Executive Summary
In July 2026, the Cybersecurity and Infrastructure Security Agency (CISA) issued an alert regarding Iranian-affiliated cyber actors targeting internet-connected programmable logic controllers (PLCs) within U.S. critical infrastructure sectors, including water and wastewater systems. These actors exploited vulnerabilities in PLCs from manufacturers such as Rockwell Automation, Schneider Electric, and Siemens, leading to operational disruptions and financial losses. The attackers manipulated data on human-machine interfaces (HMIs) and supervisory control and data acquisition (SCADA) displays, causing outages and misleading operators about system statuses.
This incident underscores the escalating threat landscape where state-sponsored actors are increasingly focusing on industrial control systems. The expansion of targeted PLC brands highlights the need for organizations to reassess and fortify their operational technology (OT) security measures to prevent potential disruptions to essential services.
Why This Matters Now
The recent expansion of targeted PLC brands by Iranian-affiliated cyber actors signifies a growing and immediate threat to critical infrastructure. Organizations must urgently reassess and strengthen their OT security measures to prevent potential disruptions to essential services.
Attack Path Analysis
Adversaries exploited internet-exposed PLCs in the Water and Wastewater Systems Sector by leveraging default or weak credentials to gain unauthorized access. Once inside, they escalated privileges by modifying PLC configurations and passwords, effectively locking out legitimate operators. The attackers then moved laterally within the network, targeting additional PLCs and OT assets to expand their control. They established command and control by altering PLC IP addresses, disrupting normal communication channels. While exfiltration of data was not explicitly reported, the attackers' actions led to significant operational disruptions. The impact included boil water notices and the necessity for sustained manual operations due to compromised PLCs.
Kill Chain Progression
Initial Compromise
Description
Adversaries exploited internet-exposed PLCs by leveraging default or weak credentials to gain unauthorized access.
Related CVEs
CVE-2017-16740
CVSS 10A buffer overflow vulnerability in Rockwell Automation MicroLogix 1400 PLCs allows remote attackers to cause a denial of service or potentially execute arbitrary code via specially crafted Modbus TCP packets.
Affected Products:
Rockwell Automation MicroLogix 1400 – Series B and C, firmware versions 21.002 and earlier
Exploit Status:
no public exploitCVE-2012-6440
CVSS 4.8The webserver password authentication mechanism in Rockwell Automation MicroLogix 1100 and 1400 controllers is vulnerable to man-in-the-middle and replay attacks, allowing unauthorized access to view and alter product configuration and diagnostics information.
Affected Products:
Rockwell Automation MicroLogix 1100 – All versions
Rockwell Automation MicroLogix 1400 – All versions
Exploit Status:
no public exploitCVE-2014-5410
CVSS 7.1A denial-of-service vulnerability in the DNP3 implementation of Rockwell Automation MicroLogix 1400 controllers allows remote attackers to disrupt communication and cause a loss of availability by sending malformed DNP3 packets.
Affected Products:
Rockwell Automation MicroLogix 1400 – Series A FRN 7 and earlier, Series B FRN 15.000 and earlier
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Exploitation of Remote Services
Remote Services
Brute Force I/O
Program Download: Download All
Point & Tag Identification
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-53 – Boundary Protection
Control ID: SC-7
PCI DSS 4.0 – Restrict Access to System Components and Cardholder Data
Control ID: 7.2.3
NYDFS 23 NYCRR 500 – Encryption of Nonpublic Information
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity
Control ID: Pillar 1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Utilities
Water and wastewater systems face direct PLC targeting threats requiring immediate OT disconnection, zero trust segmentation, and encrypted traffic controls to prevent operational disruptions.
Government Administration
Municipal water authorities must implement CISA-recommended mitigations including VPN gateways, password protection, and IP allowlisting to secure critical infrastructure against PLC attacks.
Environmental Services
Water treatment facilities require enhanced east-west traffic security and threat detection capabilities to prevent boil water notices and sustained manual operations from PLC compromises.
Industrial Automation
PLC manufacturers and system integrators must address exposed Rockwell MicroLogix vulnerabilities through secure hybrid connectivity and comprehensive egress security policy enforcement for OT networks.
Sources
- CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCshttps://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcsVerified
- Rockwell Automation Patches Serious Flaw in MicroLogix 1400 PLChttps://www.securityweek.com/rockwell-automation-patches-serious-flaw-micrologix-1400-plc/Verified
- PN1010 | Security Advisory | Rockwell Automationhttps://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1010.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit unauthorized access to PLCs and constrain lateral movement within the network, thereby reducing the attacker's ability to disrupt operations.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to access PLCs with default or weak credentials would likely be constrained, reducing unauthorized entry points.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges by modifying PLC configurations would likely be limited, reducing the risk of operator lockout.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally within the network would likely be constrained, limiting their reach to additional PLCs and OT assets.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control by altering PLC IP addresses would likely be limited, reducing communication disruptions.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate data would likely be constrained, reducing the risk of data loss.
The attacker's ability to cause operational disruptions would likely be limited, reducing the severity of the impact.
Impact at a Glance
Affected Business Functions
- Water Treatment Operations
- Wastewater Management
- SCADA System Control
Estimated downtime: 7 days
Estimated loss: $500,000
Operational data related to water treatment processes and system configurations.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict access to PLCs and OT assets, ensuring only authorized entities can communicate with critical systems.
- • Enforce strong password policies and regularly update credentials to prevent unauthorized access through default or weak passwords.
- • Deploy East-West Traffic Security measures to monitor and control lateral movement within the network, detecting and preventing unauthorized access to additional OT assets.
- • Utilize Multicloud Visibility & Control solutions to gain comprehensive insights into network traffic and detect anomalous activities indicative of command and control attempts.
- • Establish robust Egress Security & Policy Enforcement to monitor and control outbound communications, preventing data exfiltration and unauthorized external connections.



