OT SECURITY NEWS
Iran-Linked PLC Attacks in 2026: CISA's Warning and a UK Power Plant Outage
US agencies attribute a campaign against internet-exposed PLCs to Iranian-affiliated actors, and in July a small UK generator was knocked offline. What is confirmed, which controllers are targeted, and a self-check any PLC engineer can run.

A PLC cyber attack campaign that US agencies attribute to Iranian-affiliated actors has been altering programs on internet-exposed controllers since at least March 2026, and in July 2026 a small UK power generator was knocked offline for four days in an incident The Telegraph linked to Iran. The common weakness is simple: PLCs reachable from the internet with little or no authentication. The fix starts with taking them off the internet.
Checked 5 October 2026 against CISA advisory AA26-097A and reporting by Cybersecurity Dive, The Register, CBS News and Help Net Security.
What CISA advisory AA26-097A says
On 7 April 2026 the FBI, CISA, NSA, EPA, the Department of Energy and US Cyber Command published joint advisory AA26-097A. It describes a campaign the agencies attribute to Iranian-affiliated APT actors, which they also link to IRGC-affiliated actors tracked as CyberAv3ngers, against PLCs in US government facilities, water and wastewater, and energy.
The first version named Rockwell Automation CompactLogix and Micro850 controllers. On 22 July 2026 the agencies, now joined by the Treasury, updated it to add Schneider Electric Modicon M340 (BMX P34) and Siemens S7-1200 PLCs, and warned that potentially any internet-exposed PLC is at risk.

What the actors did is the part every PLC engineer should read twice. They did not use exotic exploits. They used the vendors' own engineering software, Studio 5000 Logix Designer, EcoStruxure Control Expert and TIA Portal, to connect to PLCs that were reachable from the internet and poorly protected. Once connected, they changed what was displayed on HMI and SCADA screens, deployed malicious project files, and modified and deleted program logic, including disabling shutdown and alarm functions. The advisory reports operational disruption and financial losses at victims.
What happened at the UK power plant?
On 23 August 2026 The Telegraph reported, citing sources, that a small UK power generation site had been offline for four days in July 2026 after a cyber attack it linked to Iran. A UK government spokesperson told Cybersecurity Dive that the story referred to an incident affecting a small-scale energy generator and that at no point was there a risk to the wider energy system. Energy Minister Michael Shanks said his department had briefed energy company chief executives and shared further security advice.
Be precise about what is and is not confirmed:
- Confirmed by the government: an incident affected a small-scale energy generator, with no risk to the wider system.
- Reported, not officially confirmed: the four-day outage and the link to Iran. The Register notes the UK has not formally attributed the attack to Iran or anyone else, and Cybersecurity Dive reports that an Iran-affiliated group denied involvement.
- Not published: the site, the equipment and the attack method. CBS News described it as an attack on PLCs, but officials have released no technical details.
For context, in June 2026 the head of the UK's National Cyber Security Centre said nation-state adversaries accounted for about 75% of the 200 attacks on UK critical infrastructure it handled in the previous 12 months.
Timeline of the 2026 PLC campaign
| Date | Event |
|---|---|
| March 2026 | Earliest activity described in AA26-097A |
| 7 April 2026 | AA26-097A published: Rockwell CompactLogix and Micro850 |
| June 2026 | NCSC chief: 75% of 200 UK CNI attacks linked to states |
| July 2026 | Small UK generator offline for four days, per The Telegraph |
| 22 July 2026 | AA26-097A updated: Siemens S7-1200, Schneider M340 added |
| 23 August 2026 | The Telegraph reports the UK incident |
Why a PLC cyber attack is different from an IT breach
When ransomware hits an office network, you lose data and time. When someone changes PLC logic, the process itself does something different, and if they disable alarms and trips, the people watching it may not know. That is why the AA26-097A detail about disabled shutdown and alarm functions matters so much: the protective layer is part of the target.
It is also worth keeping a sense of proportion. Dragos counted 1,140 ransomware incidents against industrial organisations in Q2 2026, up 12% on Q1, with manufacturing accounting for 747 (65%). It found no case in which a ransomware operator reached Stage 2 of the ICS Cyber Kill Chain or directly manipulated a control system. Production stopped anyway, because ERP, virtualisation, identity and remote-access systems were hit. Most plants are more likely to be stopped from the IT side; the state-linked PLC campaign is the rarer, more dangerous case.
How to check your own PLCs: CISA's mitigations
CISA's advice to asset owners is practical and mostly free to apply. Turned into a self-check:

