The following judgments apply ICD 203 confidence language. Each is falsifiable and paired with the evidence that would overturn it.
It is likely that the July 2026 United Kingdom power generation incident was conducted by CyberAv3ngers or a closely affiliated element operating under the IRGC Cyber-Electronic Command. This rests on convergence of timing, target profile, and declared strategic intent rather than on any technical indicator. Confidence is capped by the complete absence of published forensic detail and by the proliferation of the group’s tradecraft to a wide affiliate ecosystem, which materially weakens the inference from behaviour to actor.
Falsifier: release of indicators pointing to a non-Iranian actor, a criminal extortion motive, or an affiliate group operating outside IRGC-CEC direction.
It is assessed with moderate confidence that initial access was achieved against an internet-reachable operational technology asset — a programmable logic controller, a cellular gateway or modem serving one, or a remote-access service fronting the control network — rather than through phishing or supply-chain compromise of the corporate IT estate. The confirmed campaign pattern against comparable small operators is overwhelmingly one of direct exposure discovery, and small independent generators are structurally likely to present that exposure.
Falsifier: disclosure that the entry vector was email-borne, credential-stuffing against a corporate identity provider, or a managed service provider compromise.
It is assessed with low confidence that the specific mechanism was abuse of Rockwell Automation Studio 5000 Logix Designer via CVE-2021-22681 against a CompactLogix or Micro850 controller. This is the single best-documented mechanism in the concurrent campaign, but the July 2026 advisory update expanded confirmed targeting to Schneider Electric and Siemens platforms, and UK small-generator turbine and balance-of-plant control is at least as likely to be Siemens- or Schneider-based as Rockwell-based. The mechanism is plausible; the vendor specificity is not supported.
Falsifier: identification of a non-Rockwell control platform at the affected site, or of an entry vector unrelated to engineering-software impersonation.
It is highly likely that the operation was intended to demonstrate reach into UK critical national infrastructure rather than to inflict physical destruction or endanger life. Target selection below the statutory notification threshold for important generators, the negligible grid consequence, and the absence of escalation to a larger facility are all consistent with signalling. A destructive intent would have been better served by a different target set.
Falsifier: evidence of attempted equipment damage, deliberate safety-system defeat sustained to a physical limit, or parallel intrusions at higher-consequence sites.
It is a roughly even chance that the four-day outage reflects controller-integrity recovery — isolation, project-file validation, logic reload, and safety-interlock re-commissioning — as opposed to a precautionary shutdown ordered on suspicion of compromise with the duration driven by assurance and regulatory process rather than by actual malicious modification. Published reporting describes staff working to restore operations and does not distinguish between these. The distinction is operationally significant and currently unresolvable.
Falsifier: operator or NCSC confirmation of whether control logic was in fact altered.
It is likely that further intrusions against UK small and independent generators, water undertakings, and district energy operators will be attempted over the next six months, and roughly even chance that at least one produces a further disclosed operational disruption. The exposed-asset population has not materially changed, the primary enabling vulnerability has no vendor patch, and the tradecraft has proliferated beyond the originating unit to a large affiliate ecosystem with lower operational discipline.
This section establishes precisely what is known before any reconstruction is attempted. The separation is deliberate and is the load-bearing element of the assessment.
The following is the complete set of publicly reported fact regarding the UK event. It originates from a single originating outlet, with all subsequent coverage constituting aggregation rather than independent corroboration.
THE CENTRAL CONSTRAINT
Six of the sixteen elements above are the ones that would be required to describe an attack chain. All six are unavailable. Any technical narrative of this incident is therefore constructed, not reported.
This is not a reason to withhold analysis. It is a reason to label it correctly.
By contrast, the parallel activity in the United States is documented in detail by a joint advisory carrying substantial authorship weight. This material is confirmed and forms the legitimate analytic foundation for the reconstruction that follows.
Joint Cybersecurity Advisory AA26-097A was first published on 7 April 2026 and updated on 22 July 2026. Authoring agencies comprise the Federal Bureau of Investigation, the Cybersecurity and Infrastructure Security Agency, the National Security Agency, the Environmental Protection Agency, the Department of Energy, United States Cyber Command — Cyber National Mission Force, and the Department of the Treasury.
• Iranian-affiliated actors accessed internet-facing PLCs from foreign-based IP addresses using leased third-party hosted infrastructure.
