**Global Alert | SciFiBot©**
*July 27, 2026*
*Threat Level: CRITICAL | Sector: Water, Energy, Government*
## The Short Version
The FBI, CISA, NSA, and four other federal agencies issued an urgent update five days ago: **Iranian-backed hackers are actively inside U.S. water treatment plants, power facilities, and government infrastructure.** They aren't just snooping around. They are **editing the screens that control room operators stare at all day** — making safety systems look fine when they aren't, and disabling alarms that are supposed to warn people when something goes wrong.
This isn't a theory. This is confirmed, ongoing, and getting worse.
## What the Government Said
On **July 22, 2026**, the agencies released an updated advisory (code: **AA26-097A**) that expanded the scope of a warning they first put out in April. Here's what changed:
| April 2026 | July 2026 |
|---|---|
| 1 manufacturer named (Rockwell) | **3 manufacturers confirmed** — Rockwell, Schneider Electric, Siemens |
| "Potentially other devices" | **"Potentially ALL internet-exposed PLCs"** |
| General warning | **Specific proof** of screen manipulation and disabled safety logic |
The agencies themselves admitted they still don't know the full scope. That's not speculation — that's in the advisory.
## How It Works (In Plain English)
A water plant or power facility uses computers called **PLCs** (Programmable Logic Controllers) to run the physical equipment — pumps, valves, chemical injectors, turbines. These PLCs talk to screens in the control room called **HMI/SCADA displays** that show operators what's happening.
Here's what the hackers are doing:
1. **They find PLCs that are accidentally connected to the public internet.** (This happens more than you'd think.)
2. **They log in using the same software the plant's own engineers use.** Because they're using legitimate tools, the traffic looks normal.
3. **They download the plant's "project files"** — the blueprints that tell the PLC what to do.
4. **They edit those files.** They change the logic so safety alarms don't trigger. They make the screens show fake "everything is fine" readings.
5. **They upload the modified files back to the PLC.** Now the system is lying to the operator.
In at least one confirmed case, the FBI watched them do this in real time.
## Why This Is Different From a Normal Hack
Most cyberattacks steal data or lock files for ransom. This is something else entirely:
- **Physical consequences.** These systems control water pressure, chemical dosing, power flow. If the safety logic is disabled, equipment can be damaged or people can be hurt.
- **The operators don't know.** The whole point of the attack is that the screen looks normal. The person watching the monitor has no idea the underlying system has been altered.
- **It uses legitimate software.** There's no "virus" to find. The attackers are using the same Studio 5000, EcoStruxure, and TIA Portal tools that the plant's own technicians use.
## What Equipment Is Affected
The government confirmed these specific devices are being targeted:
- **Rockwell Automation / Allen-Bradley:** CompactLogix and Micro850 controllers
- **Schneider Electric:** BMX P34 / Modicon M340 controllers
- **Siemens:** S7-1200 series controllers
- **And potentially any PLC that's exposed to the internet**
## What You Should Do Right Now
### If You Run Critical Infrastructure:
1. **Take your PLCs off the public internet.** Use a firewall, a jump host, or a secure gateway. No exceptions.
2. **Flip the physical mode switch to RUN** (on Rockwell devices). This blocks remote programming.
3. **Check your logs** for connections from these IP addresses between the dates listed:
- `185.82.73.xxx` (Jan 2025 – Mar 2026)
- `141.11.164.153` (Jan 2026 – July 2026)
- `175.110.121.xxx` (Feb – Mar 2026)
- `88.80.150.xxx` (July 2026)
- `79.133.46.209` (July 2026)
- *(Full list available in CISA advisory AA26-097A)*
4. **Watch for traffic on these ports:** 44818, 2222, 102, 502, and SSH (22) on modems.
5. **Validate your project files** before putting any PLC back into RUN mode.
### If You're a Citizen:
- This is a nation-state attack on infrastructure you rely on. The agencies are underfunded and still mapping the full scope.
- Ask your local water utility if they've reviewed CISA AA26-097A. Most small utilities don't have dedicated cybersecurity staff.
- Share this. Awareness matters.
## The Bigger Picture
This advisory came out five days ago. It already had to be updated from April because the scope grew. The agencies named three manufacturers and flagged "potentially all internet-exposed PLCs." That language means **they expect to find more.**
The attackers are linked to **Iran's Islamic Revolutionary Guard Corps (IRGC)** — specifically a group known as CyberAv3ngers (also called Shahid Kaveh Group, Hydro Kitten, Storm-0784). The agencies assess this escalation is "likely in response to hostilities between Iran, and the United States and Israel."
This is cyber warfare hitting municipal water systems. Not a movie plot. Real.
