The Cybersecurity and Infrastructure Security Agency (CISA), co-authoring with the National Security Agency (NSA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA), released an advisory Thursday warning that Iranian hackers are exploiting internet-exposed Siemens S7-series PLCs. The agencies stated that the actors use internet scanning services to find poorly protected devices, then leverage AI tools to identify additional attack vectors and generate exploitation scripts, making malicious files appear as legitimate monitoring software.
"This is not a theoretical risk — it is an active threat," the advisory reads. Targeted sectors include Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities. The advisory follows a wave of cyberattacks on U.S. water infrastructure suspected to have originated from Iran less than a month ago, which affected dozens of municipalities across multiple states.
Simultaneously, Google's Threat Intelligence Group (GTIG) released a report detailing three Russian cyber-spy groups—tracked as UNC6293, UNC7005, and UNC5976—that are conducting highly targeted phishing campaigns against individuals in academia, aerospace, defense, government, and think tanks across Europe and the U.S. These groups, linked to APT29 (Cozy Bear/Ice Relic) and Russia's Foreign Intelligence Service (SVR), have adapted their tactics to abuse legitimate OAuth authentication flows, making their attacks appear more credible.
UNC6293, under observation for nearly two years, impersonates U.S. State Department employees to trick victims into granting long-term access to email accounts. In June 2026, the group was observed requesting verification codes after victims performed legitimate logins to external providers, effectively stealing account access. UNC7005, identified in February, targets academia and diplomatic personnel in Ukraine, Western Europe, and the U.S., using device-code phishing for Microsoft and WhatsApp accounts, often luring victims with invitations to diplomatic events. The group also exploits public Wi-Fi networks at hotels and conference centers to deploy infostealers and keyloggers.
While both Iranian and Russian campaigns operate independently, they collectively highlight the escalating cyber threat to critical infrastructure and knowledge-worker targets. The Iranian campaign focuses on disrupting industrial processes, while Russian groups aim for intelligence collection through credential theft.
U.S. agencies advise operators of Siemens PLCs to apply the latest security patches, isolate devices from the internet where possible, enforce strong access controls, and deploy anomaly detection for industrial control systems. Google urges potential targets of Russian phishing to verify unexpected communications, especially those requesting verification codes or account access.