Iran-linked hackers disrupt US water and energy systems

Original: US government says Iran-linked hackers are disrupting American water and energy providers

Why This Matters

Escalating ICS attacks on critical U.S. infrastructure signal a significant shift toward destructive cyberwarfare tactics by state actors.

The FBI, NSA, DOE, and CISA jointly warned on July 23, 2026 that Iranian state-backed hackers are actively targeting programmable logic controllers at U.S. water and energy providers, expanding attacks beyond Rockwell systems to include Schneider Electric and Siemens equipment.

U.S. federal agencies — the FBI, NSA, Department of Energy, and CISA — issued an updated advisory on July 23, 2026, warning that Iranian state-sponsored hackers are actively breaking into and disrupting industrial control systems (ICS) at American water and energy providers. The hackers are targeting internet-exposed programmable logic controllers (PLCs), manipulating display data and triggering outages. Originally identified targeting Rockwell controllers earlier in 2026, the scope has expanded to include Schneider Electric and Siemens products. Agencies warned that 'potentially all internet-exposed' ICS may be at risk. In one confirmed incident, the FBI stated hackers reprogrammed controllers at a critical infrastructure provider to disable shutdown and alarm processes, allowing 'systems to enter unsafe conditions without notifying operators.' The advisory links the activity to disruption efforts tied to the ongoing U.S.-Iran-Israel conflict, which began in February. Notable related incidents include the Iranian hacking group 'Handala' remotely wiping tens of thousands of devices at medical tech firm Stryker, and a claimed data breach at California water provider Cal Water in June 2026. Cal Water stated no unauthorized access to operational networks was confirmed.

Source

techcrunch.com — Read original →