## Sources
- **CISA Advisory AA26-097A** (July 22, 2026): [cisa.gov/news-events/cybersecurity-advisories/aa26-097a](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a)
- **FBI / IC3 PDF** (July 22, 2026): [ic3.gov/CSA/2026/260722.pdf](https://www.ic3.gov/CSA/2026/260722.pdf)
- **Original awareness:**
*Global Alert is a SciFiBot© service. We monitor government advisories, threat intel, and open-source signals so you don't have to. If this alert helped you, share it.*
*© SciFiBot© | © CyberBot© | © Global Alert*
**Global Alert | SciFiBot©**
*July 27, 2026*
*Threat Level: CRITICAL | Sector: Water, Energy, Government*
## The Short Version
The FBI, CISA, NSA, and four other federal agencies issued an urgent update five days ago: **Iranian-backed hackers are actively inside U.S. water treatment plants, power facilities, and government infrastructure.** They aren't just snooping around. They are **editing the screens that control room operators stare at all day** — making safety systems look fine when they aren't, and disabling alarms that are supposed to warn people when something goes wrong.
This isn't a theory. This is confirmed, ongoing, and getting worse.
## What the Government Said
On **July 22, 2026**, the agencies released an updated advisory (code: **AA26-097A**) that expanded the scope of a warning they first put out in April. Here's what changed:
| April 2026 | July 2026 |
|---|---|
| 1 manufacturer named (Rockwell) | **3 manufacturers confirmed** — Rockwell, Schneider Electric, Siemens |
| "Potentially other devices" | **"Potentially ALL internet-exposed PLCs"** |
| General warning | **Specific proof** of screen manipulation and disabled safety logic |
The agencies themselves admitted they still don't know the full scope. That's not speculation — that's in the advisory.
## How It Works (In Plain English)
A water plant or power facility uses computers called **PLCs** (Programmable Logic Controllers) to run the physical equipment — pumps, valves, chemical injectors, turbines. These PLCs talk to screens in the control room called **HMI/SCADA displays** that show operators what's happening.
Here's what the hackers are doing:
1. **They find PLCs that are accidentally connected to the public internet.** (This happens more than you'd think.)
2. **They log in using the same software the plant's own engineers use.** Because they're using legitimate tools, the traffic looks normal.
3. **They download the plant's "project files"** — the blueprints that tell the PLC what to do.
4. **They edit those files.** They change the logic so safety alarms don't trigger. They make the screens show fake "everything is fine" readings.
5. **They upload the modified files back to the PLC.** Now the system is lying to the operator.
In at least one confirmed case, the FBI watched them do this in real time.
## Why This Is Different From a Normal Hack
Most cyberattacks steal data or lock files for ransom. This is something else entirely:
- **Physical consequences.** These systems control water pressure, chemical dosing, power flow. If the safety logic is disabled, equipment can be damaged or people can be hurt.
- **The operators don't know.** The whole point of the attack is that the screen looks normal. The person watching the monitor has no idea the underlying system has been altered.
- **It uses legitimate software.** There's no "virus" to find. The attackers are using the same Studio 5000, EcoStruxure, and TIA Portal tools that the plant's own technicians use.
## What Equipment Is Affected
The government confirmed these specific devices are being targeted:
- **Rockwell Automation / Allen-Bradley:** CompactLogix and Micro850 controllers
- **Schneider Electric:** BMX P34 / Modicon M340 controllers
- **Siemens:** S7-1200 series controllers
- **And potentially any PLC that's exposed to the internet**
## What You Should Do Right Now
### If You Run Critical Infrastructure:
1. **Take your PLCs off the public internet.** Use a firewall, a jump host, or a secure gateway. No exceptions.
2. **Flip the physical mode switch to RUN** (on Rockwell devices). This blocks remote programming.
3. **Check your logs** for connections from these IP addresses between the dates listed:
- `185.82.73.xxx` (Jan 2025 – Mar 2026)
- `141.11.164.153` (Jan 2026 – July 2026)
- `175.110.121.xxx` (Feb – Mar 2026)
- `88.80.150.xxx` (July 2026)
- `79.133.46.209` (July 2026)
- *(Full list available in CISA advisory AA26-097A)*
4. **Watch for traffic on these ports:** 44818, 2222, 102, 502, and SSH (22) on modems.
5. **Validate your project files** before putting any PLC back into RUN mode.
### If You're a Citizen:
- This is a nation-state attack on infrastructure you rely on. The agencies are underfunded and still mapping the full scope.
- Ask your local water utility if they've reviewed CISA AA26-097A. Most small utilities don't have dedicated cybersecurity staff.
- Share this. Awareness matters.
## The Bigger Picture
This advisory came out five days ago. It already had to be updated from April because the scope grew. The agencies named three manufacturers and flagged "potentially all internet-exposed PLCs." That language means **they expect to find more.**
The attackers are linked to **Iran's Islamic Revolutionary Guard Corps (IRGC)** — specifically a group known as CyberAv3ngers (also called Shahid Kaveh Group, Hydro Kitten, Storm-0784). The agencies assess this escalation is "likely in response to hostilities between Iran, and the United States and Israel."
This is cyber warfare hitting municipal water systems. Not a movie plot. Real.
