The U.S. government is warning that Iranian state-backed hackers are actively breaking in and disrupting industrial control systems at American water and energy providers. This new alert comes months after federal agencies warned of an escalation in hacking from Iranian actors amid the ongoing war.
In an advisory updated Wednesday, the FBI, the NSA, the Department of Energy, and CISA said Iranian hackers were targeting programmable logic controllers on internet-connected operational networks, allowing them to manipulate data on their displays, causing outages and disruption.
The Iranian hackers were initially discovered earlier this year to be targeting controllers made by Rockwell, but the advisory has now expanded the types of industrial control systems under attack to include products from Schneider Electric and Siemens.
The agencies warn that “potentially all internet exposed” industrial control systems may be affected, and urged critical infrastructure owners to take action. Per the advisory, the Iranian-backed hackers were “conducting this activity to cause disruptive effects within the United States,” likely in response to the ongoing war between Iran, and the U.S. and Israel.
According to the FBI, the hackers broke into one critical infrastructure provider and changed the controllers’ programming logic to disabled processes that handled critical shutdowns and alarms. The feds said this allowed “systems to enter unsafe conditions without notifying operators of the anomalies.”
This is the latest in a series of cyberattacks launched by Iranian government hackers and their proxies across the region since the start of the war in February.
The hacks have ranged from the country’s typical espionage and hack-and-leak operations, such as leaking the contents of the FBI director Kash Patel’s personal email account, to more atypical destructive hacks that have caused large-scale damage or disruption. Among the more notable incidents was a hack on the U.S. medical tech giant Stryker, which allowed the Iranian hacking group “Handala” to remotely wipe tens of thousands of employee devices.
Handala also took credit for a data breach affecting California water provider Cal Water in June, and claimed it could have disrupted the water supply (without providing evidence). The water provider said that it saw no evidence of unauthorized access to its operational networks, which control the water supplies.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security.
He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com.
October 13 – 15 San Francisco Scale faster. Grow your portfolio. Gain practical expertise. No matter your goal, Disrupt can empower you.Save up to $330 today!
Most Popular OpenAI says Hugging Face was breached by its pre-release models Russell Brandom
Jack Dorsey is taking on Slack with Buzz, a group chat platform for teams and their AI agents Amanda Silberling
Light made a flip phone — it’s colorful and it’s cheap Amanda Silberling
AI music generator Suno breach affects 55M users, per Have I Been Pwned Zack Whittaker
Anthropic’s landmark $1.5B copyright settlement is approved Kirsten Korosec
Google is working on a new AI chip designed to make Gemini more efficient Lucas Ropek
Judge pauses $110B Paramount-Warner Bros. merger Aisha Malik
---
**İlgili Kaynaklar:**
SEO ve GEO eğitim platformu konusunda [GEO eğitim](https://geoakademi.com) ile iletişime geçebilirsiniz.