U.S. national security agencies are warning that Iranian state-backed hackers are actively compromising industrial control systems at American water and energy providers, raising fears about the safety and reliability of critical infrastructure.
In a joint advisory, the FBI, NSA, Department of Energy and the Cybersecurity and Infrastructure Security Agency said the hackers are targeting programmable logic controllers connected to the internet. By gaining access to these devices, attackers can alter what operators see on their screens, manipulate processes and trigger outages or unsafe conditions.
Officials said the campaign initially focused on controllers made by Rockwell Automation but has expanded to include equipment from Schneider Electric and Siemens, widening the potential impact across the industrial sector. The advisory warns that potentially all internet-exposed industrial control systems are at risk and urges operators to immediately harden their networks.
Investigators described at least one incident in which hackers infiltrated a critical infrastructure provider and changed the programming logic on its controllers. Those changes disabled safety processes responsible for shutdowns and alarms, allowing systems to enter unsafe states without alerting human operators.
U.S. authorities assess that the activity is intended to cause disruptive effects inside the United States, linking it to broader tensions involving Iran, the U.S. and Israel. The campaign fits a pattern of increasingly aggressive cyber operations by Tehran and its proxies, moving beyond espionage into attacks that can cause physical damage or prolonged disruption.
Iranian groups have long engaged in hack-and-leak operations, targeting government officials, companies and dissidents. More recently, they have been tied to destructive intrusions, including an attack on medical technology giant Stryker in which a group calling itself Handala remotely wiped tens of thousands of employee devices, according to public reporting.
Handala has also claimed responsibility for a data breach at California Water Service, asserting without proof that it could have tampered with water supplies. The utility said it found no evidence that its operational technology networks, which control water delivery, were accessed.
Security officials are pressing utilities and industrial operators to disconnect control systems from the public internet wherever possible, enforce strong authentication, and closely monitor for unusual activity. They warn that as geopolitical tensions persist, attempts to disrupt U.S. infrastructure through cyberspace are likely to continue and evolve.