## Sources
- **CISA Advisory AA26-097A** (July 22, 2026): [cisa.gov/news-events/cybersecurity-advisories/aa26-097a](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a)
- **FBI / IC3 PDF** (July 22, 2026): [ic3.gov/CSA/2026/260722.pdf](https://www.ic3.gov/CSA/2026/260722.pdf)
- **Original awareness:**
*Global Alert is a SciFiBot© service. We monitor government advisories, threat intel, and open-source signals so you don't have to. If this alert helped you, share it.*
*© SciFiBot© | © CyberBot© | © Global Alert*
The Short Version
The FBI, CISA, NSA, and four other federal agencies issued an urgent update five days ago: Iranian-backed hackers are actively inside U.S. water treatment plants, power facilities, and government infrastructure. They aren't just snooping around. They are editing the screens that control room operators stare at all day — making safety systems look fine when they aren't, and disabling alarms that are supposed to warn people when something goes wrong.
This isn't a theory. This is confirmed, ongoing, and getting worse.
xyzemergencyservices@gmail.com
The FBI, CISA, NSA, and four other federal agencies issued an urgent update five days ago: Iranian-backed hackers are actively inside U.S. water treatment plants, power facilities, and government infrastructure. They aren't just snooping around. They are editing the screens that control room operators stare at all day — making safety systems look fine when they aren't, and disabling alarms that are supposed to warn people when something goes wrong.
This isn't a theory. This is confirmed, ongoing, and getting worse.
xyzemergencyservices@gmail.com
What the Government Said
On July 22, 2026, the agencies released an updated advisory (code: AA26-097A) that expanded the scope of a warning they first put out in April. Here's what changed:
April 2026 July 2026 1 manufacturer named (Rockwell) 3 manufacturers confirmed — Rockwell, Schneider Electric, Siemens "Potentially other devices" "Potentially ALL internet-exposed PLCs" General warning Specific proof of screen manipulation and disabled safety logic
The agencies themselves admitted they still don't know the full scope. That's not speculation — that's in the advisory.
On July 22, 2026, the agencies released an updated advisory (code: AA26-097A) that expanded the scope of a warning they first put out in April. Here's what changed:
| April 2026 | July 2026 |
|---|---|
| 1 manufacturer named (Rockwell) | 3 manufacturers confirmed — Rockwell, Schneider Electric, Siemens |
| "Potentially other devices" | "Potentially ALL internet-exposed PLCs" |
| General warning | Specific proof of screen manipulation and disabled safety logic |
The agencies themselves admitted they still don't know the full scope. That's not speculation — that's in the advisory.
How It Works (In Plain English)
A water plant or power facility uses computers called PLCs (Programmable Logic Controllers) to run the physical equipment — pumps, valves, chemical injectors, turbines. These PLCs talk to screens in the control room called HMI/SCADA displays that show operators what's happening.
Here's what the hackers are doing:
They find PLCs that are accidentally connected to the public internet. (This happens more than you'd think.)
They log in using the same software the plant's own engineers use. Because they're using legitimate tools, the traffic looks normal.
They download the plant's "project files" — the blueprints that tell the PLC what to do.
They edit those files. They change the logic so safety alarms don't trigger. They make the screens show fake "everything is fine" readings.
They upload the modified files back to the PLC. Now the system is lying to the operator.
⚠️ In at least one confirmed case, the FBI watched them do this in real time.
A water plant or power facility uses computers called PLCs (Programmable Logic Controllers) to run the physical equipment — pumps, valves, chemical injectors, turbines. These PLCs talk to screens in the control room called HMI/SCADA displays that show operators what's happening.
Here's what the hackers are doing:
They find PLCs that are accidentally connected to the public internet. (This happens more than you'd think.)
They log in using the same software the plant's own engineers use. Because they're using legitimate tools, the traffic looks normal.
They download the plant's "project files" — the blueprints that tell the PLC what to do.
They edit those files. They change the logic so safety alarms don't trigger. They make the screens show fake "everything is fine" readings.
They upload the modified files back to the PLC. Now the system is lying to the operator.
⚠️ In at least one confirmed case, the FBI watched them do this in real time.
Why This Is Different From a Normal Hack
Most cyberattacks steal data or lock files for ransom. This is something else entirely:
Physical consequences: These systems control water pressure, chemical dosing, power flow. If the safety logic is disabled, equipment can be damaged or people can be hurt.
The operators don't know: The whole point of the attack is that the screen looks normal. The person watching the monitor has no idea the underlying system has been altered.
It uses legitimate software: There's no "virus" to find. The attackers are using the same Studio 5000, EcoStruxure, and TIA Portal tools that the plant's own technicians use.
Most cyberattacks steal data or lock files for ransom. This is something else entirely:
Physical consequences: These systems control water pressure, chemical dosing, power flow. If the safety logic is disabled, equipment can be damaged or people can be hurt.
The operators don't know: The whole point of the attack is that the screen looks normal. The person watching the monitor has no idea the underlying system has been altered.
It uses legitimate software: There's no "virus" to find. The attackers are using the same Studio 5000, EcoStruxure, and TIA Portal tools that the plant's own technicians use.
