What the July 22 update means for industrial asset owners, OT security professionals, and insurers.
In April, AA26-097A presented a serious but relatively bounded public picture: Iranian-affiliated actors were accessing internet-connected Rockwell Automation and Allen-Bradley programmable logic controllers across U.S. critical infrastructure, interacting with project files, manipulating human-machine interface and supervisory control and data acquisition displays, and causing operational disruption and financial loss in some cases [1].
The July 22 update is not merely an indicator-of-compromise refresh. It expands what the U.S. government has confirmed. The advisory now includes observed targeting of Schneider Electric and Siemens PLCs, theft of device project files, modification or deletion of reusable control logic, and changes that disabled critical shutdown and alarm functions. At one unnamed U.S. victim, the actors downloaded a malicious project that retained downstream ladder-logic functionality while overriding instructions responsible for maintaining safe operating parameters [1].
That is a meaningful escalation in the confirmed consequences. It does not mean every targeted PLC entered an unsafe state, every exposed device was compromised, or physical damage or injury occurred. The advisory does not make those claims. It does establish that this activity has progressed beyond loss of view or short-term disruption into manipulation capable of concealing unsafe process conditions from operators.
What the advisory now says
The actors used foreign IP addresses and leased third-party infrastructure, ran manufacturers’ legitimate PLC programming software, and connected to misconfigured, internet-facing controllers. They used Rockwell Automation Studio 5000 Logix Designer, Schneider Electric EcoStruxure Control Expert, and Siemens TIA Portal to access devices and exfiltrate project files. The government subsequently identified modification and deletion of project logic, including Rockwell Add-On Instructions and analogous function blocks, as well as manipulation of HMI and SCADA data [1].
The important point is that this activity was not dependent on exotic malware or a novel exploit. The actors did not need a zero-day or public CVE: they used legitimate engineering software and normal industrial protocols. On the network, the activity could resemble a valid engineering session; authorization, rather than protocol behavior, was the differentiator [2].
A vulnerability-centric response is therefore incomplete. Patching remains necessary, but it does not resolve a condition in which an unauthorized party can reach a controller, establish a programming session, retrieve its project, and write changes through native functions.
The authoring agencies say organizations in government services and facilities, water and wastewater, and energy were affected. They confirm that some cases resulted in operational disruption and financial loss, but do not identify the victims or provide loss amounts [1]. We should not fill those gaps with speculation.
What changed since April
The first change is manufacturer scope. The April disclosure concentrated on Rockwell CompactLogix and Micro850 controllers. The July update confirms targeting of Schneider BMX P34 and Modicon M340 PLCs and Siemens S7-1200 PLCs. It also warns that other manufacturers may be targeted opportunistically [1]. This is no longer appropriately treated as a Rockwell-only issue.
The second change is confirmed project-file exfiltration. A PLC project can provide a structured view of how a process is controlled, including logic, sequencing, tags, alarms, and dependencies. The advisory confirms that project files were transferred to threat-actor-controlled infrastructure and that the government subsequently identified modifications and deletions in project logic. This supports more tailored manipulation than blind interaction with an exposed device.
The third and most consequential change is safety and alarm suppression. HMI manipulation can cause loss of view. PLC disruption can cause loss of control or availability. Disabling shutdown and alarm logic creates a different condition: the process may continue while controls intended to stop an unsafe state, or alert the operator to it, no longer function as expected.
Depending on the process, that condition can create credible pathways to equipment damage, off-spec product, environmental release, fire, property damage, injury or fatality. These are potential loss pathways, not reported outcomes of AA26-097A. The government has confirmed the enabling manipulation; it has not reported that these physical consequences occurred.
It is also important not to overstate the timing. Several indicators newly published in July were associated with activity dating to 2025 or early 2026 [1]. The update may reflect better victim reporting and retrospective analysis as well as continuing operations. We can say the public evidentiary picture has escalated.
