Blog

CISA Update on PLCs and Iranian Hackers

Written by Bola Ogbara | Jul 31, 2026, 12:40:44 PM

News of coordinated cyberattacks on Minnesotan water systems comes shortly after an updated CISA advisory on PLCs being targeted by Iranian hackers. 

On July 22nd, 2026 several US government agencies teamed up to release an update to a previous Cybersecurity Advisory. Originally published on April 7th, 2026, the advisory “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure”, was updated by the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Environmental Protection Agency (EPA). The original advisory centered on Iranian-affiliated advanced persistent threat actors (APTs) actors exploiting operational technology (OT) devices connected to the internet. That version was a response to programmable logic controllers (PLCs) in several U.S.critical infrastructure sectors, like water and waste management services, energy, along with government services and facilities being disrupted by Iranian APTs in a series of incidents that started in March 6th, 2026.

The original report attributes the escalation of such attacks to “hostilities between Iran, and the United States and Israel.” This is hard to overstate; Iran had long been considered one of the US’ top cyber threats, featuring in the ODNI’s annual threat assessment even before the war. The US - Israel war on Israel, which started on February 28th, 2026 with initial attacks by the US and Israel has been a cyber-enabled war since its inception. In the press conferences following the start of the war, cyber operations in tandem with space operations were key to disrupting and confusing their targets. This admission was monumental and considered “what may be the most public acknowledgement of [the Pentagon’s] cyber operations capabilities to date”, although it followed the global trend of the cyber domain being a significant ground for warfare. Following the initial attacks, Iran-affiliated hackers have responded in turn with their own cyber attacks on Israel and the US. More recently, Iranian cyberattacks have reportedly been used to track US military personnel devices.

 

The April advisory came after PLC disruptions led to operational difficulties and financial losses. Then, CISA, EPA, the FBI and the US Cyber Command recommended that PLCs should be removed from immediate internet exposure through use of a firewall and secure gateway, and switched over from physical mode to run position (the latter of which are specifications if they were Rockwell Automation devices). The agencies also released a list of indicators of compromise (IOCs) and encouraged cyber analysts and engineers in critical infrastructure organizations to search logs for the IOC’s, along with suspicious traffic connected with OT devices or foreign hosting providers. The advisory provided plenty of information for a consistent period of time - but recent incidents in critical infrastructure have likely pushed these same agencies to republish the advisory.

 

Less than a week after the update to the advisory, Minnesota water systems were targeted in a coordinated attack on OT. Since the intrusion was discovered early on July 27th, staff have been working to restore automated operations in the 30+ affected community systems. The attacks started on Sunday and continued over two days, sparking coordination at the state and federal level. CISA, along with the FBI and the EPA, have been working with local utilities to support the recovery process. Fortunately the attack did not directly affect residents, as officials reported: “Drinking water remains safe, water and wastewater services remain fully operational, and no action is required from residents.”

 

Still, the attack has sparked concern about state capabilities in the face of attacks on critical infrastructure. On X, the mayor of Braham, Minnesota, Nate George, commented on the situation: “This attack on critical public infrastructure should be a warning to policymakers in St. Paul. Minnesota’s local governments are expected to defend essential systems against foreign adversaries and sophisticated criminals, often with limited staff, aging technology and inadequate resources. Fortunately, Braham was prepared.”

 

The incident has moved CISA, the FBI, and EPA to act again, with all three parties contributing to an alert issued on July 30th, 2026. There, CISA acknowledges the Minnesota attacks and stresses the importance of mitigating the risk: “CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible…Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans. OT assets exposed to the internet have an increased risk of defacement, configuration changes, operational disruptions, and, in severe cases, physical damage.”

 

The recommendations issued in the alert are consistent with those in both editions of the cybersecurity advisory, as the updated mitigations are to 1) review PLC manufacturer’s previously issued guidance to ensure security of OT deployments, 2) strictly control network access to PLC devices, 3 ) validate project files running PLCs for unauthorized changes and 4) ensure service providers are informed of active threats targeting internet-connected PLC devices. The alert emphasizes the need to update passwords, be careful about remote access to critical OT assets, and stop any direct internet access to PLCs.

 

The timing of the cyberattacks on the water systems in Minnesota suggests that CISA was not overemphasizing the need for action. In the July 22nd advisory, Acting Executive Assistant Director for Cybersecurity, Chris Butera explained that “CISA has consistently warned critical infrastructure stakeholders that Iranian-affiliated threat actors are conducting a range of targeted cyber activity to… compromise unsecure internet-connected accounts and devices. CISA and our partners urge organizations to review this updated advisory and implement recommended actions to protect against this Iranian-affiliated threat activity.” Between CISA insistence on the recommendations and the prominent example of a PLC-related attack on critical infrastructure, cybersecurity staff in critical infrastructure are hopefully running to secure their PLCs.