The War Has a Fifth Front, and It Runs Through Your Water Treatment Plant
AA26-097A's 22 July update added a seventh agency and, more importantly, moved the CyberAv3ngers campaign off Israeli-made Unitronics controllers onto the Western-made Rockwell, Siemens, and Schneider systems that run the industrial base. The mechanism — making a plant's control screen lie to its operator — this desk documented in April. The escalation, from a symbol to the backbone, is the story.
What AA26-097A actually says, why the platform shift from Unitronics to Rockwell, Siemens, and Schneider is the real story, and why this is the physical domain of a war the series has already mapped in every other domain.
In April, this desk documented the moment a joint US federal advisory first described Iranian-affiliated actors making an American water plant's control screen lie to the operator watching it — the physical front of a war the Chokepoint Doctrine had already tracked across cables on the ocean floor, satellites in low earth orbit, and the AI-model layer an enterprise runs on. That coverage was The Dashboard Is Lying, followed by the six-agency confirmation of disrupted PLCs across water, energy, and government systems. The advisory was AA26-097A, published 7 April 2026.
On 22 July, AA26-097A was updated — and the update, not the mechanism, is the story. A seventh agency joined the six: the Department of the Treasury, the sanctions authority that designated CyberAv3ngers' operators in 2024. And the campaign moved off the Israeli-made Unitronics controllers it began on, onto the Western-made Rockwell, Siemens, and Schneider Electric systems that run water, energy, chemicals, food, and transport across the entire industrial base. That jump — from a symbol to the backbone — is what changed, and it is the most significant strategic signal in the document. This is not a new war, or even a new campaign. It is the same one, arriving with a wider blast radius at a front that keeps water running in American towns that never thought of themselves as combatants.
What the advisory actually says, and what it does not
AA26-097A was first published on 7 April 2026, co-signed by the FBI, CISA, the NSA, the EPA, and the Department of Energy. On 22 July, it was updated and expanded, with US Cyber Command's Cyber National Mission Force and the Department of Treasury joining as co-authors — seven agencies in total, a detail that most of the coverage circulating this week has not fully captured. Treasury's inclusion matters: it signals that the response now includes the sanctions authority that targeted CyberAv3ngers operators in February 2024, not merely the technical and law-enforcement response that characterised the original April advisory.
The technical substance of the July update is precise, and it deserves to be read exactly as the agencies wrote it rather than as the somewhat looser paraphrase that has circulated on social media. The authoring agencies observed Iranian-affiliated APT actors using legitimate configuration software — Rockwell Automation's Studio 5000 Logix Designer, Schneider Electric's EcoStruxure Control Expert, and Siemens' Totally Integrated Automation Portal — running from leased, third-party hosted infrastructure, to exfiltrate device project files from PLCs to threat-actor-controlled servers. After extracting those files, the actors modified and deleted project file logic, including Add-On Instructions, and manipulated data displayed on HMI and SCADA screens. The consequence, stated by the agencies without qualification: the changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators of the anomalies.
The mechanism itself is the one this desk detailed in April, and it is worth restating in a single line, because it is categorically different from a data breach: the attacker has not stolen anything from the plant — it has cut the plant's ability to know what state it is in. An operator watches a screen that has been deliberately altered to read normal while the physical system it represents is not. What the July update adds is not a new technique. It is a new blast radius.
One element of the circulating commentary deserves a more careful hand than it has received. One widely circulated summary of the advisory states that the agencies tied the escalation directly to the US and Israeli military operations against Iran that began in February. That causal link is a reasonable analytical inference, and this series has made a version of it throughout its coverage of the war — but it is worth being precise that AA26-097A itself, as published by CISA, is a technical advisory describing tactics, techniques, and observed indicators of compromise. It does not, in its own language, formally state the strategic motive behind the campaign as agency-attributed fact. The distinction matters for the same reason the series has insisted on it throughout this war: the technical finding is confirmed at the highest evidentiary tier available, and the strategic motive, however plausible, sits one tier below that, in the domain of assessment rather than agency-stated fact. It is a claim worth testing formally — and this piece does exactly that, below.
The platform shift is the story, and almost nobody is reading it correctly
The detail buried inside the manufacturer-scope expansion is the one that deserves to anchor this entire analysis, because it reveals something about Iranian doctrine that the advisory's dry technical language does not spell out but that the group's own operational history makes unmistakable.
CyberAv3ngers — tracked under the aliases Storm-0784, Bauxite, Hydro Kitten, and UNC5691, and formally attributed by the US government to Iran's IRGC Cyber-Electronic Command, with six of its operators sanctioned by Treasury in February 2024 and a ten-million-dollar State Department bounty still standing on the group's leadership — built its original campaign entirely around a single, explicit ideological target class. In November 2023, the group compromised at least 75 Israeli-made Unitronics Vision Series PLCs across the US, UK, and Ireland, exploiting nothing more sophisticated than factory-default passwords on devices left reachable from the open internet. The defacement message the actors left behind stated the targeting logic in the group's own words: "You have been hacked, down with Israel. Every equipment 'made in Israel' is CyberAv3ngers legal target." The Municipal Water Authority of Aliquippa, Pennsylvania, thirty miles outside Pittsburgh, became the campaign's most visible victim when attackers seized control of a booster station and renamed the compromised device "Gaza."
That was Phase Two of a four-phase evolution that cybersecurity researchers have now mapped in full. Phase One, from 2020 to 2022, consisted of propagandistic claims of Israeli infrastructure disruption with no verified technical substance behind them. Phase Three, running through 2024 and into 2025, introduced IOCONTROL, a custom Linux-based malware platform engineered to run across a wide range of IoT and OT devices — routers, HMIs, IP cameras, and fuel management systems from vendors including D-Link, Hikvision, Red Lion, Orpak, Phoenix Contact, Teltonika, and Unitronics — using MQTT over TLS specifically to blend malicious command traffic with legitimate network activity. Phase Four, which began in March 2026 and is the subject of AA26-097A, marks the transition that should be read as the single most significant strategic signal in the entire advisory: active exploitation of Rockwell Automation Logix controllers, a documented critical authentication bypass carrying a CVSS score of 9.8, followed by the July expansion to Siemens and Schneider Electric equipment.
This analysis is published. Your decision isn't.
We run the same cross-domain, scenario-based foresight on the decision in front of you — a deal, a market entry, a supplier dependency. Board-ready in five days, with a foresight indicator watchlist.