U.S. and cybersecurity agencies issued an updated warning on July 22 regarding ongoing attacks against programmable logic controllers (PLCs) used in critical infrastructure, including water and wastewater facilities. The advisory highlighted activity linked to Iranian-affiliated cyber actors who were targeting internet-connected operational technology devices. Security experts warned that these attacks had already caused operational disruption and financial losses across multiple sectors.

The updated guidance expanded the scope of concern beyond previously identified systems. In addition to Rockwell Automation equipment, authorities reported observed targeting of Schneider Electric and Siemens PLCs. These technologies are widely used in industrial environments, including many water treatment and wastewater management facilities, making the warning particularly relevant for utility operators.

According to the advisory, attackers were not merely attempting network intrusions. Investigators observed efforts to manipulate project files, alter information displayed through supervisory control systems, and interfere with operational processes. Such actions increase the risk of service disruption and demonstrate the growing sophistication of cyber campaigns targeting operational technology environments. 

The agencies urged water utilities to review internet exposure of PLCs, strengthen access controls, implement secure gateways for remote access, and monitor industrial networks for suspicious activity. The warning reinforced a key message for the water sector: operational technology security must be treated as a critical component of infrastructure resilience, especially as threat actors continue to focus on industrial control systems.