Private-sector reporting supports the core findings
Unit 42 reported discovering a Rockwell-focused activity cluster in late March 2026, tracked as CL-STA-1128 and associated with CyberAv3ngers and Storm-0784. It assessed with moderate confidence that the actor installed Rockwell FactoryTalk software on virtual private server infrastructure and stated that the April CISA advisory mirrored its findings. Unit 42 also observed Rockwell or Allen-Bradley SCADA services and PLCs on approximately 5,600 global IP addresses from April 1 onward [3].
Censys independently identified 5,219 internet-exposed hosts responding to EtherNet/IP and identifying as Rockwell Automation or Allen-Bradley devices on April 7; 3,891 were in the United States. It also found a strong concentration on cellular carrier networks, consistent with remote field deployments and the advisory’s attention to cellular modems [4].
Those measurements are not additive and are not victim counts. Their common value is showing that the reachable attack surface was measured in the thousands, while the number of confirmed compromises remains undisclosed.
Dragos provides relevant actor-capability context. It describes BAUXITE as a behavior-based threat group with substantial technical overlap with the pro-Iranian CyberAv3ngers persona. Dragos reports that BAUXITE can reach Stage 2 of the ICS Cyber Kill Chain and has demonstrated PLC compromise, ladder-logic modification, and custom backdoor deployment [5].
Dragos also states that it does not conduct political attribution. The careful conclusion is therefore that AA26-097A is consistent with a broader CyberAv3ngers and BAUXITE-overlapping capability set, not that public evidence proves every vendor label is a one-to-one identity.
Precedent without exaggeration
The advisory points back to a CyberAv3ngers campaign beginning in November 2023 that compromised at least 75 Unitronics PLC and HMI devices and replaced valid ladder logic with malicious code [1]. The best-known public example was the Municipal Water Authority of Aliquippa, Pennsylvania. A booster-station PLC was disabled, an alarm activated, and operators moved to manual control. The utility reported no known impact to drinking-water safety or supply [6].
That incident is useful precisely because it did not become a catastrophe. Detection, an alarm, and manual operation limited the consequence. The July 2026 finding is notable because the actors have now been observed disabling the types of shutdown and alarm logic that can support such a response.
A separate precedent is IOCONTROL. Claroty analyzed the Iran-affiliated malware in a campaign affecting several hundred Orpak and Gasboy fuel-management systems in Israel and the United States [7]. IOCONTROL is not publicly tied to AA26-097A, and its victims should not be added to the current campaign. It does show that the broader actor ecosystem has pursued embedded OT and IoT devices at meaningful scale.
The possible losses cross insurance policy boundaries
For asset owners, the loss may begin with:
- cyber incident response,
- controller validation,
- engineering support,
- project restoration, and
- business interruption.
If unsafe process conditions develop, it can extend into:
- physical equipment damage,
- machinery breakdown,
- environmental cleanup,
- product loss or contamination,
- bodily injury,
- third-party property damage,
- regulatory response, and
- contingent interruption elsewhere in the value chain.
There is no reliable way to determine from the phrase “Iranian-affiliated” alone whether insurance will respond. A single event may implicate cyber, property, machinery, casualty, environmental, and specialty policies, each with different triggers, definitions, sublimits, exclusions, and causation requirements.
State-backed cyber and war wording adds uncertainty. The Lloyd’s Market Association’s model cyber-war clauses distinguish between versions that include an agreed mechanism for attributing a cyber operation to a state and versions that do not. This illustrates that attribution is a contractual issue, not simply an intelligence label [8].
The Merck and NotPetya litigation also showed that a legacy hostile-or-warlike-action exclusion did not necessarily apply to a state-attributed cyberattack under the policies and law at issue in that case [9]. That decision does not mean state-attributed cyber losses are universally covered. It demonstrates why actual wording, governing law, attribution, causation, and the circumstances of the loss matter.
