The U.S. government has issued a stark new warning that Iranian state-backed hackers are actively compromising and disrupting industrial control systems (ICS) at American water and energy utilities. The advisory, updated Wednesday by the FBI, the National Security Agency (NSA), the Department of Energy, and the Cybersecurity and Infrastructure Security Agency (CISA), details ongoing attacks that have moved beyond initial targets and now pose a wider threat to critical national infrastructure.
This alert escalates concerns first raised in April, when agencies warned that Iranian hackers were targeting programmable logic controllers (PLCs) from Rockwell Automation. The updated advisory expands the scope of the campaign to include systems manufactured by Schneider Electric and Siemens. The core of the attack involves exploiting internet-connected operational technology (OT) networks to gain access to these controllers, which act as the brains for machinery managing water pressure, energy distribution, and other essential functions.
How the Iranian Hacks Are Disrupting Industrial Systems
The primary method of disruption involves manipulating the data displayed on human-machine interfaces (HMIs). By altering the readings that operators rely on to monitor plant conditions, attackers can hide dangerous failures or mask the true state of equipment. In one confirmed incident described by the FBI, hackers changed a controller’s programming logic to disable critical safety functions, specifically those handling emergency shutdowns and alarms. The advisory states this allowed “systems to enter unsafe conditions without notifying operators of the anomalies,” creating a scenario where a minor fault could escalate into a serious industrial accident.
Agencies now warn that “potentially all internet exposed” PLCs and ICS devices could be vulnerable if not properly secured. The hackers are conducting this activity to cause “disruptive effects within the United States,” which federal officials assess is a direct response to the ongoing geopolitical conflict involving Iran, the U.S., and Israel. This marks a significant shift from the Iranian espionage and information operations seen in recent years to more aggressive, destructive cyberattacks aimed at physical-world consequences.
Confirmed and Unconfirmed Incidents
The advisory provides concrete evidence of one critical infrastructure provider where safety systems were deliberately compromised. This incident is part of a broader campaign that has included a variety of destructive operations. In a separate, high-profile case, the Iranian-linked hacking group “Handala” claimed responsibility for a data breach affecting the California water provider Cal Water in June. The group alleged it could have disrupted the water supply, though it provided no evidence for this claim and Cal Water stated it found no unauthorized access to its operational networks.
Other notable attacks attributed to Iranian state-linked actors include the data breach and leak of FBI Director Kash Patel’s personal email account and a destructive hack on U.S. medical technology giant Stryker. In that incident, the Handala group remotely wiped tens of thousands of employee devices, demonstrating a capability for large-scale digital destruction that goes beyond simple espionage.
What the Broader Campaign Reveals
The range of attacks—from espionage and data theft to disruptive operations against industrial controls—signals a escalation in Iranian cyber capabilities and intent. The targeting of OT systems is particularly concerning because these controls were historically air-gapped (physically isolated from the internet). The advisory’s focus on “internet exposed” systems suggests that many critical utilities still have insecure connections between their corporate IT networks and their operational technology, a common vulnerability known as an IT/OT gap. By breaking through this gap, attackers can move from stealing data to manipulating the physical world.
How Can Organizations Protect Against These ICS Attacks?
For critical infrastructure operators, the primary defense is to immediately reduce the attack surface. The advisory urges owners to ensure no industrial control system is directly accessible from the public internet. If remote access is required, it must be secured through a multi-factor authentication (MFA) solution and a segmented virtual private network (VPN). For organizations assessing their security posture, the immediate step is deploying a robust endpoint detection and response (EDR) solution designed specifically for OT environments, combined with rigorous network segmentation that prevents a breach in the IT network from reaching the control systems.
What Affected Users and Utilities Should Do Now
If you work for or manage a water, energy, or other critical infrastructure provider, the time to act is now. Conduct an immediate audit to identify any internet-connected PLCs, RTUs, or HMIs and isolate them behind firewalls with strict access controls. Enable multi-factor authentication on all remote access points and implement a mandatory 24-hour password change on all devices. For customers and residents served by these utilities, there is no immediate action required on your part, but you should remain vigilant for any service disruptions or official notices from your provider. This incident underscores the importance of using a reputable no-log VPN service to protect your home network from the spillover effects of such geopolitical attacks, especially if you use unsecured public Wi-Fi. The primary threat, however, remains at the organizational level, requiring immediate patching and segmentation to prevent catastrophic failures of the systems we rely on for water and power.