weak credentials, no network segmentation, and no monitoring for unauthorized logic changes. That created a walk-in path for state-sponsored attackers to disable safety systems remotely.
PLCs were never designed to be internet-accessible. They were designed for isolated operational technology networks, physically separated from IT networks and the internet, accessed only by authorized personnel on-site or via secure remote connections with multi-factor authentication and logging.
Operators put them on the internet with default passwords. "admin/admin". "1234". The manufacturer's factory default that every attacker knows. No firewall rules restricting access to specific trusted IP addresses. No intrusion detection monitoring for unauthorized configuration changes. No network segmentation isolating the PLC network from other systems.
The advisory confirms Siemens and Schneider Electric PLCs are now in scope alongside Rockwell/Allen-Bradley. That covers the dominant share of installed ICS equipment in U.S. critical infrastructure. If you operate a water system, an energy facility, or a municipal service, your PLCs are in the target set.
The remediation deadline was August 1
Federal Civilian Executive Branch agencies were ordered to remediate by August 1, 2026. That deadline has passed. Private sector critical infrastructure operators were not given a deadline, but the threat does not care whether you are federal or private.
CISA's recommended mitigations:
– Remove PLCs from direct internet accessibility
– Enforce strong, unique credentials (not default passwords)
– Implement network segmentation isolating OT from IT networks
– Monitor for unauthorized logic changes and configuration modifications
– Require multi-factor authentication for remote access
– Log all access and configuration changes
These are not advanced measures. They are baseline operational security for systems controlling physical infrastructure. The fact that they are being issued as urgent remediation guidance in 2026 means most operators never implemented them.
Iranian-affiliated targeting is escalating
The advisory assesses the campaign as likely in response to hostilities between Iran, the United States, and Israel. Iranian cyber operations have historically been retaliatory and escalatory. The targeting of U.S. critical infrastructure PLCs follows that pattern.
Previous Iranian campaigns targeted IT networks for espionage and data theft. This campaign targets OT networks for sabotage preparation. The shift from espionage to sabotage is a threat escalation, not a lateral move.
The August 1 FCEB remediation deadline signals imminent threat. CISA does not issue binding operational directives with multi-week deadlines unless the threat actor is actively exploiting the vulnerability and the risk of destructive impact is assessed as high.
If you operate critical infrastructure and your PLCs are internet-accessible with weak credentials, you are already compromised or about to be. The question is whether you remediate before the attackers decide to execute the sabotage they have already pre-positioned.
Source: CISA advisory AA26-097A, July 22, 2026