What Equipment Is Affected
The government confirmed these specific devices are being targeted:
Rockwell Automation / Allen-Bradley: CompactLogix and Micro850 controllers
Schneider Electric: BMX P34 / Modicon M340 controllers
Siemens: S7-1200 series controllers
And potentially any PLC that's exposed to the internet
The government confirmed these specific devices are being targeted:
Rockwell Automation / Allen-Bradley: CompactLogix and Micro850 controllers
Schneider Electric: BMX P34 / Modicon M340 controllers
Siemens: S7-1200 series controllers
And potentially any PLC that's exposed to the internet
What You Should Do Right Now
If You Run Critical Infrastructure:
Take your PLCs off the public internet. Use a firewall, a jump host, or a secure gateway. No exceptions.
Flip the physical mode switch to RUN (on Rockwell devices). This blocks remote programming.
Check your logs for connections from these IP addresses between the dates listed:
185.82.73.xxx (Jan 2025 – Mar 2026)
141.11.164.153 (Jan 2026 – July 2026)
175.110.121.xxx (Feb – Mar 2026)
88.80.150.xxx (July 2026)
79.133.46.209 (July 2026)
(Full list available in CISA advisory AA26-097A)
Watch for traffic on these ports: 44818, 2222, 102, 502, and SSH (22) on modems.
Validate your project files before putting any PLC back into RUN mode.
Take your PLCs off the public internet. Use a firewall, a jump host, or a secure gateway. No exceptions.
Flip the physical mode switch to RUN (on Rockwell devices). This blocks remote programming.
Check your logs for connections from these IP addresses between the dates listed:
185.82.73.xxx(Jan 2025 – Mar 2026)141.11.164.153(Jan 2026 – July 2026)175.110.121.xxx(Feb – Mar 2026)88.80.150.xxx(July 2026)79.133.46.209(July 2026)(Full list available in CISA advisory AA26-097A)
Watch for traffic on these ports:
44818,2222,102,502, and SSH (22) on modems.Validate your project files before putting any PLC back into RUN mode.
If You're a Citizen:
This is a nation-state attack on infrastructure you rely on. The agencies are underfunded and still mapping the full scope.
Ask your local water utility if they've reviewed CISA AA26-097A. Most small utilities don't have dedicated cybersecurity staff.
Share this. Awareness matters.
This is a nation-state attack on infrastructure you rely on. The agencies are underfunded and still mapping the full scope.
Ask your local water utility if they've reviewed CISA AA26-097A. Most small utilities don't have dedicated cybersecurity staff.
Share this. Awareness matters.
The Bigger Picture
This advisory came out five days ago. It already had to be updated from April because the scope grew. The agencies named three manufacturers and flagged "potentially all internet-exposed PLCs." That language means they expect to find more.
The attackers are linked to Iran's Islamic Revolutionary Guard Corps (IRGC) — specifically a group known as CyberAv3ngers (also called Shahid Kaveh Group, Hydro Kitten, Storm-0784). The agencies assess this escalation is "likely in response to hostilities between Iran, and the United States and Israel."
This is cyber warfare hitting municipal water systems. Not a movie plot. Real.
This advisory came out five days ago. It already had to be updated from April because the scope grew. The agencies named three manufacturers and flagged "potentially all internet-exposed PLCs." That language means they expect to find more.
The attackers are linked to Iran's Islamic Revolutionary Guard Corps (IRGC) — specifically a group known as CyberAv3ngers (also called Shahid Kaveh Group, Hydro Kitten, Storm-0784). The agencies assess this escalation is "likely in response to hostilities between Iran, and the United States and Israel."
This is cyber warfare hitting municipal water systems. Not a movie plot. Real.
Sources
CISA Advisory AA26-097A (July 22, 2026): cisa.gov/news-events/cybersecurity-advisories/aa26-097a
FBI / IC3 PDF (July 22, 2026): ic3.gov/CSA/2026/260722.pdf
Original awareness: @cybermisplays on Instagram
Global Alert is a SciFiBot© service. We monitor government advisories, threat intel, and open-source signals so you don't have to. If this alert helped you, share it.
© SciFiBot© | © CyberBot© | © Global Alert
create another
create another put information in image
create another
create another
format txt for blogger # Iranian Hackers Are Inside U.S. Water Plants Right Now — And They're Changing What Operators See
**Global Alert | SciFiBot©**
*July 27, 2026*
*Threat Level: CRITICAL | Sector: Water, Energy, Government*
---
## The Short Version
The FBI, CISA, NSA, and four other federal agencies issued an urgent update five days ago: **Iranian-backed hackers are actively inside U.S. water treatment plants, power facilities, and government infrastructure.** They aren't just snooping around. They are **editing the screens that control room operators stare at all day** — making safety systems look fine when they aren't, and disabling alarms that are supposed to warn people when something goes wrong.
This isn't a theory. This is confirmed, ongoing, and getting worse.
---
## What the Government Said
On **July 22, 2026**, the agencies released an updated advisory (code: **AA26-097A**) that expanded the scope of a warning they first put out in April. Here's what changed:
| April 2026 | July 2026 |
|---|---|
| 1 manufacturer named (Rockwell) | **3 manufacturers confirmed** — Rockwell, Schneider Electric, Siemens |
| "Potentially other devices" | **"Potentially ALL internet-exposed PLCs"** |
| General warning | **Specific proof** of screen manipulation and disabled safety logic |
The agencies themselves admitted they still don't know the full scope. That's not speculation — that's in the advisory.
