
Six federal agencies warn that Iranian-affiliated threat actors are actively exploiting internet-exposed programmable logic controllers (PLCs) across U.S. government facilities, water systems, and energy infrastructure. The advisory, tracked as AA26-097A, was first published in April 2026 and revised on July 22, 2026, expanding its scope to include Schneider Electric and Siemens equipment. Attackers use legitimate engineering software with valid credentials to alter controller logic and manipulate operator displays, making detection difficult. The ongoing exploitation stems from architectural weaknesses in network exposure and access control, resulting in confirmed operational disruption and financial loss for some victim organizations.