US Agencies Warn Iranian-Linked Hackers Are Disrupting Water and Energy Providers by Targeting PLCs

The FBI, NSA, Department of Energy, and CISA issued a joint cybersecurity advisory on July 22, 2026, warning that Iranian state-backed hackers are targeting programmable logic controllers (PLCs) on internet-connected operational networks at US water and energy providers. The advisory, designated AA26-097A, states that the actors are manipulating data on PLC displays, causing operational outages and disruption, and that they are conducting this activity specifically to cause disruptive effects within the United States. The Environmental Protection Agency also joined the updated warning, which CISA published on its site alongside a coordinated FBI alert. TechCrunch CISA
The advisory initially focused on Rockwell Automation controllers and was subsequently expanded to include industrial control system products from Schneider Electric and Siemens. The agencies warned that "potentially all internet exposed" industrial control systems may be affected, broadening the scope well beyond the named vendors.
According to the FBI, the hackers breached one critical infrastructure provider and altered the controllers' programming logic to disable processes handling critical shutdowns and alarms. With those safety processes disabled, systems could enter unsafe conditions without notifying operators of anomalies. The advisory does not specify which provider was breached or when the intrusion occurred.
The TechCrunch reporting on the advisory does not name a specific Iranian hacking group responsible for the PLC attacks. A group called "Handala" is mentioned in the article only in connection with separate incidents: a device wipe at Stryker and a data breach at Cal Water. The Department of Justice announced the seizure of domains linked to Handala on April 7, 2026.
This advisory is not the first US government warning about Iranian-affiliated actors exploiting PLCs in critical infrastructure. The FBI published an alert on April 7, 2026, titled "Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure," describing the threat actors as an "Iranian-affiliated advanced persistent threat" group targeting devices spanning multiple US Water and Wastewater Systems. The FBI's Internet Crime Complaint Center (IC3) published a related cybersecurity advisory PDF the same date, and the FBI publicized the warning on its official Facebook page on April 24. FBI
CISA had previously issued advisory AA23-335A, addressing IRGC-affiliated cyber actors exploiting PLCs across multiple sectors, with the most recent update to that advisory dated December 18, 2024. AP News reported as far back as December 2023 that a small western Pennsylvania water authority was among multiple US organizations breached by Iran-affiliated hackers. AP News
The operational pattern described in the July advisory is straightforward in its mechanics and alarming in its implications. The actors are not merely defacing HMI screens or rendering symbolic gestures. By modifying PLC programming logic to disable shutdown and alarm processes, they are removing the last-line-of-defense safety interlocks that operators rely on to detect and respond to anomalous conditions. In a water treatment facility, a silenced alarm on a chemical dosing loop could mean dosing continues past safe thresholds with no operator awareness. In an energy context, the failure of automatic shutdown logic on pressurized or thermal systems carries obvious physical safety consequences.
The attack surface is not narrow. PLCs from three major vendors, Rockwell Automation, Schneider Electric, and Siemens, are explicitly named, and the advisory's language about "potentially all internet exposed" ICS suggests the agencies view the vulnerability class as broader than any single product line. PLCs and other operational technology devices have historically been designed for reliability and ease of remote access, not for authenticated, zero-trust network architectures. Internet-exposed PLCs with default or weak credentials remain common across the water and wastewater sector in particular, where small utilities often lack dedicated cybersecurity staff.
The escalation from initial focus on Rockwell controllers to a multi-vendor scope, combined with the confirmation that at least one provider had its safety logic actively modified, distinguishes this advisory from earlier awareness-level warnings. The April FBI alert framed the threat as exploitation of PLCs across multiple sectors. The July advisory, issued jointly by four agencies plus the EPA, documents a confirmed breach resulting in the disabling of safety-critical processes and characterizes the activity as deliberately intended to cause disruption on US soil.
For operators of water, wastewater, and energy infrastructure, the immediate implications are operational. The advisory's existence at this level of interagency coordination signals that the threat has moved from generalized concern to documented, active exploitation with demonstrated impact on safety systems. Utilities running internet-exposed PLCs from any of the named vendors, or from vendors not yet named, should treat the advisory as a directive to audit external exposure, verify controller programming integrity, and confirm that alarm and shutdown logic has not been tampered with.


