Federal and international agencies updated a joint advisory on July 22, warning that Iranian-affiliated hackers are exploiting internet-connected programmable logic controllers (PLCs) across multiple U.S. critical infrastructure sectors.
What happened
On July 22, 2026, the FBI, U.S. Cyber Command's Cyber National Mission Force, and other federal agencies updated a joint advisory warning that Iranian-affiliated hackers are targeting internet-connected PLCs, which are computers that control physical equipment.
The attackers are targeting PLCs made by Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens. Attackers change the settings that control this equipment, disrupting how systems operate. They can also change what staff see on connected screens that display information about the equipment.
The attacks have affected organizations in the Government Services and Facilities, Water and Wastewater Systems, and Energy sectors. In some cases, they caused operational disruptions and financial losses.
The backstory
Agencies first published this advisory in April 2026, warning about attacks targeting Rockwell Automation PLCs. The agencies previously linked similar activity to CyberAv3ngers (also known as Shahid Kaveh Group), a threat actor tied to Iran's Islamic Revolutionary Guard Corps (IRGC) Cyber Electronic Command.
Going deeper
The July update expands the advisory's scope in two ways. First, it broadens the list of targeted manufacturers beyond Rockwell Automation to include Schneider Electric and Siemens, and it flags potential targeting of other branded PLCs. Secondly, it adds new technical guidance for detecting malicious changes within reusable code modules used in Rockwell Automation PLC programs. The agencies also note restricting direct internet access to these devices and point organizations toward best-practice resources for secure deployment.
What was said
The agencies stated they are "urgently warning U.S. organizations of ongoing cyber exploitation of internet-connected OT devices." They urged affected organizations to "engage your cyber incident response plans and contact the authoring agencies and applicable vendors through existing support channels" for support and investigation assistance.
Why it matters
The updated advisory expands the list of affected PLC manufacturers to include Schneider Electric and Siemens, in addition to Rockwell Automation/Allen-Bradley. Consequently, healthcare facilities should not assume they are unaffected simply because they do not use Rockwell equipment.
Healthcare organizations may focus on protecting electronic health records (EHRs) and patient data while overlooking the systems that keep a facility running. For example, a hospital's climate control or door access system may rely on a PLC that is connected to the internet.
If attackers change how a PLC controls equipment or alter the information shown on connected screens, staff may receive incorrect information or physical systems may not operate as expected or potentially create safety concerns.
The bottom line
Healthcare organizations should review whether any PLCs in their facilities are internet-accessible and apply the mitigations in the updated advisory such as restricting direct internet access. Given the expanded manufacturer scope, facilities that assumed they were unaffected because they don't use Rockwell Automation equipment should reassess their systems.
FAQs
What is a programmable logic controller (PLC)?
A PLC is an industrial computer that manages and monitors physical equipment, such as climate control, access control, or manufacturing machinery.
Why would hackers want to target a PLC instead of a computer network?
PLCs control physical processes and equipment, compromising one can cause real-world disruption, not just data theft.
What does it mean for a PLC to be "internet-connected"?
It means the device can be reached and potentially accessed remotely over the internet, rather than being isolated on a private, air-gapped network.
