In July 2026, a coordinated multi-agency advisory from the FBI, CISA, NSA, EPA, DOE, and US Cyber Command identified ongoing Iranian state-sponsored attacks against US critical infrastructure. The campaign is actively exploiting Industrial Control Systems (ICS) manufactured by Siemens, Schneider Electric, and Rockwell Automation—the three largest vendors of SCADA and PLC systems operating America's power grid, water treatment, and industrial processes.
This matters because ICS devices are not typically hardened like enterprise IT networks. They run legacy software, patch slowly, and often lack segmentation from operational networks. A successful compromise at scale could allow an adversary to modify process commands, disrupt control loops, or trigger safety system failures without triggering alarms.
The advisory's focus on three specific vendors suggests either: (a) a concentrated vulnerability chain affecting their product lines, or (b) targeting of the highest-value assets in critical sectors. Either interpretation signals systemic exposure across multiple critical infrastructure domains simultaneously.
What distinguishes this alert is its joint attribution and multi-agency coordination—FBI, CISA, NSA, EPA, DOE, and US Cyber Command do not jointly issue warnings casually. The specificity of vendor names and the operational focus indicate this is not theoretical risk, but active, ongoing exploitation in real-time.
The convergence of targeting—grid operators, water utilities, and industrial facilities—suggests reconnaissance or positioning for larger operational impact. ICS systems are harder to patch, easier to hide in, and more directly control physical consequence than enterprise networks.

