3 min read

Washington widens its warning as Iran's cyber-physical reach grows — and its own threats escalate-288

Washington widens its warning as Iran's cyber-physical reach grows — and its own threats escalate-288

July 23, 2026

The US federal government has broadened a warning about Iranian-linked hackers targeting the industrial control systems that run American critical infrastructure, expanding the list of affected equipment makers just as President Trump publicly threatened to strike Iranian infrastructure directly in response to attacks on shipping in the Strait of Hormuz — two moves that, taken together, mark a sharp escalation in an already tense standoff.

CISA, together with the FBI and the Environmental Protection Agency, revised an advisory first issued in April that had focused specifically on programmable logic controllers — the industrial computers that physically operate equipment like pumps, valves, and switches — made by Rockwell Automation and Allen-Bradley. Wednesday's update expands that scope to include equipment from Schneider Electric and Siemens, and flags the possibility of further manufacturers being targeted as well. Both Schneider and Siemens controllers are used extremely widely across the United States and internationally, meaning the pool of potentially exposed facilities just grew substantially.

Control system cross-section — the tampered HMI feeding down through a shared control bus into the four PLC modules, colored to show which two were in the original April scope (teal) versus newly added in July (coral), connected to the physical equipment they operate

 The advisory describes the observed intrusions as involving malicious interference with the project files that engineers use to program these controllers, along with tampering with the human-machine interface and supervisory control displays that plant operators rely on to monitor and manage their systems in real time. Targeted organizations have already suffered both operational disruption and direct financial losses. These controllers sit at the core of power utilities, wastewater treatment plants, and manufacturing facilities — meaning a successful compromise doesn't just steal data, it can physically alter what equipment does. Officials said they expect the pressure from Iran-affiliated attackers to continue, and urged operators to restrict direct internet access to these systems and ensure secure deployment practices.

The advisory itself doesn't name specific groups or attacks — attribution here is deliberately hard to pin down, since Tehran has a documented pattern of using ransomware gangs and other seemingly independent groups as cover for state-directed operations. That pattern has precedent: a pro-Iranian hacktivist group that previously attacked a Los Angeles transit agency was later found by researchers to actually be an arm of Iran's own intelligence services operating under a hacktivist façade.

The timing is what turns a routine technical advisory into a geopolitical signal. On the same day the expanded advisory was issued, President Trump said the United States would strike a bridge or a power plant inside Iran if Tehran continued targeting ships in the Strait of Hormuz — an explicit threat against Iranian critical infrastructure delivered directly by the US president. Seen side by side, an American warning about Iran quietly expanding its reach into US industrial control systems, and an American president threatening to hit Iranian infrastructure in return, describe two sides of the same escalating confrontation — one being fought partly in the physical world and partly inside the control systems that keep both countries' infrastructure running.

Tension gauge — a rising thermometer showing the three escalating events, fill level nearly at the top to reflect where things stand now