Blog

Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure - CISA Advisory Update 

By Mary Gannon, Director of OT Resilience, Copia Automation

On July 22nd, 2026, CISA came out with updated guidance for the original advisory posted in April 2026 regarding Iranian-affiliated cyber actors targeting internet connected operational technology (OT) assets including programmable logic controllers (PLCs). The updates expanded the initial known vendor targets from solely Rockwell Automation PLCs, to include PLCs manufactured by Schneider Electric, Siemens, and potentially others. New shared details indicate that the cyber actors modified PLC code, and in one case, introduced new logic that overrode existing code responsible for  maintaining safe operational parameters within the victim environment. 

Without resilient infrastructure, unauthorized changes to PLC code can go unnoticed until an operational failure occurs. True preparedness goes beyond merely preventing an attack; it encompasses the capacity to rapidly detect and restore operations safely in the event of a compromise.

Mitigation strategies in response to this advisory

The updated advisory reinforced existing mitigation recommendations as well as added some new ones. Key original recommendations include creating and testing strong backups of PLC logic and configurations, and monitoring asset management systems for device configuration changes. A new recommendation is to review project files running on PLCs for unauthorized changes. This proactive step is essential for identifying discrepancies between the currently running code and your authorized baseline configuration.

Copia’s OT resiliency and code management platform empowers engineering teams to meet these critical mandates by automating backups and providing version control for PLC and automation code, while simultaneously detecting code drift through comprehensive, real-time change history. OT resilience is a key component of defending against these increasingly frequent threats. If recovery and resilience are not prioritized, OT systems will continue to be a weak link within your network.