• Actors installed and ran manufacturers’ own legitimate engineering software on that infrastructure — Rockwell Automation Studio 5000 Logix Designer, Schneider Electric EcoStruxure Control Expert, and Siemens Totally Integrated Automation Portal.
• That software was used to exfiltrate device project files from victim PLCs to actor-controlled infrastructure.
• Following extraction, the FBI and CISA identified modification and deletion of project file logic, including Add-On Instructions, together with data manipulation on HMI and SCADA displays.
• At a confirmed United States victim, the modifications disabled critical shutdown and alarm logic, permitting systems to enter unsafe conditions without operator notification.
• Inbound malicious traffic was observed against PLC ports 44818, 2222, 102 and 502, and against modems on port 22, including cases where Dropbear SSH was enabled for remote command and control.
• Explicitly named target devices include Rockwell Automation CompactLogix and Micro850 controllers.
• The 22 July update expanded observed manufacturer scope from Rockwell alone to include Schneider Electric, Siemens, and potentially other manufacturers, and added guidance on detecting malicious changes in reusable code modules.
• Named affected sectors: Government Services and Facilities, Water and Wastewater Systems, and Energy.
CVE-2021-22681 (CVSS 9.8) is an authentication bypass affecting Rockwell Automation Logix controllers. Rockwell has confirmed the flaw cannot be remediated by software update because it is architectural in nature, stemming from a shared cryptographic key embedded in the engineering software that cannot be changed without breaking legitimate deployments. The vulnerability was added to the CISA Known Exploited Vulnerabilities catalog in March 2026 following confirmed exploitation by Iranian-affiliated actors. There is no vendor patch; only compensating controls exist.
Between 26 and 27 July 2026, coordinated activity disrupted water and wastewater operations at more than thirty utilities in Minnesota, with subsequent incidents reported in Michigan, Georgia, South Dakota and New Jersey, and aggregate impact reported across twelve states. Effects included one plant shutdown, forced reversion to manual operation, flooding, loss of water pressure, and boil-water advisories. Attribution of the Minnesota cluster to CyberAv3ngers derives from Tenable Research Special Operations on the basis of operational pattern and timing; United States agencies have not issued official attribution for that cluster.
The reconstruction in Section 4 rests on a single analytic move: that a confirmed campaign, targeting a defined asset class, using a defined toolset, producing a defined effect, and occurring in the same calendar month, is the most probable explanation for an unexplained event of matching effect against a matching target profile in an allied nation.
That move is reasonable. It is also the weakest joint in the assessment, and it carries three specific liabilities that a reader must hold throughout:
1. Effect similarity is not mechanism similarity. A four-day generation outage is consistent with control-logic tampering, but equally consistent with an IT-side compromise triggering precautionary shutdown, with an OT network intrusion short of logic modification, or with a recovery timeline driven by assurance requirements rather than damage.
2. Sector transfer is not free. The confirmed campaign detail is dominated by water and wastewater victims running specific small-utility architectures. Power generation — even small-scale — differs in control platform, turbine protection design, and safety instrumented system independence.
3. Tradecraft has proliferated. Techniques have reportedly spread to sixty or more affiliated pro-Iranian groups coordinated through a joint operations structure. Behavioural matching to CyberAv3ngers is therefore substantially weaker as an attribution signal in 2026 than it was in 2023.
The actor profile below is well established in open reporting and is presented as confirmed background. It should not be read as evidence of involvement in the UK incident.
NOTE ON IOCONTROL
IOCONTROL is Phase Three capability. It is not referenced in the current advisory as a component of Phase Four activity, and there is no basis for asserting its presence in the UK incident.
Its documented characteristics — modified UPX packing, MQTT over TLS command and control on port 8883, DNS-over-HTTPS for resolution, AES-256-CBC configuration encryption, systemd persistence — remain valid detection content for the broader actor set. They are retained in Section 6 as hunting hypotheses, explicitly separated from campaign-confirmed indicators.
Phase Three indicator values, including the December 2024 sample hash and associated command-and-control domain, are historical. Treating them as current-campaign indicators would generate false assurance.
STATUS OF THIS SECTION
Everything that follows is INFERRED. No stage described has been observed at the United Kingdom facility. Each stage carries an independent confidence rating reflecting how well the confirmed campaign supports its transfer to this incident.
Confidence degrades across the chain. Early stages are strongly supported by campaign evidence and structural reasoning. Later stages are progressively more speculative.