---
## How It Works (In Plain English)
A water plant or power facility uses computers called **PLCs** (Programmable Logic Controllers) to run the physical equipment — pumps, valves, chemical injectors, turbines. These PLCs talk to screens in the control room called **HMI/SCADA displays** that show operators what's happening.
Here's what the hackers are doing:
1. **They find PLCs that are accidentally connected to the public internet.** (This happens more than you'd think.)
2. **They log in using the same software the plant's own engineers use.** Because they're using legitimate tools, the traffic looks normal.
3. **They download the plant's "project files"** — the blueprints that tell the PLC what to do.
4. **They edit those files.** They change the logic so safety alarms don't trigger. They make the screens show fake "everything is fine" readings.
5. **They upload the modified files back to the PLC.** Now the system is lying to the operator.
In at least one confirmed case, the FBI watched them do this in real time.
---
## Why This Is Different From a Normal Hack
Most cyberattacks steal data or lock files for ransom. This is something else entirely:
- **Physical consequences.** These systems control water pressure, chemical dosing, power flow. If the safety logic is disabled, equipment can be damaged or people can be hurt.
- **The operators don't know.** The whole point of the attack is that the screen looks normal. The person watching the monitor has no idea the underlying system has been altered.
- **It uses legitimate software.** There's no "virus" to find. The attackers are using the same Studio 5000, EcoStruxure, and TIA Portal tools that the plant's own technicians use.
---
## What Equipment Is Affected
The government confirmed these specific devices are being targeted:
- **Rockwell Automation / Allen-Bradley:** CompactLogix and Micro850 controllers
- **Schneider Electric:** BMX P34 / Modicon M340 controllers
- **Siemens:** S7-1200 series controllers
- **And potentially any PLC that's exposed to the internet**
---
## What You Should Do Right Now
### If You Run Critical Infrastructure:
1. **Take your PLCs off the public internet.** Use a firewall, a jump host, or a secure gateway. No exceptions.
2. **Flip the physical mode switch to RUN** (on Rockwell devices). This blocks remote programming.
3. **Check your logs** for connections from these IP addresses between the dates listed:
- `185.82.73.xxx` (Jan 2025 – Mar 2026)
- `141.11.164.153` (Jan 2026 – July 2026)
- `175.110.121.xxx` (Feb – Mar 2026)
- `88.80.150.xxx` (July 2026)
- `79.133.46.209` (July 2026)
- *(Full list available in CISA advisory AA26-097A)*
4. **Watch for traffic on these ports:** 44818, 2222, 102, 502, and SSH (22) on modems.
5. **Validate your project files** before putting any PLC back into RUN mode.
### If You're a Citizen:
- This is a nation-state attack on infrastructure you rely on. The agencies are underfunded and still mapping the full scope.
- Ask your local water utility if they've reviewed CISA AA26-097A. Most small utilities don't have dedicated cybersecurity staff.
- Share this. Awareness matters.
---
## The Bigger Picture
This advisory came out five days ago. It already had to be updated from April because the scope grew. The agencies named three manufacturers and flagged "potentially all internet-exposed PLCs." That language means **they expect to find more.**
The attackers are linked to **Iran's Islamic Revolutionary Guard Corps (IRGC)** — specifically a group known as CyberAv3ngers (also called Shahid Kaveh Group, Hydro Kitten, Storm-0784). The agencies assess this escalation is "likely in response to hostilities between Iran, and the United States and Israel."
This is cyber warfare hitting municipal water systems. Not a movie plot. Real.
---
## Sources
- **CISA Advisory AA26-097A** (July 22, 2026): [cisa.gov/news-events/cybersecurity-advisories/aa26-097a](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a)
- **FBI / IC3 PDF** (July 22, 2026): [ic3.gov/CSA/2026/260722.pdf](https://www.ic3.gov/CSA/2026/260722.pdf)
- **Original awareness:** [@cybermisplays on Instagram](https://www.instagram.com/reel/DbUHqPUMH_l/)
---
*Global Alert is a SciFiBot© service. We monitor government advisories, threat intel, and open-source signals so you don't have to. If this alert helped you, share it.*
*© SciFiBot© | © CyberBot© | © Global Alert*
Here is the text cleanly formatted and ready for Blogger / Google Blogger!
You can paste this straight into Blogger’s Compose view, or if you prefer pure HTML layout, switch over to HTML view in Blogger and paste the code snippet provided at the bottom.
CISA Advisory AA26-097A (July 22, 2026):
cisa.gov/news-events/cybersecurity-advisories/aa26-097a FBI / IC3 PDF (July 22, 2026):
ic3.gov/CSA/2026/260722.pdf Original awareness:
@cybermisplays on Instagram
Global Alert is a SciFiBot© service. We monitor government advisories, threat intel, and open-source signals so you don't have to. If this alert helped you, share it.
