The FBI, CISA, and six other U.S. federal agencies confirmed on July 22, 2026, that Iranian actors have attacked internet-exposed programmable logic controllers (PLCs), with documented operational impact and financial losses. In the United Kingdom, an alleged intrusion at a power generation plant — reported without official confirmation — fuels tension between media alarm and public evidence.
- Joint advisory AA26-097A (CISA, FBI, NSA, EPA, DOE, CNMF, Treasury) documents Iranian attacks on Rockwell Automation, Schneider Electric, and Siemens PLCs with manipulation of project files and ladder logic.
- The FBI observed at least one U.S. victim where added logic overwrote operational safety parameters in the PLC, causing operational disruption and financial losses.
- The NCSC assessed on March 2, 2026, that Iranian-linked actors have "almost certainly" retained offensive capabilities against industrial control systems (ICS).
- The claim of a four-day blackout at a British power plant remains unconfirmed: no public forensic evidence proves direct manipulation of power generation.
Advisory AA26-097A and the Technical Modus Operandi
The joint advisory AA26-097A, published July 22, 2026, expands the initial scope focused on Rockwell Automation to include Schneider Electric and Siemens. The agencies report active targeting of internet-connected PLCs via mass scanning on specific ports: 44818 (EtherNet/IP), 2222 (CSP), 102 (Siemens S7), 502 (Modbus), and 20256.
Initial access exploits CVE-2021-22681, an authentication bypass vulnerability in Rockwell PLCs with a CVSS score of 9.8 per the official NVD record. Once in control, actors use legitimate engineering tools such as Studio 5000 to modify PLC project files and ladder logic.
Persistence relies on cellular modems and Dropbear SSH tunnels, avoiding custom malware. This "living-off-the-land" pattern makes detection harder for traditional tools: behavioral signatures must distinguish malicious use of native protocols from legitimate operator activity.
HMI Manipulation and Process State Concealment
A distinctive element of the documented campaign is the alteration of human-machine interfaces (HMIs) and SCADA systems to hide or modify the representation of process state. The FBI observed that the project file loaded onto the PLC "maintained the ladder logic for downstream functions but added logic that specifically overwrote instruction sets responsible for maintaining operational safety parameters."
This technique exposes a structural vulnerability in OT supervision: operators rely on HMI visual indications for real-time decisions. If the display shows nominal parameters while the PLC executes anomalous conditions, human detection is neutralized without the need for sophisticated rootkits.
The November 2023 CyberAv3ngers campaign, attributed to the IRGC-CEC and sanctioned by the Treasury in February 2024, compromised at least 75 Unitronics devices in U.S. water infrastructure. The pattern observed then — exposed PLCs, compromised credentials, parameter manipulation — forms the evolutionary baseline for the activity documented in 2026.
The U.K. Picture: Alarm Without Public Evidence
The NCSC, the U.K.'s national cybersecurity center, has expressed specific concern about ICS risks linked to Iran. On March 2, 2026, it assessed that Iranian state and affiliated actors have "almost certainly" retained offensive capabilities against industrial control systems.
On June 17, 2026, NCSC CEO Richard Horne stated that roughly 75% of more than 200 incidents involving U.K. critical national infrastructure in the year to May 2026 were attributed to hostile states, including Iran, Russia, and China.
Against this backdrop, debuglies.com reported an alleged four-day shutdown of an unidentified British power plant, explicitly stating in its analysis that "the reported four-day shutdown of an unidentified British power plant remains officially unconfirmed in public sources." The same source adds: "no public forensic evidence currently demonstrates that power generation, rather than IT or dependent security support operations, was directly manipulated."
The absence of public indicators of compromise, timeline, or forensic attribution for any U.K.-specific incident prevents treating the claim as verified. The distinction matters: the NCSC has warned of the risk, not confirmed the event.
"In some cases, this activity has caused operational disruption and financial losses" — CISA AA26-097A
Why It Matters
The dossier does not document specific mitigations for the Iranian campaign or detailed operational recommendations for critical infrastructure operators. The cited source does not specify whether the NCSC or other U.K. authorities are conducting private investigations into the power plant claim.
The brief does not list public indicators of compromise (IoCs) associated with specific incidents in the United Kingdom, nor explicit firmware versions or patches for the affected PLCs. No compromised supply chain or lateral movement techniques beyond the OT perimeter are documented.
The source does not specify the nature of any data potentially exposed in intrusions, nor whether Iranian actors exfiltrated engineering information or process configurations beyond manipulation of operational parameters. The dossier also does not clarify whether the 2026 campaign represents a quantitative or qualitative escalation over the 2023 CyberAv3ngers activity.
The Lesson of the Gap Between Headline and Evidence
The narrative structure emerging from the dossier is asymmetric: the United States has technical advisories with compromise details, while the United Kingdom has strategic alarms without public forensic correspondence. This asymmetry does not invalidate the severity of the threat, but it conditions operational readability.
British critical infrastructure operators are left managing a risk documented by analogy, not by case identity. The NCSC has provided the threat context (retained capability, state prevalence); confirmation that this capability has been successfully exercised against U.K. electrical targets in the manner reported is missing.
The editorial reading suggests that defensive urgency does not depend on verification of the specific claim. The technical pattern — PLCs exposed on the internet, weak or bypassable credentials, legitimate tools used for unauthorized modifications — is reproducible regardless of confirmation of every single incident. The pertinent question for defenders is not "which plant was hit," but "which OT assets are reachable from the internet and with what attack surface."
FAQ
Does CVE-2021-22681 affect only Rockwell PLCs?
The NVD record identifies CVE-2021-22681 for Rockwell Automation products. The CISA AA26-097A advisory from July 2026 extends observed targeting to Schneider Electric and Siemens, but does not specify additional CVEs for these vendors in the context of the Iranian campaign.
Why does the U.K. claim remain unverifiable?
No technical indicators of compromise, identity of the alleged victim, event timeline, or official statements from NCSC, Ofgem, or DESNZ have been published. The source that reported the claim explicitly declares it unconfirmed.
Do the documented attacks require sophisticated malware?
No. The campaign confirmed by the United States relies on legitimate engineering tools and native protocols. The FBI observed the use of modified project files, not custom malware payloads. This pattern reduces visibility for signature-based defenses.
Information is based on the cited advisory and current as of publication.
Information is based on the cited source and current as of publication.
Sources
- https://debuglies.com/2026/08/23/irans-ot-breach-uk-power-and-scada-exposure/
- https://nhimg.org/community/cybersecurity-beyond-identity/plc-exploitation-and-ot-identity-gaps-are-your-controls-keeping-up
- https://shieldworkz.com/blogs/technical-analysis-of-iranian-cyber-campaigns-targeting-ot-ics-in-water-and-energy-sectors
- https://www.cyfirma.com/research/cyfirma-industry-report-energy-utilities-5/
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a
- https://www.cisa.gov/news-events/alerts/2023/11/28/exploitation-unitronics-plcs-used-water-and-wastewater-systems
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-290a
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-055a
- https://www.cisa.gov/news-events/alerts/2023/11/28/exploitation-unitronics-plcs-used-water-and-wastewater-systems?utm_source=chatgpt.com
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-290a?utm_source=chatgpt.com
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-055a?utm_source=chatgpt.com