Some vendor-specific notes:
- Siemens S7-1200: in TIA Portal, under the CPU's protection settings, choose an access level that requires a password for write access (or full protection) and set strong passwords. Leave PUT/GET communication disabled unless a specific partner needs it. Use the CPU's own protection, not just the project password.
- Rockwell CompactLogix: put the key switch in RUN, not REM, so the program cannot be changed remotely. Use source protection and the controller's security features, and on newer 5380 and 5580 controllers consider CIP Security. Micro850 controllers should have a controller password set in Connected Components Workbench.
- Schneider Modicon M340: set application and memory protection in EcoStruxure Control Expert, and restrict which addresses may connect over Modbus TCP.
None of these replaces the first item. A PLC that is not reachable from the internet cannot be reached by this campaign from the internet. Remote support should go through a VPN or remote-access gateway with multi-factor authentication, ideally one that is switched on only when needed.
A worked example: exposure by port
The advisory lists the ports the actors targeted. If your firewall or router forwards any of these from a public address to the control network, treat it as urgent:
| Port | Protocol | Typical device |
|---|---|---|
| 44818 (TCP/UDP) | EtherNet/IP explicit messaging | Rockwell Logix and Micro800 |
| 2222 (UDP) | EtherNet/IP implicit I/O | Rockwell and many EtherNet/IP devices |
| 102 (TCP) | ISO-TSAP, S7comm | Siemens S7 PLCs |
| 502 (TCP) | Modbus TCP | Schneider and many others |
| 22 (TCP) | SSH | Gateways and embedded devices |
Only test systems you are authorised to test. Your IT team, your security provider or your national CERT can check exposure from outside.
What 'modified ladder logic' means for change management
If an attacker can change your logic, so could an untrained colleague or a contractor's laptop with malware. Every plant needs to know what the PLC should be running. That means an offline, version-controlled backup of every program and configuration, a scheduled comparison against what is actually in the CPU, and a rule that changes go through a recorded procedure. CISA's advisory specifically recommends reviewing project files for unauthorised changes using vendor tools.

What to tell your manager this week
If you are the engineer who looks after the controls, you do not need a budget to start. A one-page note to your manager or site lead should say:
- Exposure: whether any PLC, HMI or remote-access device on site is reachable from the internet, and who confirmed it.
- Remote access: which vendors and contractors connect remotely, how, and whether multi-factor authentication is used.
- Backups: whether there is a current, offline copy of every PLC program and when it was last compared with the running code.
- Protection: which controllers have access protection and key switches set, and which do not.
- Next steps: the two or three fixes that can be done in a planned stop, and who will do them.
This is also exactly the evidence an insurer, auditor or customer will ask for after the next headline.
Where IEC 62443 fits
Everything above is a subset of what the ISA/IEC 62443 series asks for: zones and conduits to separate networks, controlled remote access, account management, and patch and backup processes, with responsibilities split between asset owners, integrators and product suppliers. Our OT cybersecurity explainer walks through IEC 62443 and the Purdue model, and the guide to free IEC 62443 training lists ways to learn it. Machine builders selling into the EU should also read our note on Cyber Resilience Act reporting obligations. For network basics, subnetting for PLC and OT networks is a good primer. In the UK, the NCSC's operational technology guidance is the official starting point.
Learn to defend your controllers, free
Start with Cybersecurity for PLC Programmers, which hardens Siemens and Rockwell controllers step by step. Then take OT and ICS Cybersecurity with ISA/IEC 62443 and ICS Security Foundations for the framework, and OT Security Assessment to learn how to test a plant without stopping it. They are grouped in the OT security courses and the IIoT and security learning path. Our PROFINET vs EtherNet/IP guide explains the networks the targeted Siemens and Rockwell controllers sit on.
Every course is free. An optional EDWartens Certificate of Completion, from US$2.99, can be verified at edwartens.com/verification. It is not a vendor certification and is not accredited.
Take the free course

