Iranian state-backed hackers are actively disrupting critical US water and energy infrastructure to cause widespread chaos amidst escalating geopolitical tensions, federal agencies warned on Wednesday.
Critical Infrastructure Under Active Attack
In an updated joint advisory, the FBI, the NSA, the Department of Energy, and the Cybersecurity and Infrastructure Security Agency (CISA) revealed that cyber operatives are targeting programmable logic controllers (PLCs) linked to the internet. By infiltrating these operational networks, the attackers can manipulate display data, triggering severe operational outages and service disruptions.
While initial intelligence identified targets using Rockwell automation controllers, the threat has now expanded. Federal authorities have broadened their warning to include industrial control systems manufactured by global giants Schneider Electric and Siemens.
Disabling Safety Alarms and Controls
The implications of these breaches are highly alarming. Security agencies warn that virtually any internet-exposed industrial control system is vulnerable. According to intelligence reports, the Iranian-sponsored actors are executing these hostile campaigns to trigger disruptive real-world impacts across the United States, driven by ongoing conflicts involving the US, Israel, and Iran.
In one chilling incident detailed by the FBI, hackers breached a critical utility provider and altered the controllers’ programming logic. This malicious modification disabled the automated processes responsible for emergency shutdowns and safety alarms, allowing the facility to operate under highly hazardous conditions without alerting system operators.
A Broader Campaign of Cyber Warfare
This offensive represents the latest escalation in a sustained cyber campaign launched by Tehran-affiliated groups and their regional proxies since February. These operations have transitioned from traditional cyber espionage and targeted data leaks to highly destructive, physical-world disruptions.
Recent high-profile operations include the compromise and leak of personal emails belonging to FBI Director Kash Patel. More aggressively, a destructive attack on US medical technology giant Stryker—attributed to the Iranian hacking collective “Handala”—resulted in the remote wiping of tens of thousands of corporate devices.
The same group, Handala, also claimed responsibility for a June cyberattack targeting California utility provider Cal Water, boasting that they had the capability to compromise the local water supply. However, Cal Water later confirmed that there was no evidence of unauthorised access to its operational technology networks, ensuring the safety of the water distribution system.
