On 22 July 2026, the agencies behind joint advisory AA26-097A issued a substantial update. The original advisory — published 7 April 2026 by the FBI, CISA, NSA, EPA, DOE, and US Cyber Command’s Cyber National Mission Force — warned that Iranian-affiliated APT actors were actively exploiting internet-facing operational technology devices across multiple US critical infrastructure sectors.

The July update makes four changes:

  1. The Department of the Treasury is added as a co-author.
  2. The observed manufacturer scope is broadened to include targeting of Schneider Electric and Siemens programmable logic controllers, alongside other branded and manufactured PLCs.
  3. New detection guidance and mitigations are published.
  4. A refreshed set of indicators of compromise is released.

The agencies state that since at least March 2026, the Iranian-affiliated APT group has disrupted the function of PLCs deployed across a wide variety of industrial automation processes in the Government Services and Facilities, Water and Wastewater Systems, and Energy sectors. Some victims have experienced operational disruption and financial loss. Reported technical impacts include manipulation of data on operator displays, causing outages and disruption.

This is an update to the campaign ComplianceHub covered in April in our analysis of the CyberAv3ngers water and wastewater PLC advisory. Readers who acted on that advisory should treat the July revision as an expansion of scope rather than a new event — and re-run their exposure assessment against the wider manufacturer list.

Read the four changes as a threat-model update

Advisory updates are frequently skimmed. Each of these four changes carries a distinct operational implication.

Treasury’s addition as co-author signals that the response has a financial and sanctions dimension. Treasury co-authorship on a technical advisory typically accompanies, or precedes, designations under the sanctions programmes administered by OFAC. For operators, the practical consequence is in the ransom and extortion path: any payment made to a designated entity or to actors acting on behalf of one carries strict-liability sanctions exposure independent of whether the payer knew. OFAC’s 2020 and 2021 advisories on ransomware payments remain the controlling guidance, and they make clear that mitigating credit attaches to timely reporting to law enforcement and to the existence of a compliance programme. Any critical infrastructure operator without a sanctions screening step embedded in its incident response plan should add one this quarter.

The manufacturer expansion to Schneider and Siemens materially widens the affected population. The April advisory’s narrower scope allowed many operators to conclude, correctly at the time, that their equipment was not implicated. Schneider Electric and Siemens PLCs are ubiquitous across water treatment, power distribution, building automation, and manufacturing. An exposure assessment run in April against the original list must be repeated.

New detection guidance should be operationalised, not filed. The gap between advisory publication and detection engineering is where most of the value is lost.

Refreshed IOCs carry an expiry problem. Indicators are the most perishable form of threat intelligence — infrastructure rotates, hashes change. Refreshed IOCs are worth ingesting immediately and worth deprioritising within weeks in favour of behavioural detection.

The persistent root cause: PLCs reachable from the internet

The advisory’s central emphasis is the one it shared in April, and it has not changed: restrict direct internet access to operational technology.

Internet-exposed PLCs and HMIs are not an exotic misconfiguration. They exist because of an accumulation of reasonable-seeming local decisions: a vendor needed remote support access; a small utility with no on-site engineering staff needed after-hours visibility; a cellular modem was installed for a temporary project and never removed; an integrator’s default configuration was never hardened. In the water sector specifically, thousands of systems serve populations too small to fund a dedicated OT security function.

The consequence is that a threat actor requires no zero-day. Internet-wide scanning identifies exposed devices; default or absent credentials complete the intrusion. The manipulation of operator display data described in the advisory is particularly dangerous because it attacks the operator’s picture of reality — the control room believes the process is nominal while it is not.

Regulatory obligations by sector

Water and wastewater

The America’s Water Infrastructure Act of 2018 (AWIA) § 2013 requires community water systems serving more than 3,300 people to conduct risk and resilience assessments and to prepare or revise emergency response plans, on a recurring five-year cycle. The assessments must address the electronic, computer, and other automated systems the system uses — which is to say, exactly the equipment in this advisory.

The sector’s gap is well documented: EPA lacks the pervasive cybersecurity mandate other sectors have, an attempted sanitary-survey approach was withdrawn following litigation, and the result is that the largest number of exposed assets sits in the sector with the least binding regulation. The EPA and WaterISAC guidance remains advisory. Operators should not read the absence of a mandate as an absence of liability — negligence exposure and state public utility commission oversight both fill part of the gap. Our coverage of the ICO’s £963k fine against South Staffordshire Water illustrates how the equivalent exposure materialises in a jurisdiction that does regulate.

Energy

The NERC CIP standards apply to the bulk electric system and are enforceable with penalties. Several are directly implicated:

  • CIP-005 (Electronic Security Perimeters) — the requirement that external routable connectivity to BES Cyber Systems traverse an identified electronic access point.
  • CIP-007 (Systems Security Management) — ports and services, patch management, malicious code prevention, security event monitoring.
  • CIP-010 (Configuration Change Management and Vulnerability Assessments) — baseline configuration monitoring, which is the control that detects unauthorised firmware or logic changes on a PLC.
  • CIP-008 (Incident Reporting and Response Planning) — reporting of reportable cyber security incidents, including attempts to compromise.

Distribution-level assets fall outside NERC CIP and inside state PUC jurisdiction, which varies considerably. The Iranian campaign has not respected that boundary.

Government services and facilities

Federal facilities fall under FISMA and applicable CISA binding operational directives. BOD 23-02, requiring the removal of internet-exposed management interfaces on federal networked devices, is the directive most directly on point and its logic is worth adopting voluntarily by non-federal operators.

Cross-sector reporting

CIRCIA will require covered entities in critical infrastructure sectors to report substantial cyber incidents within 72 hours and ransom payments within 24 hours once its timelines are operative — see our CIRCIA analysis. Operators should build the reporting workflow now rather than at enforcement.

A 30-day action plan

Week 1 — establish exposure. Enumerate every OT device with any path to the internet, including cellular modems, vendor remote-access appliances, and engineering workstations with dual-homed connections. Validate externally using an internet-facing scan of your own address space and a search of public device-indexing services for your organisation’s assets. Compare against the expanded manufacturer list in the update.

Week 2 — eliminate direct exposure. Remove or firewall every direct path. Where remote access is genuinely required, route it through an authenticated jump host with MFA, session recording, and time-bounded access. Vendor access should be enabled on request and disabled by default, not standing.

Week 3 — harden and baseline. Change all default credentials on PLCs and HMIs. Enable and enforce controller run/program mode protections where the platform supports them. Capture a configuration and logic baseline for every controller and store it offline — this is both a detection capability and a recovery capability.

Week 4 — detect and rehearse. Ingest the refreshed IOCs. Implement the new detection guidance. Then run a tabletop on the specific scenario in the advisory: operator displays showing normal values while the process deviates. The exercise should surface how your team would recognise the discrepancy, what independent instrumentation exists, and how manual operation would be initiated.

Conclusion

The July update to AA26-097A does not describe a new technique. It describes the same campaign reaching further, into more manufacturers’ equipment, with enough success that the agencies have added Treasury to the byline and refreshed the indicator set.

The mitigation has not changed since April and will not change in October: PLCs and HMIs should not be reachable from the internet. The reason the advisory keeps being updated rather than closed is that this control is organisationally difficult in a sector of small operators with vendor dependencies and thin staffing — not that it is technically hard.

Operators who assessed their exposure in April and found none should assess again this week. The list of what counts as exposed just got longer.

This article is provided for informational purposes only and does not constitute legal advice.