OT SECURITY NEWS

Iran-Linked PLC Attacks in 2026: CISA's Warning and a UK Power Plant Outage

US agencies attribute a campaign against internet-exposed PLCs to Iranian-affiliated actors, and in July a small UK generator was knocked offline. What is confirmed, which controllers are targeted, and a self-check any PLC engineer can run.

By EDWartens engineering team 5 October 2026 10 min
Iran-Linked PLC Attacks in 2026: CISA's Warning and a UK Power Plant Outage

A PLC cyber attack campaign that US agencies attribute to Iranian-affiliated actors has been altering programs on internet-exposed controllers since at least March 2026, and in July 2026 a small UK power generator was knocked offline for four days in an incident The Telegraph linked to Iran. The common weakness is simple: PLCs reachable from the internet with little or no authentication. The fix starts with taking them off the internet.

Checked 5 October 2026 against CISA advisory AA26-097A and reporting by Cybersecurity Dive, The Register, CBS News and Help Net Security.

What CISA advisory AA26-097A says

On 7 April 2026 the FBI, CISA, NSA, EPA, the Department of Energy and US Cyber Command published joint advisory AA26-097A. It describes a campaign the agencies attribute to Iranian-affiliated APT actors, which they also link to IRGC-affiliated actors tracked as CyberAv3ngers, against PLCs in US government facilities, water and wastewater, and energy.

The first version named Rockwell Automation CompactLogix and Micro850 controllers. On 22 July 2026 the agencies, now joined by the Treasury, updated it to add Schneider Electric Modicon M340 (BMX P34) and Siemens S7-1200 PLCs, and warned that potentially any internet-exposed PLC is at risk.

PLCs named in CISA advisory AA26-097A
PLCs named in CISA advisory AA26-097A

What the actors did is the part every PLC engineer should read twice. They did not use exotic exploits. They used the vendors' own engineering software, Studio 5000 Logix Designer, EcoStruxure Control Expert and TIA Portal, to connect to PLCs that were reachable from the internet and poorly protected. Once connected, they changed what was displayed on HMI and SCADA screens, deployed malicious project files, and modified and deleted program logic, including disabling shutdown and alarm functions. The advisory reports operational disruption and financial losses at victims.

What happened at the UK power plant?

On 23 August 2026 The Telegraph reported, citing sources, that a small UK power generation site had been offline for four days in July 2026 after a cyber attack it linked to Iran. A UK government spokesperson told Cybersecurity Dive that the story referred to an incident affecting a small-scale energy generator and that at no point was there a risk to the wider energy system. Energy Minister Michael Shanks said his department had briefed energy company chief executives and shared further security advice.

Be precise about what is and is not confirmed:

  • Confirmed by the government: an incident affected a small-scale energy generator, with no risk to the wider system.
  • Reported, not officially confirmed: the four-day outage and the link to Iran. The Register notes the UK has not formally attributed the attack to Iran or anyone else, and Cybersecurity Dive reports that an Iran-affiliated group denied involvement.
  • Not published: the site, the equipment and the attack method. CBS News described it as an attack on PLCs, but officials have released no technical details.

For context, in June 2026 the head of the UK's National Cyber Security Centre said nation-state adversaries accounted for about 75% of the 200 attacks on UK critical infrastructure it handled in the previous 12 months.

Timeline of the 2026 PLC campaign

DateEvent
March 2026Earliest activity described in AA26-097A
7 April 2026AA26-097A published: Rockwell CompactLogix and Micro850
June 2026NCSC chief: 75% of 200 UK CNI attacks linked to states
July 2026Small UK generator offline for four days, per The Telegraph
22 July 2026AA26-097A updated: Siemens S7-1200, Schneider M340 added
23 August 2026The Telegraph reports the UK incident

Why a PLC cyber attack is different from an IT breach

When ransomware hits an office network, you lose data and time. When someone changes PLC logic, the process itself does something different, and if they disable alarms and trips, the people watching it may not know. That is why the AA26-097A detail about disabled shutdown and alarm functions matters so much: the protective layer is part of the target.

It is also worth keeping a sense of proportion. Dragos counted 1,140 ransomware incidents against industrial organisations in Q2 2026, up 12% on Q1, with manufacturing accounting for 747 (65%). It found no case in which a ransomware operator reached Stage 2 of the ICS Cyber Kill Chain or directly manipulated a control system. Production stopped anyway, because ERP, virtualisation, identity and remote-access systems were hit. Most plants are more likely to be stopped from the IT side; the state-linked PLC campaign is the rarer, more dangerous case.

How to check your own PLCs: CISA's mitigations

CISA's advice to asset owners is practical and mostly free to apply. Turned into a self-check:

A PLC self-check based on CISA's mitigations
A PLC self-check based on CISA's mitigations

Some vendor-specific notes:

  • Siemens S7-1200: in TIA Portal, under the CPU's protection settings, choose an access level that requires a password for write access (or full protection) and set strong passwords. Leave PUT/GET communication disabled unless a specific partner needs it. Use the CPU's own protection, not just the project password.
  • Rockwell CompactLogix: put the key switch in RUN, not REM, so the program cannot be changed remotely. Use source protection and the controller's security features, and on newer 5380 and 5580 controllers consider CIP Security. Micro850 controllers should have a controller password set in Connected Components Workbench.
  • Schneider Modicon M340: set application and memory protection in EcoStruxure Control Expert, and restrict which addresses may connect over Modbus TCP.

