
The U.S. government is alerting that hackers supported by the Iranian state are currently infiltrating and disrupting industrial control systems at American water and energy companies. This recent warning comes after federal agencies indicated a rise in hacking from Iranian entities amid the ongoing conflict.
In an advisory released Wednesday, the FBI, NSA, Department of Energy, and CISA reported that Iranian hackers are focusing on programmable logic controllers within internet-connected operational networks, enabling them to alter data displayed, leading to outages and disturbances.
Earlier this year, the Iranian hackers were found to be targeting Rockwell-made controllers, but the advisory has since broadened to include industrial control systems from Schneider Electric and Siemens.
The agencies cautioned that “potentially all internet exposed” industrial control systems might be impacted and encouraged critical infrastructure owners to take preventive measures. According to the advisory, the Iranian-affiliated hackers were “conducting this activity to cause disruptive effects within the United States,” likely as a reaction to the ongoing conflict involving Iran, the U.S., and Israel.
The FBI stated that the hackers gained access to one critical infrastructure provider and altered the programming logic of the controllers to disable processes responsible for crucial shutdowns and alarms. The authorities noted this permitted “systems to enter unsafe conditions without alerting operators to the discrepancies.”
This is the latest in a wave of cyberattacks executed by Iranian government hackers and their affiliates throughout the region since the conflict began in February.
The hacks have varied from the typical espionage and hack-and-leak strategies, such as exposing the personal email account of FBI director Kash Patel, to more unusual destructive hacks that have resulted in extensive damage or disruptions. Among the more significant incidents was an attack on the U.S. medical technology company Stryker, which enabled the Iranian hacking group “Handala” to remotely erase tens of thousands of employee devices.
Handala also claimed responsibility for a data breach involving California’s water supplier Cal Water in June, asserting it could have compromised the water supply (without providing proof). The water supplier stated it found no indication of unauthorized access to its operational networks, which manage the water supplies.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

