Key Takeaways
- Iranian state-backed hackers are targeting U.S. water and energy systems.
- Federal agencies warn of potential disruptions to critical infrastructure.
- Recent attacks have involved manipulating industrial control systems.
- Ongoing geopolitical tensions may be driving these cyberattacks.
Ongoing Cyber Threats
The U.S. government has issued a warning regarding Iranian hackers who are actively disrupting industrial control systems at American water and energy providers. This alert follows previous warnings about an increase in cyberattacks from Iranian actors amid escalating tensions in the region.
Details of the Attacks
In an advisory released recently, the FBI, NSA, Department of Energy, and CISA reported that Iranian hackers are targeting programmable logic controllers on operational networks connected to the internet. This access allows them to manipulate data displays, leading to outages and operational disruptions.
Initially, these hackers were found to be focusing on controllers manufactured by Rockwell. However, the advisory has since broadened to include systems from Schneider Electric and Siemens, indicating a wider range of potential vulnerabilities.
Impact on Critical Infrastructure
The advisory warns that nearly all internet-exposed industrial control systems could be at risk. The Iranian-backed hackers are reportedly conducting these operations to create disruptions within the United States, likely as a reaction to the ongoing conflict involving Iran, the U.S., and Israel.
According to the FBI, one incident involved hackers breaching a critical infrastructure provider and altering the programming logic of controllers. This manipulation disabled processes essential for critical shutdowns and alarms, allowing systems to enter unsafe conditions without alerting operators.
Recent Cyber Incidents
This development is part of a broader pattern of cyberattacks attributed to Iranian government hackers and their affiliates since the onset of the war in February. These attacks have included traditional espionage tactics as well as more destructive operations that have caused significant disruptions.
One notable incident involved the U.S. medical technology company Stryker, where the Iranian hacking group known as Handala remotely wiped thousands of employee devices. Handala also claimed responsibility for a data breach affecting California’s Cal Water in June, suggesting it could have disrupted the water supply, although the company reported no evidence of unauthorized access to its operational networks.
