The Advisory Everyone Is Citing This Weekend Was Published on 7 April and Updated on 22 July
CISA’s PLC advisory is the strongest document in the file and the only multi-agency, on-the-record source naming Iranian-affiliated actors. Neither of its dates falls inside the past week.
Advisory AA26-097A, “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure,” was published 7 April 2026 and updated 22 July 2026. Its authors are the FBI, CISA, NSA, EPA, the Department of Energy, US Cyber Command and partners. The text states that since at least March 2026 the authoring agencies identified, through engagements with victim organisations, an Iranian-affiliated APT group that disrupted the function of PLCs, with attackers attempting to download malicious project files and manipulate data on HMI and SCADA displays, “resulting in operational disruption and financial loss.” The 22 July update adds detection guidance for malicious changes in reusable code modules in Rockwell Automation programs and widens the manufacturer scope from Rockwell alone to Schneider Electric, Siemens and potentially other brands. Sectors named include water and wastewater, energy, and government services and facilities including local municipalities.
Three other items circulating with recent timestamps this weekend carry older substance. SOCRadar’s Iran–Israel cyber conflict dashboard shows a three-day page age and states on its own face that map and incident data were last updated in March 2026. Fortinet’s “Recent Cyber Attacks” page also shows a three-day timestamp for incidents from 2025. Citizen Lab’s finding that former MEP Stelios Kouloglou was infected with NSO Group’s Pegasus in October 2022 and March 2023, while a substitute member of the European Parliament’s PEGA committee, is Report 194, published 3 July — and Citizen Lab is explicit that it attributes the infections to no government and found no indication of Greek government responsibility. Amnesty’s Elina Castillo Jiménez said at the time: “If an elected member of parliament is not safe from unlawful surveillance, then no one is.”
Assessment: The April advisory is what gives the Iran hypothesis in the water story its plausibility, and it is being laundered into the present tense as if it were a fresh finding about Minnesota. It is not: it describes activity from March onward against a named class of controllers, and it does not mention the July intrusions. Treat the July update’s expansion from Rockwell to Schneider and Siemens as the real news in it — the agencies widened the aperture nine days before Minnesota. Also note what Iran’s cyber posture usually produces and has not produced here: no IRNA, Fars or Foreign Ministry denial has surfaced. Silence from Tehran on an accusation it normally rebuts is worth logging.