Iran’s PLC Campaign Just Escalated — and Maritime Runs on the Same Controllers

What CISA’s Updated AA26-097A Advisory and the Minnesota Water Attacks Mean for Ports and Vessel Operators

July 31, 2026 | By The CyberSurv Team | CyberSurv

Port operations control room at blue hour overlooking illuminated ship-to-shore cranes and a container vessel, with SCADA monitors in the foreground

On July 22, seven federal agencies — the FBI, CISA, NSA, EPA, DOE, U.S. Cyber Command’s Cyber National Mission Force, and the Treasury Department — took the unusual step of re-issuing a joint advisory they had first published in April. AA26-097A warns that Iranian-affiliated threat actors are actively exploiting internet-exposed programmable logic controllers (PLCs) across U.S. critical infrastructure. The update expanded the target list from Rockwell Automation to include Schneider Electric and Siemens devices — and four days later, more than 30 Minnesota water utilities were hit in a coordinated attack.

The advisory names water, energy, and government facilities as the affected sectors. Maritime is not on that list. We think it should be read as if it were. The controllers being targeted are the same models running cranes, terminals, and shipboard systems across the maritime transportation system.

A Rare Second Alarm from Seven Federal Agencies

Federal agencies do not routinely re-publish advisories. When they do, it means the campaign is escalating. The July 22 update to AA26-097A documents three developments that changed the picture:

The target list grew. The original April advisory focused on Rockwell Automation/Allen-Bradley controllers. The update adds Schneider Electric Modicon M340 and Siemens S7-1200 PLCs — and warns that “potentially all internet-exposed PLCs” are in scope. Attackers are scanning for the standard industrial ports: 44818 and 2222 (EtherNet/IP), 102 (Siemens S7), and 502 (Modbus), plus SSH on exposed cellular modems.

The tradecraft matured. The actors are not deploying exotic malware. They are using the vendors’ own engineering software — Rockwell’s Studio 5000, Schneider’s EcoStruxure Control Expert, Siemens’ TIA Portal — running on leased cloud infrastructure to connect to exposed controllers, exfiltrate project files, and push modified logic back down. To a firewall, this traffic looks like an engineer doing engineering.

The intent turned dangerous. At one U.S. victim, investigators found the actors had downloaded a modified project file that preserved normal downstream operation but overrode the instruction sets maintaining safe operating parameters. The changes disabled shutdown and alarm logic — allowing the process to enter unsafe conditions without ever notifying operators. That is not espionage. That is sabotage engineering.

Four Days Later, the Water Went Off in Minnesota

On July 26 and 27, more than 30 Minnesota communities saw coordinated attacks on their water and wastewater systems. Braham’s well and treatment plant shut down temporarily. Plymouth disconnected cellular equipment at water towers and lift stations as a precaution. Analysis of the incidents points to exactly the systems named in the advisory: Rockwell Logix controllers, Schneider Modicon M340s, and Siemens S7-1200s, reached through internet-facing connections.

Officials have not formally attributed the attacks, but the operational pattern matches the IRGC-linked group known as CyberAv3ngers — the same actor set behind the 2023 Unitronics PLC compromises that defaced controllers at U.S. water utilities. The difference between 2023 and 2026 is capability. Defacing an HMI is vandalism. Silently disabling safety logic while operators see normal readings is something else entirely.

Why This Is a Maritime Advisory in All but Name

Walk the deck plates and terminal yards of any modern maritime operation and you will find the advisory’s target list everywhere. Siemens S7-series controllers run ship-to-shore crane motion and spreader systems. Schneider Modicon PLCs manage ballast water treatment, bilge and fuel transfer, and terminal conveyor lines. Rockwell CompactLogix controllers sit inside gate automation, reefer power management, and pump stations up and down the waterfront. Modbus on port 502 — one of the protocols being actively scanned — remains the lingua franca of shipboard automation.

Maritime also shares the exposure pattern that made the Minnesota utilities reachable. Remote assets — lift stations for a utility; outlying terminals, moorings, and vessels for an operator — get connected over cellular modems and satellite links so vendors and engineers can reach them without a truck roll or a launch. The advisory specifically documents attackers compromising internet-exposed modems via SSH to reach the OT behind them. Every VSAT terminal, cellular gateway, and vendor remote-access box in a fleet or facility is the same class of doorway.

And maritime operators are squarely inside the threat actor’s declared interest. Iranian-affiliated groups have a long record of targeting shipping and port logistics, and CISA has separately warned critical infrastructure operators that Iranian actors may target vulnerable U.S. networks amid ongoing tensions. An opportunistic campaign that scans the entire internet for exposed controllers does not check what sector you are in before it connects.

What Maritime Operators Should Do Now

The advisory’s mitigations are concrete, and for MTSA-regulated facilities and vessels they align directly with the cybersecurity assessments and plans the Coast Guard’s cyber rule already requires — work that must be completed before the July 2027 compliance deadline. We recommend five actions this quarter:

1. Find your exposed controllers before someone else does. Inventory every PLC, HMI, and remote modem reachable from the internet — including cellular and satellite paths that bypass the corporate firewall. This is precisely the visibility a Maritime Cybersecurity Assessment is designed to produce, and it satisfies a core requirement of the Subpart F assessment obligation.

2. Get PLCs off the open internet. Put controllers behind a secure gateway and firewall, restrict engineering-workstation protocols to known hosts, and monitor ports 44818, 2222, 102, and 502 for traffic from unfamiliar sources — especially foreign hosting providers.

3. Verify your logic, not just your network. Because these actors modify project files while preserving normal operation, network monitoring alone will not catch a compromised controller. Compare running PLC programs against known-good project files, review Add-On Instructions and function blocks for unauthorized changes, and set Rockwell controllers’ physical mode switches to RUN to block remote reprogramming.

4. Test the doorway. Remote-access paths — vendor connections, VSAT management interfaces, cellular gateways — should be validated by adversarial testing, not assumptions. Our Penetration Testing engagements routinely find exposed OT paths that asset inventories miss.

5. Make it continuous. This campaign has been running since at least March and is escalating. Point-in-time hygiene will not keep pace. RiskGuard 365℠ provides the continuous monitoring, threat intelligence, and incident-response readiness that turns a one-time assessment into a standing defense — and our Security Leadership Program gives operators without a dedicated CySO the executive ownership the Coast Guard rule expects.

Final Thoughts

AA26-097A is addressed to water utilities, energy companies, and municipalities. But threat actors read port scans, not sector labels. The controllers Iranian-affiliated actors are exploiting today are the controllers moving containers, treating ballast water, and keeping engine rooms running across the maritime industry. Minnesota’s utilities got four days between the warning and the attack. Maritime operators reading this advisory today may have more time — but not much more, and the difference will come down to who found their exposed controllers first.

Let’s Explore What’s Possible

Whether you need a Subpart F-aligned assessment of your facility’s OT exposure, adversarial testing of your remote-access paths, or continuous monitoring across your fleet, our team helps maritime operators close exactly the gaps this campaign is exploiting. Let’s talk before the next advisory becomes the next incident.

Schedule a Consultation

Scroll to Top

Discover more from CyberSurv.com

Subscribe now to keep reading and get access to the full archive.

Continue reading