Confidence: MODERATE
The actors are assessed to have identified the facility through untargeted internet-wide scanning rather than through deliberate selection of a named victim. The confirmed campaign is characterised by discovery-driven targeting: adversaries enumerate exposed industrial protocol services, then select from what responds. Scanning against EtherNet/IP services on ports 44818 and 2222, Siemens S7 on port 102, and Modbus TCP on port 502 yields banner responses disclosing device model, firmware revision, and in many cases whether authentication is enforced.
The victim profile is consistent with a structurally predictable exposure class rather than with strategic significance. Small independent generators — particularly intermittently dispatched gas-fired peaking plant — characteristically operate with no dedicated OT security function, rely on consumer-grade or cellular remote access to avoid staffed operation, and fall below the regulatory thresholds that drive assurance activity at larger sites. The UK Government’s own characterisation of the affected site as far below notification thresholds is, in this reading, precisely the reason it was reachable.
Analytic weight: strong. This stage requires no assumption beyond the confirmed campaign methodology and generic sector structure.
Confidence: LOW to MODERATE
Three candidate mechanisms are consistent with the confirmed campaign. They are presented in assessed order of likelihood, and the assessment does not select between them.
Under this pathway, the actors leased overseas virtual private server infrastructure, installed the relevant vendor engineering suite, and connected to the exposed controller as though from a legitimate engineering workstation. Where the platform is Rockwell Logix, CVE-2021-22681 permits authentication to be satisfied without valid user credentials: the shared cryptographic key that the controller uses to verify that traffic originates from genuine Rockwell software can be recovered from the software itself or intercepted from unprotected EtherNet/IP traffic. Possession of that key is sufficient to impersonate authorised engineering software. Because the weakness is architectural, no patch closes it — only network isolation, CIP Security, and controller keyswitch discipline mitigate.
Equivalent access under Schneider EcoStruxure Control Expert or Siemens TIA Portal does not require this specific CVE; where controllers are exposed without enforced authentication or with default protection, the engineering suite alone is sufficient. This is materially important: the campaign does not depend on the Rockwell flaw, and the UK platform is unknown.
Compromise of a consumer-grade remote desktop tool, an unauthenticated cellular gateway, or a vendor maintenance channel serving the control network. This pathway is well precedented in the sector and would produce an indistinguishable outcome. It is under-represented in the confirmed advisory content only because that content is written around directly exposed controllers.
Corporate network compromise followed by traversal into the control environment through inadequate segmentation. Assessed least likely on the basis of campaign pattern, but not excluded, and would be the expected finding if the incident proves to have originated in a business-system intrusion.
Analytic weight: moderate for the class of access; weak for any specific mechanism. The frequent public framing of this incident as a CVE-2021-22681 exploitation is an assumption, not a finding.
Confidence: LOW
Where the confirmed campaign methodology was applied, the following sequence would be expected:
1. Extraction of the controller project file, containing the full control programme — logic, tuning parameters, alarm thresholds, interlock definitions, and shutdown sequences — to actor infrastructure.
2. Offline analysis of that programme to identify the safety and alarm constructs, and the reusable code modules through which changes propagate across multiple control loops.
3. Modification of logic to disable or neutralise shutdown and alarm functions, such that out-of-bound process conditions no longer trigger automated protective response or operator notification.
4. Adjustment of process parameters — setpoints, thresholds, actuator positions — to drive the plant toward conditions it could not safely sustain.
5. Redeployment of the altered programme to the controller, displacing the legitimate logic.
The addition of Add-On Instruction detection guidance to the July advisory update indicates the actors are editing reusable code constructs rather than only top-level routines. This is operationally significant: a single modified reusable module can alter behaviour across many control loops simultaneously, and integrity verification limited to the main programme will not detect it.
Analytic weight: this is confirmed campaign behaviour in the United States. Its occurrence in the United Kingdom is entirely unverified. It is equally possible that access was obtained without logic modification, and that the outage reflects a precautionary response.
Confidence: LOW
The confirmed campaign includes falsification of data presented on HMI and SCADA displays, executed concurrently with the logic modification. The effect is that operators observe nominal process values while the physical plant responds to adversarial logic. Automated protection is disabled and the human backstop is simultaneously blinded.
This dual manipulation is the actor’s most consequential technical characteristic. Defeating the safety instrumented function alone leaves an operator able to intervene on observation; falsifying the view alone leaves automated protection intact. Doing both removes the layered assumption on which operational safety cases are generally written. The capability class has previously been associated principally with Sandworm operations against Ukrainian grid infrastructure, and its appearance in a proliferating affiliate ecosystem is the most strategically significant element of this campaign.
