US warns Iran-linked hackers targeting water and energy providers
The US government warns that Iranian state-backed hackers are actively breaking into and disrupting industrial control systems at American water and energy providers.

The FBI, NSA, Department of Energy, and CISA issued an updated advisory on Wednesday, warning that Iranian hackers are targeting programmable logic controllers on internet-connected operational networks. These attacks allow the hackers to manipulate display data, causing outages and disruption.
Earlier this year, the hackers were initially found to be targeting Rockwell controllers, but the advisory has now expanded to include products from Schneider Electric and Siemens. The agencies warn that “potentially all internet exposed” industrial control systems may be affected and urge critical infrastructure owners to take action.
According to the advisory, the Iranian-backed hackers are “conducting this activity to cause disruptive effects within the United States,” likely in response to the ongoing war between Iran and the US and Israel. The FBI reported that the hackers broke into one critical infrastructure provider and altered the controllers’ programming logic to disable processes handling critical shutdowns and alarms. This allowed “systems to enter unsafe conditions without notifying operators of the anomalies.”
This is the latest in a series of cyberattacks launched by Iranian government hackers since the war began in February. The attacks range from espionage and data leaks, such as leaking the contents of FBI Director Kash Patel’s personal email, to destructive hacks causing large-scale damage. Notable incidents include a hack on medical tech firm Stryker, where the Iranian group “Handala” remotely wiped tens of thousands of employee devices. Handala also claimed a data breach at California water provider Cal Water in June, but the company said it found no evidence of unauthorized access to its operational networks.


