Tech

US agencies warn of Iranian cyberattacks targeting critical water and energy infrastructure

The FBI, NSA, and other agencies urge immediate action as Iranian hackers exploit programmable logic controllers from major manufacturers to manipulate data and disable safety alarms.

Author
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: TechCrunch · original
US government says Iran-linked hackers are disrupting American water and energy providers
Federal advisory highlights active disruptions to industrial control systems

The US government has issued an urgent advisory warning that Iranian state-backed hackers are actively disrupting industrial control systems at American water and energy providers. The FBI, the NSA, the Department of Energy, and CISA reported that the actors are targeting programmable logic controllers from manufacturers including Rockwell, Schneider Electric, and Siemens. The agencies caution that potentially all internet-exposed industrial control systems may be affected and have urged critical infrastructure owners to take immediate remedial action.

This updated alert, released on Wednesday, marks a significant escalation in the scope of the threat. While Iranian hackers were initially identified earlier this year as targeting controllers made by Rockwell, the advisory has now expanded to include products from Schneider Electric and Siemens. The agencies state that the hackers are manipulating data on their displays to cause outages and disruption, conducting this activity to cause disruptive effects within the United States.

According to the FBI, the attackers have already breached at least one critical infrastructure provider. In this incident, the hackers changed the controllers’ programming logic to disable processes that handled critical shutdowns and alarms. This manipulation allowed systems to enter unsafe conditions without notifying operators of the anomalies, a tactic that poses severe risks to public safety and operational continuity.

The cyber activity is believed to be in response to the ongoing war between Iran, the US, and Israel. This alert follows months of warnings from federal agencies regarding an escalation in hacking from Iranian actors since the start of the conflict in February. The campaign has ranged from espionage and hack-and-leak operations, such as the leaking of FBI Director Kash Patel’s personal emails, to more destructive hacks designed to cause large-scale damage.

Notable prior incidents include a hack on medical technology giant Stryker, where the Iranian group Handala remotely wiped tens of thousands of employee devices. Handala also claimed responsibility for a data breach affecting California water provider Cal Water in June, alleging it could have disrupted the water supply. Cal Water has stated it saw no evidence of unauthorized access to its operational networks, which control water supplies.

Geopolitical tensions have further intensified, with Iran’s military command announcing on Thursday that it would target vessels in the Strait of Hormuz following US strikes. US Central Command has disputed the complete closure of the waterway, stating that commercial ships continue to transit. The convergence of these cyber threats and physical maritime tensions underscores the heightened risk landscape for critical infrastructure owners.

Continue reading

More from Tech

Read next: Open-source tool claims 97 per cent token savings for AI agents
Read next: Valvoline Unveils August 2026 Promotional Offers for Service and Retail Buyers
Read next: Developer Antirez releases native MiniMax H3 inference engine for Apple Silicon