Analytic weight: confirmed for the campaign; unverified for this incident. If applied at the UK site, it would substantially explain a four-day recovery, since assurance would require independent verification of every display mapping in addition to the control logic itself.
Confidence: LOW
Campaign-confirmed persistence centres on SSH access to modems and gateways rather than to controllers themselves, with Dropbear SSH enabled on port 22 for remote command and control. This distinction matters for response scoping: an integrity programme addressing only the PLC leaves the actual persistence mechanism intact on the communications device.
Malicious logic resident in a redeployed project file constitutes persistence in its own right, surviving controller restart and power cycling, and will be reintroduced by any restore from a compromised backup. Ongoing interaction would be expected over the same industrial protocol ports used for access.
Analytic weight: weak for this incident. No persistence mechanism has been reported. Assertions that IOCONTROL was deployed are unsupported for Phase Four activity generally and for this event specifically.
If the reconstruction holds, a four-day restoration is proportionate. Recovery from suspected control-logic compromise at a site without mature OT assurance requires, at minimum:
• Physical isolation of the controller and all associated communications equipment from external connectivity.
• Establishment that a known-good project file exists and has not itself been contaminated — frequently the longest single step, as many small operators hold only online or vendor-held backups of uncertain provenance.
• Reload of trusted logic and full re-verification of interlocks, alarm thresholds, and shutdown sequencing.
• Independent validation that HMI and SCADA display mappings report true process state.
• Examination of gateways, modems and engineering workstations for persistence.
• Re-commissioning and safe-operation demonstration, potentially with regulator or insurer involvement.
The same four days are equally consistent with a precautionary shutdown in which most of that programme was executed and found nothing. Duration alone does not discriminate between the two, and no published detail does either.
Structured evaluation of alternatives to the primary reconstruction. Likelihood reflects assessed probability given currently available reporting.
DIAGNOSTIC PRIORITY
H1 and H2 are the operative competition, and they are separated by a single unpublished fact: whether control logic was actually altered.
Every subsequent question — severity characterisation, adequacy of the UK regulatory threshold, whether the actor demonstrated intent or merely capability — turns on that one determination.
DIAGNOSTIC PRIORITY
H1 and H2 are the operative competition, and they are separated by a single unpublished fact: whether control logic was actually altered.
Every subsequent question — severity characterisation, adequacy of the UK regulatory threshold, whether the actor demonstrated intent or merely capability — turns on that one determination.
Ordered by risk reduction per unit of effort. The first control subsumes most of the remainder.
1. Remove operational technology assets from direct internet exposure. This is the central directive of the advisory and the single change that invalidates the entire discovery-driven access model.
2. Where remote access is operationally required, route it exclusively through VPN with multi-factor authentication. Consumer-grade remote desktop tooling is explicitly inadequate.
3. Inventory external exposure independently of asset registers. Enumerate against 44818, 2222, 102, 502, 20000 and 22 from outside the perimeter. Cellular-connected gateways installed by integrators are routinely absent from formal inventory.
4. Establish offline, integrity-verified project file baselines with cryptographic hashing, and validate that restoration from them has been tested. A backup of unknown provenance is not a recovery capability.
5. Implement periodic project file and Add-On Instruction integrity comparison against baseline. Verification limited to the main programme will not detect modification of reusable modules.
6. Enforce controller keyswitch discipline — physical mode selector in RUN — where the platform supports it, and deploy CIP Security or equivalent authenticated transport.
7. Independently verify that HMI and SCADA display values correspond to true field state. Physical instrument comparison against displayed values should be a routine assurance activity, not an incident-only one.
8. Audit modems, cellular gateways and communications equipment for unexpected SSH services. Persistence in this campaign sits on the communications device, not the controller.
9. Extend scope beyond Rockwell. Schneider Electric and Siemens platforms are confirmed in scope as of the July 2026 update.
Formulated for detection engineering. Each is a hypothesis to be tested against telemetry, not an indicator of confirmed compromise.
• Engineering software sessions to controllers originating from network locations outside the defined engineering workstation set, particularly from hosting provider or VPS address space.
• Project file upload or download operations occurring outside scheduled maintenance windows, or from an unexpected source.
• Controller programme change events without a corresponding change management record — the highest-value single detection in this campaign.
