PLC Campaign Spreads Beyond One Utility Outage

Minnesota’s water outages now read as part of a broader PLC campaign, not a local one-off. The break is that attackers are no longer just taking systems offline; they are going after engineering project files and reusable code modules, which can change what controllers do across sites and vendors. CISA’s updated AA26-097A now spans Rockwell Automation, Schneider Electric, and Siemens devices, and Tenable says project-file exfiltration is in scope for the first time. It also ties in KEV-listed CVE-2021-22681 for Rockwell Logix controllers, which has no vendor patch and has already been linked to Iranian-affiliated exploitation. For water and wastewater operators, the risk is cross-vendor compromise through the engineering workflow itself. Restoring one affected site does not erase stolen controller projects or the trust that automation tools place in them, so the blast radius can extend past the original outage.

Part of the PlainSec briefing for 2026-07-29

Sources