World

Iran-linked cyberattacks shift focus from data theft to physical infrastructure

A four-day outage at a UK power plant and widespread disruptions to US water systems highlight a new strategic threat to essential services, prompting calls for improved operational resilience.

Editorial persona
Adrian Cole
Political Correspondent
Published
Draft
Source: Al Jazeera Global News · View original source
The Iran war is bringing cyberwarfare into critical infrastructure
POLICY & SECURITY

Recent cyber incidents in the United Kingdom and the United States suggest a significant shift in how state-linked actors target critical infrastructure. In the UK, a power plant was forced offline for four days in an attack reportedly linked to Iran-linked hackers. While the British government noted that the facility was relatively small and posed no risk to the wider energy system, the incident has raised questions about the vulnerability of larger facilities to similar disruptions.

Across the Atlantic, water and wastewater systems in at least 12 US states have reported recent cyberattacks. The impact has been tangible, with more than 30 community water systems affected in Minnesota alone. In Georgia, a cyber incident caused a drop in water pressure that necessitated a boil-water advisory. Although the US government has not publicly accused Iran of these specific attacks, reports point to a hacker group associated with the Islamic Revolutionary Guard Corps (IRGC).

These events mark a departure from traditional cyberthreats, which have historically focused on data theft, such as passwords and personal information. Critical infrastructure presents a different risk profile because the systems being attacked control parts of the physical world. For societies to function, electricity must be generated, water must be treated, and transport networks must operate. Increasingly, these physical processes rely on underlying digital technology that creates both efficiency and opportunity for attackers.

US authorities have specifically warned about Iranian-affiliated actors targeting internet-connected programmable logic controllers, the industrial technology used to manage physical equipment. Agencies have identified activity across water, energy, and government services, including attempts that resulted in operational disruption. This highlights a growing concern that geography offers less protection in cyberwarfare, as infrastructure thousands of miles away can become a target based on the technology it uses or the country it operates in.

The strategic intent behind these attacks remains unclear, ranging from intelligence gathering and disruption to demonstrating capability. However, the interdependence of modern systems means that a successful attack on one sector can create serious consequences for others. Energy supports communications and healthcare, while water systems require power and digital controls. Disruption in one area can therefore spread through organisations that depend on one another.

In response, the FBI has advised affected US water utilities to practise reverting to manual controls if automated systems are compromised. This advice underscores a broader policy shift towards resilience, acknowledging that no government can assume every attack will be prevented. Operators are now being urged to review their exposure, particularly where operational technology is accessible from the internet, and to prepare for the possibility that an attacker may succeed despite existing defences.

Continue reading

More from World

Read next: Qatar says it will keep pursuing diplomacy in US-Iran conflict
Read next: IPCC affiliations raise transparency questions, Guardian journalist says
Read next: China steps up effort against Myanmar scam centres