None of these replaces the first item. A PLC that is not reachable from the internet cannot be reached by this campaign from the internet. Remote support should go through a VPN or remote-access gateway with multi-factor authentication, ideally one that is switched on only when needed.

A worked example: exposure by port

The advisory lists the ports the actors targeted. If your firewall or router forwards any of these from a public address to the control network, treat it as urgent:

PortProtocolTypical device
44818 (TCP/UDP)EtherNet/IP explicit messagingRockwell Logix and Micro800
2222 (UDP)EtherNet/IP implicit I/ORockwell and many EtherNet/IP devices
102 (TCP)ISO-TSAP, S7commSiemens S7 PLCs
502 (TCP)Modbus TCPSchneider and many others
22 (TCP)SSHGateways and embedded devices

Only test systems you are authorised to test. Your IT team, your security provider or your national CERT can check exposure from outside.

What 'modified ladder logic' means for change management

If an attacker can change your logic, so could an untrained colleague or a contractor's laptop with malware. Every plant needs to know what the PLC should be running. That means an offline, version-controlled backup of every program and configuration, a scheduled comparison against what is actually in the CPU, and a rule that changes go through a recorded procedure. CISA's advisory specifically recommends reviewing project files for unauthorised changes using vendor tools.

If you suspect a PLC program was changed
If you suspect a PLC program was changed

What to tell your manager this week

If you are the engineer who looks after the controls, you do not need a budget to start. A one-page note to your manager or site lead should say:

  1. Exposure: whether any PLC, HMI or remote-access device on site is reachable from the internet, and who confirmed it.
  2. Remote access: which vendors and contractors connect remotely, how, and whether multi-factor authentication is used.
  3. Backups: whether there is a current, offline copy of every PLC program and when it was last compared with the running code.
  4. Protection: which controllers have access protection and key switches set, and which do not.
  5. Next steps: the two or three fixes that can be done in a planned stop, and who will do them.

This is also exactly the evidence an insurer, auditor or customer will ask for after the next headline.

Where IEC 62443 fits

Everything above is a subset of what the ISA/IEC 62443 series asks for: zones and conduits to separate networks, controlled remote access, account management, and patch and backup processes, with responsibilities split between asset owners, integrators and product suppliers. Our OT cybersecurity explainer walks through IEC 62443 and the Purdue model, and the guide to free IEC 62443 training lists ways to learn it. Machine builders selling into the EU should also read our note on Cyber Resilience Act reporting obligations. For network basics, subnetting for PLC and OT networks is a good primer. In the UK, the NCSC's operational technology guidance is the official starting point.

Learn to defend your controllers, free

Start with Cybersecurity for PLC Programmers, which hardens Siemens and Rockwell controllers step by step. Then take OT and ICS Cybersecurity with ISA/IEC 62443 and ICS Security Foundations for the framework, and OT Security Assessment to learn how to test a plant without stopping it. They are grouped in the OT security courses and the IIoT and security learning path. Our PROFINET vs EtherNet/IP guide explains the networks the targeted Siemens and Rockwell controllers sit on.

Every course is free. An optional EDWartens Certificate of Completion, from US$2.99, can be verified at edwartens.com/verification. It is not a vendor certification and is not accredited.

Take the free course

Questions

What is CISA advisory AA26-097A?

AA26-097A is a joint US advisory, first published on 7 April 2026 and updated on 22 July 2026, warning that actors the agencies describe as Iranian-affiliated are exploiting internet-exposed PLCs in US critical infrastructure. It was co-authored by the FBI, CISA, NSA, EPA, DOE, US Cyber Command and, from the update, the Treasury.

Which PLCs are being targeted?

The advisory names Rockwell Automation CompactLogix and Micro850 controllers, Schneider Electric Modicon M340 (BMX P34) and Siemens S7-1200 PLCs, and warns that potentially any internet-exposed PLC is at risk. The actors used each vendor's own engineering software to connect.

How do I check if my PLC is exposed to the internet?

Ask your network or IT team for every public IP address the site uses and check that no firewall or router rule forwards PLC ports such as 44818, 2222, 102 or 502 to the control network. Your national CERT or an external scan by your security provider can confirm it from outside. Never scan systems you are not authorised to test.

Was the UK power plant attack confirmed?

The UK government confirmed an incident affecting a small-scale energy generator and said there was no risk to the wider energy system. The Telegraph reported that the site was offline for four days in July 2026 and linked the attack to Iran, but the UK has not formally attributed it and no technical details have been published.

Does ransomware usually reach the PLC?

Rarely. Dragos counted 1,140 ransomware incidents against industrial organisations in Q2 2026 and found none that reached the stage of directly manipulating a control system. Production still stopped in many cases because the IT systems a plant depends on, such as ERP and identity services, were encrypted.

Sources

Written by the EDWartens engineering team for general education. Product names are trademarks of their owners; mentioning them does not imply endorsement. Prices and terms of other providers were checked on the date shown and can change.