Full Report
The observed incidents include “malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays,” the advisory says.
Analysis Summary
# Incident Report: Iranian-Linked Targeting of Critical Infrastructure OT/ICS
## Executive Summary
Affiliates of the Iranian regime have expanded their targeting of internet-facing Operational Technology (OT) and Programmable Logic Controllers (PLCs) across multiple manufacturers including Schneider Electric and Siemens. The campaign involves the manipulation of HMI/SCADA displays and malicious project file interactions, resulting in operational disruptions and financial losses for critical infrastructure sectors. Federal agencies (CISA, FBI, EPA) have issued an expanded warning as these state-sponsored activities are expected to continue amidst escalating geopolitical tensions.
## Incident Details
- **Discovery Date:** Initial alert April 2026; expanded advisory July 22, 2026
- **Incident Date:** Ongoing (2026)
- **Affected Organization:** Multiple (Unspecified)
- **Sector:** Critical Infrastructure (Power Utilities, Wastewater Treatment, Manufacturing)
- **Geography:** United States (Primary focused)
## Timeline of Events
### Initial Access
- **Date/Time:** April 2026 (Initial reporting phase)
- **Vector:** Exploitation of internet-facing OT devices and PLCs.
- **Details:** Attackers targeted devices left exposed to the public internet, specifically focusing on those with weak or default security configurations.
### Lateral Movement
- **Details:** The report notes "malicious project file interactions," suggesting attackers may move from initial access points to modify the logic and configuration files that control industrial processes.
### Data Exfiltration/Impact
- **Details:** Manipulation of Human Machine Interface (HMI) and SCADA displays to provide false information to operators or disrupt physical processes. Organizations reported operational downtime and associated financial recovery costs.
### Detection & Response
- **How it was discovered:** Observed active targeting by CISA and the FBI across multiple industrial environment victims.
- **Response actions taken:** CISA, FBI, and EPA issued a joint revised cybersecurity advisory (AA26-097a) to broaden the scope of affected hardware.
## Attack Methodology
- **Initial Access:** Exploiting direct internet connectivity of PLCs/OT assets.
- **Persistence:** Not explicitly detail, but typically achieved through modified project files or backdoored firmware.
- **Defense Evasion:** Use of proxies, "hacktivist" personas as cover, or leveraging ransomware gangs to mask state-sponsored attribution.
- **Discovery:** Scanning for internet-connected industrial hardware (e.g., Schneider Electric, Siemens, Rockwell Automation).
- **Impact:** Manipulation of SCADA/HMI displays and operational disruption of physical machinery.
## Impact Assessment
- **Financial:** Reported financial losses due to remediation and operational downtime.
- **Data Breach:** Compromise of proprietary "project files" and industrial logic.
- **Operational:** Disruption to essential services such as water treatment and power generation.
- **Reputational:** Public concern regarding the security of critical national infrastructure.
## Indicators of Compromise
- **Network indicators:** Direct connections to OT ports (e.g., Port 502 for Modbus, Port 44818/2222 for EtherNet/IP) from unauthorized or foreign IP addresses.
- **File indicators:** Unauthorized changes to PLC project files or logic configurations.
- **Behavioral indicators:** Unusual login activity on HMI panels; discrepancies between physical sensor data and SCADA display values.
## Response Actions
- **Containment measures:** Isolation of OT networks from the public internet.
- **Eradication steps:** Reverting PLCs to known-good project file baselines and changing all administrative passwords.
- **Recovery actions:** Implementation of hardened security configurations as per CISA/EPA guidelines.
## Lessons Learned
- **Key takeaways:** Critical infrastructure remains a primary target for asymmetric warfare by nation-states. Relying on "security through obscurity" or assuming OT is "air-gapped" when it is actually internet-facing is a catastrophic failure.
- **What could have been done better:** Earlier identification of internet-exposed assets using attack surface management tools could have prevented initial access.
## Recommendations
- **Restrict Connectivity:** Immediately remove all PLCs and OT hardware from the public-facing internet.
- **Secure Remote Access:** Use VPNs with Multi-Factor Authentication (MFA) if remote access is strictly required.
- **Password Hygiene:** Change all default vendor passwords on Schneider, Siemens, and Rockwell devices.
- **Integrity Checks:** Regularly verify the checksums of PLC project files to ensure no unauthorized logic changes have been made.