Cybersecurity · Intermediate · Free
Cybersecurity for PLC Programmers: Hardening Siemens and Rockwell Controllers

Cybersecurity · Intermediate · Free
OT and ICS Cybersecurity with ISA/IEC 62443

Cybersecurity · Beginner · Free
ICS Security Foundations: Control Systems, Defence in Depth and the 62443 Requirements

Cybersecurity · Intermediate · Free
OT Security Assessment: Testing a Plant Without Stopping It
Questions
What is CISA advisory AA26-097A?
AA26-097A is a joint US advisory, first published on 7 April 2026 and updated on 22 July 2026, warning that actors the agencies describe as Iranian-affiliated are exploiting internet-exposed PLCs in US critical infrastructure. It was co-authored by the FBI, CISA, NSA, EPA, DOE, US Cyber Command and, from the update, the Treasury.
Which PLCs are being targeted?
The advisory names Rockwell Automation CompactLogix and Micro850 controllers, Schneider Electric Modicon M340 (BMX P34) and Siemens S7-1200 PLCs, and warns that potentially any internet-exposed PLC is at risk. The actors used each vendor's own engineering software to connect.
How do I check if my PLC is exposed to the internet?
Ask your network or IT team for every public IP address the site uses and check that no firewall or router rule forwards PLC ports such as 44818, 2222, 102 or 502 to the control network. Your national CERT or an external scan by your security provider can confirm it from outside. Never scan systems you are not authorised to test.
Was the UK power plant attack confirmed?
The UK government confirmed an incident affecting a small-scale energy generator and said there was no risk to the wider energy system. The Telegraph reported that the site was offline for four days in July 2026 and linked the attack to Iran, but the UK has not formally attributed it and no technical details have been published.
Does ransomware usually reach the PLC?
Rarely. Dragos counted 1,140 ransomware incidents against industrial organisations in Q2 2026 and found none that reached the stage of directly manipulating a control system. Production still stopped in many cases because the IT systems a plant depends on, such as ERP and identity services, were encrypted.
Sources
- CISA: AA26-097A Iranian-affiliated cyber actors exploit PLCs across US critical infrastructure
- WaterISAC: CISA updates Iranian-affiliated PLC targeting advisory AA26-097A
- Cybersecurity Dive: UK power facility disabled in cyberattack (24 August 2026)
- The Register: Iran-linked cyberattack shut down a UK power plant (24 August 2026)
- CBS News: Iran-linked hackers blamed for taking down UK power plant, reports say
- Dragos: Industrial ransomware analysis Q2 2026
- Help Net Security: Ransomware gangs don't need control system access to disrupt production
- NCSC: Operational technology guidance collection
Written by the EDWartens engineering team for general education. Product names are trademarks of their owners; mentioning them does not imply endorsement. Prices and terms of other providers were checked on the date shown and can change.

IMTS 2026 Highlights: Automation, AI and Robotic Machining Trends

PACK EXPO International 2026: Automation to Watch (Oct 18-21)

Schneider Electric to Buy PTC for US$22.6 Billion: What It Means for Engineers

2.3 Million Technician Openings: Deloitte-MI Study on AI and Skills

Intrinsic Open-Sources Intrinsic Core at ROSCon 2026: What It Means

Qualcomm to Buy PickNik: What Happens to MoveIt and ROS 2 Users