VYPR
advisoryPublished Jul 23, 2026· 2 sources

Federal Agencies Warn of Sophisticated PLC Exploitation Targeting U.S. Critical Infrastructure

Multiple federal agencies have updated a joint advisory warning of ongoing, sophisticated attacks against Programmable Logic Controllers (PLCs) that control U.S. critical infrastructure, leading to confirmed operational disruption.

Six federal agencies, including CISA, the FBI, and the NSA, have issued a stark warning about the persistent and evolving threat to U.S. critical infrastructure. Their updated joint advisory, AA26-097A, details ongoing exploitation of internet-facing Programmable Logic Controllers (PLCs) that are vital for operating sectors such as government facilities, water systems, and energy infrastructure. The advisory, first released in April 2026 and revised on July 22, highlights that advanced persistent threat (APT) actors are actively targeting these industrial control systems (ICS).

The attackers employ sophisticated techniques, scanning the internet for exposed PLCs and then connecting to them using legitimate engineering software, mimicking the actions of authorized technicians. Once inside the system, they alter the core control logic—the instructions that dictate how physical equipment operates. A particularly insidious tactic involves manipulating the Human-Machine Interface (HMI) displays, making it appear to operators that everything is functioning normally, thereby masking the malicious changes and preventing human detection of anomalies.

Programmable Logic Controllers (PLCs) are specialized industrial computers designed to manage and automate physical processes. They replaced older, hardwired relay systems with reprogrammable logic, enabling precise control over equipment like valves, pumps, and circuit breakers. While PLCs can operate independently, many are connected to networks, creating an attack vector that sophisticated actors are now exploiting. The "project file" (e.g., Rockwell's .ACD file) contains the entire operational blueprint for the PLC, including logic, configuration, and I/O mapping, making its compromise a critical threat.

This ongoing campaign represents a significant escalation from a similar, though less impactful, effort observed in November 2023. That earlier campaign, attributed to Iranian-linked actors, primarily targeted U.S. water facilities and often exploited simple default credentials. The current attacks, while potentially involving the same threat actors, are more advanced. They leverage legitimate engineering software, bypass the need for weak credentials, and have expanded their scope beyond Rockwell Automation / Allen-Bradley equipment to include Schneider Electric and Siemens PLCs, among others.

Crucially, unlike the largely disruption-free 2023 campaign, the current exploitation has resulted in confirmed operational disruptions and financial losses for some affected organizations. This underscores the real-world impact of these attacks on essential services. The advisory also points to a subtler but equally dangerous risk: the potential for malicious changes to be hidden within shared, reusable code modules, making detection even more challenging.

The targeted sectors are critical to national security and public well-being, making these attacks a significant concern. The involvement of multiple federal agencies in issuing the advisory signals the severity and breadth of the threat. Organizations operating critical infrastructure are urged to implement robust security measures to defend against these advanced threats.

Trend Micro's Vision One platform is capable of detecting and blocking the indicators of compromise (IoCs) associated with this activity, providing a layer of defense against these sophisticated ICS attacks. The continuous evolution of these threats necessitates ongoing vigilance and adaptation of security strategies within the industrial control systems landscape.

CISA has updated its advisory regarding the exploitation of internet-exposed Programmable Logic Controllers (PLCs), noting a broadened range of targeted manufacturers beyond Rockwell Automation to include Schneider Electric and Siemens. The agency highlights that these devices are increasingly found across various critical infrastructure sectors, including water and wastewater, energy, and local government facilities, leading to operational disruption and financial losses. The update emphasizes the ease with which these industrial control systems can be compromised due to their public internet accessibility and lack of authentication, with specialized search tools like Shodan revealing thousands of vulnerable devices globally.

Synthesized by Vypr AI