Published August 2, 2026 | Version v1

Ambient Authority at the Controller: A Detection Engineering Analysis of the July 2026 Iranian-Affiliated Water-Sector PLC Campaign

  • 1. Saluca Labs

Description

Between roughly 26 and 27 July 2026, an actor tracked as CyberAv3ngers, assessed by the United States intelligence community to be directed by Iran's IRGC Cyber-Electronic Command, ran a coordinated intrusion set against internet-exposed programmable logic controllers (PLCs) at United States drinking-water and wastewater utilities, affecting more than thirty municipal systems in Minnesota before spreading to Michigan and at least five further states. Unlike the group's 2023 Unitronics campaign, the 2026 activity manipulated controller program logic, Add-On Instructions, and alarm parameters to disable safety-shutdown behavior, producing loss of monitoring and control and, in some cases, pressure loss and localized flooding. The benign safety outcome was contingent on human operators noticing the tamper and reverting, not on the control system refusing an unsafe command.

This report converts the CISA/FBI/EPA joint advisory AA26-097A and the public forensic picture into detection-engineering guidance. It contributes a 22-entry detection catalog and a 21-item control checklist, each mapped to MITRE ATT&CK for ICS, ranked by evasion resistance and proximity to physical impact, with Sigma, Suricata/Snort, and Zeek logic included. It argues that the root enabler is a general anti-pattern, fused ambient authority: the co-location of standing reachability and standing capability on a single asset, with no per-action policy mediating writes and no tamper-evident record of them, and that the same anti-pattern and the same governing controls (deny-by-default per-action policy, cryptographic identity, tamper-evident logging) apply to autonomous AI agents holding ambient authority over connected tools. The report contains only defensive material and no exploitation guidance.

AI disclosure. Prepared by the Saluca Agentic AI Research Team with Cristian Ruvalcaba as human author and editor, consistent with prior Saluca Labs publications.

This analysis is independent and is not endorsed by CISA, the FBI, the EPA, Rockwell Automation, Schneider Electric, Siemens, or any party named in it. Attribution to Iran is a United States intelligence-community assessment, not an adjudicated fact, and the incident is still developing.

Notes

Companion to the Saluca Labs report 'Machine-Speed Intrusion' (Zenodo, DOI 10.5281/zenodo.21686547). Defensive material only; no exploitation guidance. Incident analysis current to 2026-08-01. The deposit file is a single combined whitepaper (Markdown and PDF).

Files

ambient-authority-at-the-controller-v1.0.md

Files (103.8 kB)

Name Size Download all
md5:5877d98b1ff8dd27f3f59c3e82e494a7
28.1 kB Preview Download
md5:f0dab332127b8931743ab20ba3b87fed
75.7 kB Preview Download

Additional details