The US government is warning that state-sponsored Iranian hackers are actively breaking into and disrupting industrial control systems at US water and energy providers. This new alert comes months after federal agencies warned of escalating hacking by Iranian actors amid the ongoing war.
In advisory updated Wednesdaythe FBI, NSA, Department of Energy and CISA said Iranian hackers are targeting programmable logic controllers on Internet-connected business networks, allowing them to manipulate data on their screens, causing outages and outages.
The Iranian hackers were initially discovered earlier this year to be targeting Rockwell controllers, but the advisory has now expanded the types of industrial control systems under attack to include products from Schneider Electric and Siemens.
The agencies warned that “potentially all internet-exposed industrial control systems” could be affected and urged owners of critical infrastructure to take action. According to the advisory, Iranian-backed hackers “conducted this activity to cause subversive effects in the United States,” likely in response to the ongoing war between Iran and the US and Israel.
According to the FBI, hackers broke into a critical infrastructure provider and changed the programming logic of controllers to disable processes that handled critical shutdowns and alarms. The feds said this allowed “systems to enter unsafe conditions without notifying operators of the anomalies.”
This is the latest in a series of cyberattacks that Iranian government hackers and their proxies have launched across the region since the war began in February.
The hacks range from the country’s standard espionage and hack-and-leak operations, such as the leaking of the contents of FBI Director Kash Patel’s personal email account, to more informal destructive intrusions that have caused large-scale damage or disruption. Among the most notable incidents was a hack at US medical technology giant Stryker, which allowed the Iranian hacker group “Handala” to remotely wipe tens of thousands of employee devices.
Handala also took credit for a data breach affect California’s water provider, Cal Water in June, and claimed he could have cut off the water supply (without providing evidence). The water provider said it saw no evidence of unauthorized access to its operational networks, which control water supply.
When you purchase through links in our articles, we may earn a small commission. This does not affect our editorial independence.