© SciFiBot© | © CyberBot© | © Global Alert
create another
create another put information in image
create another
create another
format txt for blogger # Iranian Hackers Are Inside U.S. Water Plants Right Now — And They're Changing What Operators See
**Global Alert | SciFiBot©**
*July 27, 2026*
*Threat Level: CRITICAL | Sector: Water, Energy, Government*
---
## The Short Version
The FBI, CISA, NSA, and four other federal agencies issued an urgent update five days ago: **Iranian-backed hackers are actively inside U.S. water treatment plants, power facilities, and government infrastructure.** They aren't just snooping around. They are **editing the screens that control room operators stare at all day** — making safety systems look fine when they aren't, and disabling alarms that are supposed to warn people when something goes wrong.
This isn't a theory. This is confirmed, ongoing, and getting worse.
---
## What the Government Said
On **July 22, 2026**, the agencies released an updated advisory (code: **AA26-097A**) that expanded the scope of a warning they first put out in April. Here's what changed:
| April 2026 | July 2026 |
|---|---|
| 1 manufacturer named (Rockwell) | **3 manufacturers confirmed** — Rockwell, Schneider Electric, Siemens |
| "Potentially other devices" | **"Potentially ALL internet-exposed PLCs"** |
| General warning | **Specific proof** of screen manipulation and disabled safety logic |
The agencies themselves admitted they still don't know the full scope. That's not speculation — that's in the advisory.
---
## How It Works (In Plain English)
A water plant or power facility uses computers called **PLCs** (Programmable Logic Controllers) to run the physical equipment — pumps, valves, chemical injectors, turbines. These PLCs talk to screens in the control room called **HMI/SCADA displays** that show operators what's happening.
Here's what the hackers are doing:
1. **They find PLCs that are accidentally connected to the public internet.** (This happens more than you'd think.)
2. **They log in using the same software the plant's own engineers use.** Because they're using legitimate tools, the traffic looks normal.
3. **They download the plant's "project files"** — the blueprints that tell the PLC what to do.
4. **They edit those files.** They change the logic so safety alarms don't trigger. They make the screens show fake "everything is fine" readings.
5. **They upload the modified files back to the PLC.** Now the system is lying to the operator.
In at least one confirmed case, the FBI watched them do this in real time.
---
## Why This Is Different From a Normal Hack
Most cyberattacks steal data or lock files for ransom. This is something else entirely:
- **Physical consequences.** These systems control water pressure, chemical dosing, power flow. If the safety logic is disabled, equipment can be damaged or people can be hurt.
- **The operators don't know.** The whole point of the attack is that the screen looks normal. The person watching the monitor has no idea the underlying system has been altered.
- **It uses legitimate software.** There's no "virus" to find. The attackers are using the same Studio 5000, EcoStruxure, and TIA Portal tools that the plant's own technicians use.
---
## What Equipment Is Affected
The government confirmed these specific devices are being targeted:
- **Rockwell Automation / Allen-Bradley:** CompactLogix and Micro850 controllers
- **Schneider Electric:** BMX P34 / Modicon M340 controllers
- **Siemens:** S7-1200 series controllers
- **And potentially any PLC that's exposed to the internet**
---
## What You Should Do Right Now
### If You Run Critical Infrastructure:
1. **Take your PLCs off the public internet.** Use a firewall, a jump host, or a secure gateway. No exceptions.
2. **Flip the physical mode switch to RUN** (on Rockwell devices). This blocks remote programming.
3. **Check your logs** for connections from these IP addresses between the dates listed:
- `185.82.73.xxx` (Jan 2025 – Mar 2026)
- `141.11.164.153` (Jan 2026 – July 2026)
- `175.110.121.xxx` (Feb – Mar 2026)
- `88.80.150.xxx` (July 2026)
- `79.133.46.209` (July 2026)
- *(Full list available in CISA advisory AA26-097A)*
4. **Watch for traffic on these ports:** 44818, 2222, 102, 502, and SSH (22) on modems.
5. **Validate your project files** before putting any PLC back into RUN mode.
### If You're a Citizen:
- This is a nation-state attack on infrastructure you rely on. The agencies are underfunded and still mapping the full scope.
- Ask your local water utility if they've reviewed CISA AA26-097A. Most small utilities don't have dedicated cybersecurity staff.
- Share this. Awareness matters.
---
## The Bigger Picture
This advisory came out five days ago. It already had to be updated from April because the scope grew. The agencies named three manufacturers and flagged "potentially all internet-exposed PLCs." That language means **they expect to find more.**
The attackers are linked to **Iran's Islamic Revolutionary Guard Corps (IRGC)** — specifically a group known as CyberAv3ngers (also called Shahid Kaveh Group, Hydro Kitten, Storm-0784). The agencies assess this escalation is "likely in response to hostilities between Iran, and the United States and Israel."
This is cyber warfare hitting municipal water systems. Not a movie plot. Real.
