A vendor list changed and nobody reported it
On 7 April 2026 the US Cybersecurity and Infrastructure Security Agency published advisory AA26-097A, describing the exploitation of internet-exposed programmable logic controllers across government services, water and wastewater, and energy. The controllers it named were Rockwell Automation Allen-Bradley units, and the activity it described ran back to March. For a European operator that read as an American problem about American equipment.
On 22 July the advisory was updated. The revision expanded the named equipment to include Schneider Electric and Siemens controllers alongside Rockwell, added detection guidance for manipulated code modules, and published fresh indicators covering September 2025 through July 2026. Four days later, between 26 and 27 July, more than thirty Minnesota community water systems were hit in a coordinated attack.
Every headline since has been about the attack itself or about who carried it out. The vendor list is the part of this that travels across the Atlantic, and it changed nine days ago.
The three controllers now named
The advisory names Rockwell Automation CompactLogix and Micro850, Schneider Electric Modicon M340, and the Siemens S7-1200 series. Two of those three families are the default fit-out of a European plant room. Rockwell's installed base is concentrated in North America; Siemens and Schneider are European manufacturers whose controllers run European water treatment, wastewater, food processing and general manufacturing.
The change is not a product defect. Nothing in the advisory describes a newly disclosed vulnerability in a Siemens or Schneider product. It describes controllers reachable from the public internet, protected by default or unchanged credentials, whose programs were then altered. The exposure is a configuration and access decision, usually made years ago by an integrator, and usually not revisited since.
That distinction decides who owns the fix. A product vulnerability is a patch you wait for. An exposed controller is an asset register and a remote-access path, and both of those are yours.
The technique moved from the password to the logic
In 2023 and 2024 the same sector was hit through Unitronics Vision series controllers, where at least 75 devices in the United States, Israel, the United Kingdom and Ireland were compromised through unchanged default passwords. That was an access problem with an access answer. The 2026 campaign is a different order of operation.
The advisory describes three moves in sequence. Vendor engineering software running on third-party hosted infrastructure was used to pull PLC project files out of victim environments. Add-On Instructions, the reusable code modules embedded in those programs, were then manipulated to disable safety shutdowns and alarms. Finally the data driving the HMI and SCADA displays was modified, so equipment could be run outside safe limits without the operator screen showing anything unusual.
Alongside that sit the cruder steps: administrator passwords changed to lock operators out of their own controllers, and IP settings altered to orphan a controller from the network that supervises it. A password policy answers the 2023 attack. Nothing in a password policy answers an edited alarm.
Two hours in Braham is a staffing fact
Braham, Minnesota has a population of roughly 1,700. The attack disabled the computerised controls at its well and its water treatment plant, and crews had operations back within two hours. Plymouth, South St Paul and Maple Plain also disclosed incidents, and more than thirty communities were affected in total on 26 and 27 July.
What restored Braham in two hours was people who could run the plant by hand. That is a staffing line rather than a security budget line, and it is the one most often thinned on the argument that the process is automated. In the incidents reported so far drinking water quality was not affected, though CISA's 30 July alert lists boil water notices and prolonged manual operation among the consequences this activity has caused.
On attribution nothing is settled. No federal or state agency has formally attributed the Minnesota attacks. A WaterISAC memo citing the Minnesota Fusion Center says the activity is aligned with the campaign CISA described, without presenting direct evidence; the operational pattern matches CyberAv3ngers, a group formally attributed to Iran's Islamic Revolutionary Guard Corps Cyber-Electronic Command; US intelligence agencies are reported to suspect Iran; and the President has publicly disputed that. None of those positions changes a single control you would put in place.
Three questions that do not need attribution
First, ask your integrator for every remote-access path into a controller, and do not accept the network diagram as the answer. The diagram documents the design; the exposure usually comes from what was added later for a support contract, a commissioning visit or an out-of-hours callout. CISA's 30 July alert, issued with the Environmental Protection Agency and the FBI, asks for exactly three things: take the controllers off the public internet and reach them through a VPN or gateway, enable password protection and change every default, and allowlist the addresses permitted to connect.
Second, can you produce today's controller program and compare it against the last approved version, including the Add-On Instructions? If the honest answer is that the current program exists only on the controller itself, then the manipulation this advisory describes has no detection path in your plant at all. A signed, version-controlled record of what the logic is supposed to be is the control here, and most sites cannot produce one.
Third, does your alarm test prove the alarm fires from the process, or only that the display can draw one? This reaches past the plant floor. Water and wastewater are Annex I essential sectors under NIS2, so a significant incident carries a 24-hour early warning and a 72-hour notification, with the management body accountable for the measures. That clock starts when you become aware, and a technique built to edit both the safety logic and the screen that reports it is a technique built to delay the moment you become aware.
Read next: CISA's First AI Agent Platform Is Now a Must-Patch | The SharePoint Patch You Skipped in May Is Now Urgent



