US Warns Iran-Linked Hackers Target Water and Energy Systems
3 min read
U.S. federal agencies have issued a fresh cybersecurity warning after discovering that Iran-linked state-backed hackers are actively targeting critical infrastructure across the country, including water and energy providers.
The updated advisory, released on Wednesday by the FBI, the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the Department of Energy, says the hackers are compromising industrial control systems that manage essential services. Officials warned that the attacks are capable of disrupting operations and creating potentially unsafe conditions.
According to the advisory, the hackers have been targeting programmable logic controllers (PLCs) connected to the internet through operational technology (OT) networks. Once inside, attackers can manipulate the information displayed to operators, interfere with system functions, and potentially trigger service outages or operational disruptions.
Federal agencies first identified the campaign earlier this year when Iranian hackers were found targeting industrial controllers manufactured by Rockwell Automation. The latest warning expands the list of affected equipment to include products from Schneider Electric and Siemens, suggesting that the scope of the attacks has grown.
Authorities cautioned that virtually any internet-exposed industrial control system could be at risk. They urged operators of critical infrastructure to strengthen their cybersecurity defenses and secure operational networks against potential intrusions.
The advisory states that the hackers are believed to be conducting these operations to create disruptive effects inside the United States. Officials linked the activity to ongoing geopolitical tensions involving Iran, the United States, and Israel.
One confirmed incident highlighted by the FBI involved an attack on a U.S. critical infrastructure provider. Investigators said the hackers altered the programming logic of programmable logic controllers responsible for critical shutdown procedures and alarm systems.
By modifying those settings, the attackers reportedly disabled safety-related processes, allowing systems to enter unsafe operating conditions without alerting operators to the abnormalities. Such attacks could significantly increase operational risks if not detected quickly.
The latest warning follows several months of increased cyber activity attributed to Iranian government-backed hacking groups and affiliated organizations since the conflict began in February.
These operations have included both traditional cyber espionage and more destructive attacks aimed at disrupting organizations. Earlier this year, hackers claimed responsibility for breaching the personal email account of FBI Director Kash Patel. Another major incident targeted U.S. medical technology company Stryker, where the Iranian-linked hacking group known as Handala reportedly wiped tens of thousands of employee devices remotely, causing widespread disruption.
Handala also claimed responsibility for a data breach involving California-based water provider Cal Water in June. The group alleged it had the ability to disrupt the company’s water supply, although it did not provide evidence supporting that claim.
Cal Water later stated that its investigation found no signs of unauthorized access to the operational technology networks responsible for managing water distribution, indicating that the company’s water systems remained unaffected.
The latest advisory highlights growing concerns about cyber threats targeting America’s critical infrastructure. With hackers increasingly focusing on operational technology rather than traditional IT systems, federal agencies continue urging organizations to reduce internet exposure, strengthen network security, and closely monitor industrial control environments for suspicious activity.
As cyberattacks become more sophisticated and increasingly tied to geopolitical conflicts, protecting essential infrastructure remains a top priority for U.S. cybersecurity agencies.
Also read : DoorDash Launches Drone Delivery Unit After FAA Approval