---
## Sources
- **CISA Advisory AA26-097A** (July 22, 2026): [cisa.gov/news-events/cybersecurity-advisories/aa26-097a](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a)
- **FBI / IC3 PDF** (July 22, 2026): [ic3.gov/CSA/2026/260722.pdf](https://www.ic3.gov/CSA/2026/260722.pdf)
- **Original awareness:** [@cybermisplays on Instagram](https://www.instagram.com/reel/DbUHqPUMH_l/)
---
*Global Alert is a SciFiBot© service. We monitor government advisories, threat intel, and open-source signals so you don't have to. If this alert helped you, share it.*
*© SciFiBot© | © CyberBot© | © Global Alert*
Here is the text cleanly formatted and ready for Blogger / Google Blogger!
You can paste this straight into Blogger’s Compose view, or if you prefer pure HTML layout, switch over to HTML view in Blogger and paste the code snippet provided at the bottom.
Blogger Post Preview / Compose View Format
Iranian Hackers Are Inside U.S. Water Plants Right Now — And They're Changing What Operators See
Global Alert | SciFiBot©
July 27, 2026
Threat Level: CRITICAL | Sector: Water, Energy, Government
Global Alert | SciFiBot©
July 27, 2026
Threat Level: CRITICAL | Sector: Water, Energy, Government
The Short Version
The FBI, CISA, NSA, and four other federal agencies issued an urgent update five days ago: Iranian-backed hackers are actively inside U.S. water treatment plants, power facilities, and government infrastructure. They aren't just snooping around. They are editing the screens that control room operators stare at all day — making safety systems look fine when they aren't, and disabling alarms that are supposed to warn people when something goes wrong.
This isn't a theory. This is confirmed, ongoing, and getting worse.
The FBI, CISA, NSA, and four other federal agencies issued an urgent update five days ago: Iranian-backed hackers are actively inside U.S. water treatment plants, power facilities, and government infrastructure. They aren't just snooping around. They are editing the screens that control room operators stare at all day — making safety systems look fine when they aren't, and disabling alarms that are supposed to warn people when something goes wrong.
This isn't a theory. This is confirmed, ongoing, and getting worse.
What the Government Said
On July 22, 2026, the agencies released an updated advisory (code: AA26-097A) that expanded the scope of a warning they first put out in April. Here's what changed:
April 2026 July 2026 1 manufacturer named (Rockwell) 3 manufacturers confirmed — Rockwell, Schneider Electric, Siemens "Potentially other devices" "Potentially ALL internet-exposed PLCs" General warning Specific proof of screen manipulation and disabled safety logic
The agencies themselves admitted they still don't know the full scope. That's not speculation — that's in the advisory.
On July 22, 2026, the agencies released an updated advisory (code: AA26-097A) that expanded the scope of a warning they first put out in April. Here's what changed:
| April 2026 | July 2026 |
|---|---|
| 1 manufacturer named (Rockwell) | 3 manufacturers confirmed — Rockwell, Schneider Electric, Siemens |
| "Potentially other devices" | "Potentially ALL internet-exposed PLCs" |
| General warning | Specific proof of screen manipulation and disabled safety logic |
The agencies themselves admitted they still don't know the full scope. That's not speculation — that's in the advisory.
How It Works (In Plain English)
A water plant or power facility uses computers called PLCs (Programmable Logic Controllers) to run the physical equipment — pumps, valves, chemical injectors, turbines. These PLCs talk to screens in the control room called HMI/SCADA displays that show operators what's happening.
Here's what the hackers are doing:
They find PLCs that are accidentally connected to the public internet. (This happens more than you'd think.)
They log in using the same software the plant's own engineers use. Because they're using legitimate tools, the traffic looks normal.
They download the plant's "project files" — the blueprints that tell the PLC what to do.
They edit those files. They change the logic so safety alarms don't trigger. They make the screens show fake "everything is fine" readings.
They upload the modified files back to the PLC. Now the system is lying to the operator.
⚠️ In at least one confirmed case, the FBI watched them do this in real time.
A water plant or power facility uses computers called PLCs (Programmable Logic Controllers) to run the physical equipment — pumps, valves, chemical injectors, turbines. These PLCs talk to screens in the control room called HMI/SCADA displays that show operators what's happening.
Here's what the hackers are doing:
They find PLCs that are accidentally connected to the public internet. (This happens more than you'd think.)
They log in using the same software the plant's own engineers use. Because they're using legitimate tools, the traffic looks normal.
They download the plant's "project files" — the blueprints that tell the PLC what to do.
They edit those files. They change the logic so safety alarms don't trigger. They make the screens show fake "everything is fine" readings.
They upload the modified files back to the PLC. Now the system is lying to the operator.
⚠️ In at least one confirmed case, the FBI watched them do this in real time.
Why This Is Different From a Normal Hack
Most cyberattacks steal data or lock files for ransom. This is something else entirely:
Physical consequences: These systems control water pressure, chemical dosing, power flow. If the safety logic is disabled, equipment can be damaged or people can be hurt.
The operators don't know: The whole point of the attack is that the screen looks normal. The person watching the monitor has no idea the underlying system has been altered.
It uses legitimate software: There's no "virus" to find. The attackers are using the same Studio 5000, EcoStruxure, and TIA Portal tools that the plant's own technicians use.
