On July 22, 2026, CISA, FBI, NSA, EPA, DOE, CNMF, and Treasury updated joint advisory AA26-097A. The document describes ongoing activity since March 2026: Iran-affiliated APT actors are compromising internet-exposed PLCs in U.S. critical infrastructure. The update was published after a coordinated attack struck more than 30 Minnesota water and wastewater systems on July 26–27.
- Iranian actors use legitimate engineering software (Rockwell Studio 5000, Schneider EcoStruxure, Siemens TIA Portal) to upload malicious project files to internet-exposed PLCs.
- CVE-2021-22681, CVSS 9.8, affects Rockwell Logix controllers; Rockwell has confirmed no patch exists and none is planned.
- Censys detected 5,219 Rockwell/Allen-Bradley hosts exposed globally as of April 2026, of which 3,891 (74.6%) were in the United States.
- The July 22, 2026 advisory expanded scope from Rockwell to Schneider Electric (BMX P34, Modicon M340) and Siemens (S7-1200).
The Mechanism: Legitimate Software as an Attack Vector
The attackers do not use custom malware or zero-days. According to the CISA advisory, they use legitimate copies of PLC configuration software hosted on rented infrastructure abroad. From there they download malicious project files to controllers, modify Add-On Instructions (AOIs), alter HMI/SCADA displays, and disable safety shutdown logic.
In one confirmed victim, the malicious project file preserved downstream ladder logic but added instructions that overwrote safe operating parameters. Operators received no alarms because HMI/SCADA data had been falsified. The result: unsafe physical states masked as normal operations.
The CISA advisory indicates attackers used Dropbear SSH on victim cellular modems for remote access. The source does not specify whether this mechanism was employed in the Minnesota systems.
"Iranian cyber actors continue to target U.S. critical infrastructure, and the FBI is committed to identifying, disrupting, and imposing costs on those responsible" — Brett Leatherman, Assistant Director, FBI Cyber Division
The Unpatchable Vulnerability: CVE-2021-22681
CVE-2021-22681 affects Rockwell Logix controllers and carries a CVSS 3.1 score of 9.8 (critical). According to Tenable Research analysis, the flaw consists of an embedded cryptographic key in Studio 5000 Logix Designer software, enabling impersonation and unauthenticated controller access.
Rockwell Automation has confirmed no patch exists and none is planned. CISA added the flaw to the Known Exploited Vulnerabilities (KEV) catalog following confirmation of in-the-wild exploitation starting March 2026.
For Schneider Electric and Siemens, the July 22, 2026 advisory indicates BMX P34, Modicon M340, and S7-1200 devices are now in the crosshairs. The brief does not establish whether the same CVE-2021-22681 applies or whether attackers use different mechanisms.
The Minnesota Wave: Impact on Water Systems
On July 26–27, 2026, a coordinated attack hit more than 30 Minnesota water and wastewater systems. In Braham, a town of roughly 1,700 residents, the treatment plant was temporarily shut down. In Plymouth, a city of about 80,000, authorities preemptively disconnected the connected cellular apparatus. Maple Plain declared a state of emergency.
Minnesota IT Services (MNIT) confirmed the coordinated attack; the investigation is active. According to Tenable Research assessment, the operational pattern is consistent with the CyberAv3ngers ecosystem. The government advisory uses the generic designation "Iranian-affiliated APT actors" without official attribution to a specific group.
The authoring agencies assess the activity intends to cause disruptive effects in the United States, likely in response to Iran-U.S.-Israel tensions.
"Minnesota's local governments are expected to defend essential systems against foreign adversaries and sophisticated criminals, often with limited staff, aging technology and inadequate resources" — Nate George, Mayor of Braham
Immediate Actions
The July 22, 2026 CISA update includes guidance for critical infrastructure operators:
- Remove PLCs from direct internet exposure; where not possible, enforce rigid network segmentation between OT and IT.
- Verify project files for detection of maliciously modified AOIs, per the new CISA guidance published in the update.
- Consult the STIX XML and JSON files published by CISA, which contain 22 IPv4 indicators with actor-association timeframes from January 2025 through July 2026, mapped to MITRE ATT&CK techniques T0883, T0885, T1041, T1219, T1565.
What We Don't Know
The brief leaves several points open. It is not established whether data exfiltration occurred in the Minnesota systems. It is not confirmed whether attackers caused physical damage or only operational disruption. It is not known whether Schneider and Siemens were hit via the same CVE-2021-22681 or through different vulnerabilities. No official government attribution to a specific group has been announced.
The Big Picture
The July 22, 2026 update is not a preventive advisory but a document on activity ongoing for months. The Minnesota attack occurred after the update's publication, demonstrating the campaign continues. The combination of an unpatchable vulnerability, legitimate software as a vector, and small targets with limited resources makes this threat particularly difficult to counter with traditional measures.
Sources
- CISA Advisory AA26-097A
- CISA/FBI/EPA Update Warning
- CybersecurityNews - Technical Details
- TechTimes - Minnesota Incident Details
- CybersecurityDive - Government Context
- TechCrunch - Broader Campaign
- CISA STIX XML IOCs
- CISA STIX JSON IOCs
Information verified against cited sources and current as of publication.
Sources
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a
- https://www.cisa.gov/news-events/news/cisa-fbi-epa-and-us-government-partners-update-warning-iran-affiliated-threat-actors-targeting
- https://cybersecuritynews.com/iran-hackers-exploit-rockwell-plcs/
- https://www.techtimes.com/articles/322059/20260729/iranian-hackers-exploited-unpatchable-plc-flaw-breach-30-minnesota-water-systems.htm
- https://www.cybersecuritydive.com/news/cisa-fbi-iran-hackers-target-water-energy/826025/
- https://techcrunch.com/2026/07/23/us-government-says-iran-linked-hackers-are-disrupting-american-water-and-energy-providers/
- https://www.cisa.gov/sites/default/files/2026-07/AA26-097A.stix_.xml
- https://www.cisa.gov/sites/default/files/2026-07/AA26-097A.stix_.json
- https://www.cisa.gov/news-events/news/cisa-fbi-epa-and-us-government-partners-update-warning-iran-affiliated-threat-actors-targeting?_sp=6074e05a-75c7-42ea-9891-90f03c0cfe95
- https://www.securityweek.com/cal-water-finds-no-evidence-of-ot-activity-after-hackers-claimed-they-could-disrupt-water-supply/