Key facts
- Iranian state-backed hackers are actively targeting and disrupting industrial control systems at US water and energy providers.
- The hackers manipulate programmable logic controllers on internet-connected operational networks to cause outages.
- The advisory expanded the types of industrial control systems under attack to include products from Schneider Electric and Siemens.
- The goal of the cyberattacks is to cause disruptive effects within the United States.
- The activity is likely in response to the ongoing war between Iran, the US, and Israel.
The U.S. government has issued a stark warning regarding Iranian state-backed hackers actively targeting and disrupting industrial control systems at American water and energy providers. The advisory, updated by the FBI, NSA, Department of Energy, and CISA, highlights that these actors are manipulating programmable logic controllers on internet-connected operational networks. This manipulation allows them to alter data on displays, leading to outages and disruptions.
Initially discovered targeting controllers made by Rockwell, the scope of the attacks has now expanded to include products from Schneider Electric and Siemens. The agencies caution that "potentially all internet exposed" industrial control systems could be affected and urge critical infrastructure owners to implement protective measures. The advisory states that the hackers are conducting this activity to cause disruptive effects within the United States, likely as retaliation for the ongoing conflict involving Iran, the U.S., and Israel.
One instance detailed by the FBI involved hackers altering a critical infrastructure provider's controller programming to disable essential shutdown and alarm processes, allowing systems to enter unsafe conditions without operators being alerted. This marks an escalation in cyberattacks from Iranian government hackers and their proxies since the war began in February, moving beyond typical espionage to more destructive actions.
Notable past incidents include a hack on U.S. medical tech giant Stryker, where the group Handala remotely wiped tens of thousands of employee devices. Handala also claimed responsibility for a June data breach affecting California water provider Cal Water, though the provider stated there was no evidence of unauthorized access to its operational networks.
