HomeAll NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Iran-linked hackers targeting US water and energy providers, government warns

Created at 23 Jul · 6:06 PM1 source↑ Market-relevant
IN SHORT

US government agencies issued a warning that Iran-backed hackers are actively targeting and disrupting industrial control systems at American water and energy providers. The attacks aim to cause disruptive effects within the United States, likely in response to the ongoing war.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Who's Involved

FBI
agency issuing cybersecurity advisory
NSA
agency issuing cybersecurity advisory
Department of Energy
agency issuing cybersecurity advisory
CISA
agency issuing cybersecurity advisory
Rockwell
manufacturer of targeted industrial control systems
Schneider Electric
manufacturer of targeted industrial control systems
Siemens
manufacturer of targeted industrial control systems
Handala
Iranian hacking group
Cal Water
California water provider affected by data breach
Iran-linked hackers targeting US water and energy providers, government warns

↳ Why This Matters

The coordinated cyberattacks by Iran-linked hackers on critical U.S. infrastructure pose a significant national security threat, potentially leading to widespread disruptions in essential services like water and energy supply, and escalating geopolitical tensions.

Key facts

  • Iranian state-backed hackers are actively targeting and disrupting industrial control systems at US water and energy providers.
  • The hackers manipulate programmable logic controllers on internet-connected operational networks to cause outages.
  • The advisory expanded the types of industrial control systems under attack to include products from Schneider Electric and Siemens.
  • The goal of the cyberattacks is to cause disruptive effects within the United States.
  • The activity is likely in response to the ongoing war between Iran, the US, and Israel.

The U.S. government has issued a stark warning regarding Iranian state-backed hackers actively targeting and disrupting industrial control systems at American water and energy providers. The advisory, updated by the FBI, NSA, Department of Energy, and CISA, highlights that these actors are manipulating programmable logic controllers on internet-connected operational networks. This manipulation allows them to alter data on displays, leading to outages and disruptions.

Initially discovered targeting controllers made by Rockwell, the scope of the attacks has now expanded to include products from Schneider Electric and Siemens. The agencies caution that "potentially all internet exposed" industrial control systems could be affected and urge critical infrastructure owners to implement protective measures. The advisory states that the hackers are conducting this activity to cause disruptive effects within the United States, likely as retaliation for the ongoing conflict involving Iran, the U.S., and Israel.

One instance detailed by the FBI involved hackers altering a critical infrastructure provider's controller programming to disable essential shutdown and alarm processes, allowing systems to enter unsafe conditions without operators being alerted. This marks an escalation in cyberattacks from Iranian government hackers and their proxies since the war began in February, moving beyond typical espionage to more destructive actions.

Notable past incidents include a hack on U.S. medical tech giant Stryker, where the group Handala remotely wiped tens of thousands of employee devices. Handala also claimed responsibility for a June data breach affecting California water provider Cal Water, though the provider stated there was no evidence of unauthorized access to its operational networks.

Frequently asked questions

Iranian hackers are targeting programmable logic controllers on internet-connected operational networks, including those made by Rockwell, Schneider Electric, and Siemens.

The hackers are conducting this activity to cause disruptive effects within the United States, likely in response to the ongoing war between Iran, and the U.S. and Israel.

The attacks can manipulate data on displays, cause outages, and disable critical shutdown and alarm processes, potentially leading to unsafe conditions without operators being notified.

What Happens Next

01Critical infrastructure owners are urged to take action to protect their systems.
02Further advisories may be issued detailing new threats or vulnerabilities.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

US government agencies warned of Iranian state-backed hackers targeting industrial control systems.
Hackers are manipulating programmable logic controllers to cause outages and disruption.
The advisory expanded the types of industrial control systems under attack.
Iranian hackers disabled critical shutdown and alarm processes at one provider.
The activity is likely a response to the ongoing war between Iran, the US, and Israel.
Sponsored

London Quick Take - 22 July - UK inflation softens, oil rises and chips rally ahead of Alphabet, Tesla earnings

SAXO

Sources

T1
US government says Iran-linked hackers are disrupting American water and energy providersTechCrunch

Related Stories

IRGC claims missile, drone strikes on US bases in Kuwait, Bahrain, Jordan
23 Jul · 4:46 AM
Trump Vows Punishment for Iran After Houthi Red Sea Tanker Attacks
23 Jul · 2:41 AM
Iran vows 'eye for an eye' after US strike kills two on Iraq border
23 Jul · 2:41 AM
US warns citizens in Middle East to exercise caution amid escalating conflict
23 Jul · 3:31 AM
US strikes damage two naval vessels in Iran's Hormozgan
23 Jul · 4:26 AM