Neither owners nor insurers should assume coverage or exclusion before reading the wording and establishing the technical and causal facts. Relevant evidence may include who accessed the controller, what logic changed, when the process deviated, why operations stopped, whether physical damage occurred, and how attribution is resolved under the policy. In practice, coverage may remain unresolved while response, repair, and continuity costs are already accumulating.
The easier solution is risk avoidance, by identifying and protecting all OT devices from external access.
What asset owners should do
The joint advisory contains detailed mitigations, manufacturer guidance, detection instructions, and incident-reporting contacts. Asset owners and integrators should follow immediately [1].
For a broader control framework, our analysis of the top six effective cybersecurity solutions for industrial environments addresses the defensible architecture, controlled external access, known-good configurations, logging, OT-specific response, and supporting infrastructure that determine whether this activity is prevented, detected, contained, and recovered [10]. (DeNexus)
The appropriate response is not panic. It is to recognize what the evidence now shows: an Iranian-affiliated actor has used normal engineering functions to steal PLC projects, alter control logic, manipulate operator information, and suppress shutdown and alarm functions. That is a credible cyber-physical loss scenario. It deserves a response based on verified exposure, process consequence, and tested controls—not headlines or FUD.
You can't defend what you haven't quantified.
AA26-097A describes a credible cyber-physical loss pathway — one that crosses cyber, property, machinery, casualty, and environmental policy boundaries. The question for your board isn't whether the advisory is serious. It's what an event like this would actually cost you, and which controls measurably reduce that exposure.
The DeRISK Platform quantifies OT cyber risk in financial terms — Expected Annual Loss, Value at Risk, and loss exceedance curves — so you can prioritise the controls that reduce exposure and evidence the residual risk you transfer.
References
[1] Federal Bureau of Investigation, et al. “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure.” Joint Cybersecurity Advisory AA26-097A, 7 Apr. 2026, updated 22 July 2026. https://www.ic3.gov/CSA/2026/260722.pdf
[2] Mueller, Markus. “These Iranian-Affiliated Attackers Didn’t Need a Zero-Day. They Just Used the Manual.” Nozomi Networks, 8 Apr. 2026. https://www.nozominetworks.com/blog/these-iranian-affiliated-attackers-didnt-need-a-zero-day-they-just-used-the-manual
[3] Unit 42. “Threat Brief: Escalation of Cyber Risk Related to Iran.” Palo Alto Networks, updated 17 Apr. 2026. https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/
[4] Censys. “Iranian-Affiliated APT Targeting of Rockwell/Allen-Bradley PLCs.” Censys, 8 Apr. 2026. https://censys.com/blog/iranian-affiliated-apt-targeting-rockwell-allen-bradley-plcs/
[5] Dragos. “BAUXITE.” Dragos, n.d. Accessed 23 July 2026. https://www.dragos.com/threat/bauxite
[6] Wolfe, Jeremy. “Aliquippa, Pennsylvania Suffers Cyberattack on Booster Station PLC.” WaterWorld, 30 Nov. 2023. https://www.waterworld.com/water-utility-management/article/14302077/aliquippa-pennsylvania-suffers-cyberattack-on-booster-station-plc
[7] Team82. “Inside a New OT/IoT Cyberweapon: IOCONTROL.” Claroty, 10 Dec. 2024. https://claroty.com/team82/research/inside-a-new-ot-iot-cyber-weapon-iocontrol
[8] Lloyd’s Market Association. “Cyber War & Cyber Operation Clauses Updated.” LMA, 20 Jan. 2023. https://lmalloyds.com/cyber-war-cyber-operation-clauses-updated/
[9] Merck & Co., Inc., et al. v. ACE American Insurance Company, et al.. Superior Court of New Jersey, Appellate Division, 1 May 2023. Justia. https://law.justia.com/cases/new-jersey/appellate-division-published/2023/a-1879-21.html
[10] DeNexus. “Top 6 Cybersecurity Solutions for Industrial Environments.” DeNexus, 14 Jan. 2026. https://www.denexus.io/resources/top-6-effective-cybersecurity-solutions-industrial-environments