UPDATED: Joint Cybersecurity Advisory
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure to Cause Disruption

In April 2026, the Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and Environmental Protection Agency (EPA) issued an advisory warning U.S. organizations about ongoing cyber exploitation of internet-connected operational technology (OT) devices, including Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), across multiple critical infrastructure sectors.
On July 28, 2026, the advisory was updated to include Schneider Electric and Siemens and to add guidance on detecting and reviewing project files running on programmable logic controllers (PLCs), including reusable code modules embedded within PLC programs.