• Add-On Instruction or reusable module modification, distinguished from main-routine change.
• Alarm and interlock configuration changes, including disablement, threshold widening, or suppression.
• Divergence between historian-recorded process values and independently sourced field instrumentation — the primary technical means of detecting view manipulation.
• New SSH listeners on communications equipment, and outbound SSH from OT segments.
• Outbound MQTT over TLS on port 8883 from OT segments, and DNS-over-HTTPS resolution from devices with no legitimate requirement. Phase Three tradecraft; retained as a hunting hypothesis only.
• Inbound connections to industrial protocol ports from previously unobserved external sources, correlated against scanning-service address space.
The UK Government position — that the affected site sits far below the notification threshold for important generators and represents a rounding error against grid capacity — is accurate as a statement of grid consequence and simultaneously a description of the vulnerability. Assurance regimes scale with consequence. Adversary access scales with exposure. Where those two curves diverge, the least regulated assets become the most reachable, and demonstration effects can be achieved without touching a regulated entity.
This has a direct read-across to the United States, where the confirmed victim population is dominated by small water and wastewater systems that are similarly below the effective reach of assurance activity. The pattern in both jurisdictions is not adversary sophistication defeating strong defences; it is adversary opportunism finding assets that no regime requires anyone to defend.
The reported spread of this tradecraft to a large affiliate ecosystem changes the defensive calculus in two ways. First, it degrades behavioural attribution: technique matching no longer identifies the originating unit with useful confidence. Second, and more consequentially, it distributes a capability for defeating safety systems and operator visibility to actors with materially lower operational discipline than the originating unit. The risk of unintended physical consequence rises accordingly, and it rises independently of any decision taken in Tehran.
CVE-2021-22681 will not be fixed. The architectural nature of the flaw means the exposed Logix population remains permanently vulnerable to engineering-software impersonation wherever it is network-reachable, for the remaining service life of the installed base — measured in decades. Every mitigation available is a compensating control that assumes the attacker cannot reach the device. Where that assumption fails, there is no second layer. Defensive planning should treat network reachability of these controllers as the terminal control, not as one control among several.
• Publication of technical detail by NCSC or the operator — particularly control platform and whether logic was modified. This would resolve H1 against H2 and would validate or invalidate Sections 4.2 through 4.5 in their entirety.
• Formal UK Government attribution to a named actor.
• Disclosure of indicators shared under the Government’s sector briefing to power company chief executives.
• Identification of additional UK victims, which would shift the assessment from demonstration toward campaign.
• Evidence of targeting above the notification threshold, which would represent material escalation in intent.
SINGLE-SOURCE DEPENDENCY
The entirety of UK incident reporting derives from one originating exclusive. The apparent breadth of coverage is syndication, not corroboration.
This does not indicate the reporting is wrong — the Government response is consistent with a real event. It does mean the factual base supports far less analytic weight than the volume of coverage might suggest, and that any subsequent correction to the originating report propagates to everything built on it, including this assessment.
ICD 203 terminology is applied throughout. Likelihood expressions carry their standard meanings: almost no chance, very unlikely, unlikely, roughly even chance, likely, very likely, almost certain. Confidence levels — low, moderate, high — describe the strength of the evidentiary base underlying a judgment and are stated independently of likelihood. A high-likelihood judgment held with low confidence is a legitimate and, in this product, common construction.
• The core limitation is stated plainly: no technical information about the UK incident is available. Sections 4 through 6 describe a confirmed campaign and hypothesise its application. They do not describe what happened at the affected site.
• Reasoning by campaign analogy is inherently vulnerable to confirmation bias. A prominent, well-documented, temporally adjacent campaign will attract explanation of an unexplained event regardless of actual causation.
• The confirmed campaign evidence base is US-centric and water-sector-weighted. Transfer to UK power generation carries unquantified error.
• Reporting is approximately 24 hours old at publication. Early reporting on infrastructure incidents is frequently revised.
• This assessment intentionally avoids resolving Stage 2 to a single mechanism. Analysis asserting CVE-2021-22681 exploitation at the UK site as established fact should be treated as unsupported.
This product is derived entirely from open sources and contains no privileged or client information. It is suitable for onward distribution. If reproduced in part, the Analytic Caution on the cover page and the observed-versus-inferred partition in Section 2 should be retained; extracting Section 4 in isolation would misrepresent the evidentiary basis of the analysis.
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.