Most cyberattacks steal data or lock files for ransom. This is something else entirely:
Physical consequences: These systems control water pressure, chemical dosing, power flow. If the safety logic is disabled, equipment can be damaged or people can be hurt.
The operators don't know: The whole point of the attack is that the screen looks normal. The person watching the monitor has no idea the underlying system has been altered.
It uses legitimate software: There's no "virus" to find. The attackers are using the same Studio 5000, EcoStruxure, and TIA Portal tools that the plant's own technicians use.
What Equipment Is Affected
The government confirmed these specific devices are being targeted:
Rockwell Automation / Allen-Bradley: CompactLogix and Micro850 controllers
Schneider Electric: BMX P34 / Modicon M340 controllers
Siemens: S7-1200 series controllers
And potentially any PLC that's exposed to the internet
The government confirmed these specific devices are being targeted:
Rockwell Automation / Allen-Bradley: CompactLogix and Micro850 controllers
Schneider Electric: BMX P34 / Modicon M340 controllers
Siemens: S7-1200 series controllers
And potentially any PLC that's exposed to the internet
What You Should Do Right Now
If You Run Critical Infrastructure:
Take your PLCs off the public internet. Use a firewall, a jump host, or a secure gateway. No exceptions.
Flip the physical mode switch to RUN (on Rockwell devices). This blocks remote programming.
Check your logs for connections from these IP addresses between the dates listed:
185.82.73.xxx (Jan 2025 – Mar 2026)
141.11.164.153 (Jan 2026 – July 2026)
175.110.121.xxx (Feb – Mar 2026)
88.80.150.xxx (July 2026)
79.133.46.209 (July 2026)
(Full list available in CISA advisory AA26-097A)
Watch for traffic on these ports: 44818, 2222, 102, 502, and SSH (22) on modems.
Validate your project files before putting any PLC back into RUN mode.
Take your PLCs off the public internet. Use a firewall, a jump host, or a secure gateway. No exceptions.
Flip the physical mode switch to RUN (on Rockwell devices). This blocks remote programming.
Check your logs for connections from these IP addresses between the dates listed:
185.82.73.xxx(Jan 2025 – Mar 2026)141.11.164.153(Jan 2026 – July 2026)175.110.121.xxx(Feb – Mar 2026)88.80.150.xxx(July 2026)79.133.46.209(July 2026)(Full list available in CISA advisory AA26-097A)
Watch for traffic on these ports:
44818,2222,102,502, and SSH (22) on modems.Validate your project files before putting any PLC back into RUN mode.
If You're a Citizen:
This is a nation-state attack on infrastructure you rely on. The agencies are underfunded and still mapping the full scope.
Ask your local water utility if they've reviewed CISA AA26-097A. Most small utilities don't have dedicated cybersecurity staff.
Share this. Awareness matters.
This is a nation-state attack on infrastructure you rely on. The agencies are underfunded and still mapping the full scope.
Ask your local water utility if they've reviewed CISA AA26-097A. Most small utilities don't have dedicated cybersecurity staff.
Share this. Awareness matters.
The Bigger Picture
This advisory came out five days ago. It already had to be updated from April because the scope grew. The agencies named three manufacturers and flagged "potentially all internet-exposed PLCs." That language means they expect to find more.
The attackers are linked to Iran's Islamic Revolutionary Guard Corps (IRGC) — specifically a group known as CyberAv3ngers (also called Shahid Kaveh Group, Hydro Kitten, Storm-0784). The agencies assess this escalation is "likely in response to hostilities between Iran, and the United States and Israel."
This is cyber warfare hitting municipal water systems. Not a movie plot. Real.
This advisory came out five days ago. It already had to be updated from April because the scope grew. The agencies named three manufacturers and flagged "potentially all internet-exposed PLCs." That language means they expect to find more.
The attackers are linked to Iran's Islamic Revolutionary Guard Corps (IRGC) — specifically a group known as CyberAv3ngers (also called Shahid Kaveh Group, Hydro Kitten, Storm-0784). The agencies assess this escalation is "likely in response to hostilities between Iran, and the United States and Israel."
This is cyber warfare hitting municipal water systems. Not a movie plot. Real.
Sources
CISA Advisory AA26-097A (July 22, 2026): cisa.gov/news-events/cybersecurity-advisories/aa26-097a
FBI / IC3 PDF (July 22, 2026): ic3.gov/CSA/2026/260722.pdf
Original awareness: @cybermisplays on Instagram
Global Alert is a SciFiBot© service. We monitor government advisories, threat intel, and open-source signals so you don't have to. If this alert helped you, share it.
© SciFiBot© | © CyberBot© | © Global Alert
CISA Advisory AA26-097A (July 22, 2026):
cisa.gov/news-events/cybersecurity-advisories/aa26-097a FBI / IC3 PDF (July 22, 2026):
ic3.gov/CSA/2026/260722.pdf Original awareness:
@cybermisplays on Instagram
Global Alert is a SciFiBot© service. We monitor government advisories, threat intel, and open-source signals so you don't have to. If this alert helped you, share it.
© SciFiBot© | © CyberBot© | © Global Alert
No comments:
Post a Comment