SYS::ONLINE
Wasteland.
Briefs1506
Issues20
SinceFeb 2026
LIVE
▣ Breach IRAN-HACKERS-US 2026-07-23

US Water and Energy Providers: Iranian State-Backed ICS Disruption

"Here is the complete intel brief:"

Here is the complete intel brief:


title: "US Water and Energy Providers: Iranian State-Backed ICS Disruption" date: 2026-07-23 slug: iran-hackers-us-water-energy-ics-disruption


US Water and Energy Providers: Iranian State-Backed ICS Disruption

The U.S. government is warning that Iranian state-backed hackers are actively breaking into and disrupting industrial control systems (ICS) at American water and energy providers. In an advisory updated Wednesday, the FBI, NSA, Department of Energy, and CISA confirmed the intrusions target internet-connected programmable logic controllers (PLCs), letting attackers manipulate operator displays and trigger outages. The alert follows earlier federal warnings of escalating Iranian cyber activity amid the ongoing war between Iran and the U.S. and Israel.

What Happened

Federal agencies say Iranian hackers are targeting PLCs exposed on internet-connected operational networks at critical infrastructure providers. Initially discovered earlier this year targeting Rockwell controllers, the campaign has since expanded to include products from Schneider Electric and Siemens. The agencies warn that "potentially all internet exposed" ICS may be affected.

In at least one confirmed case, the FBI says the hackers broke into a critical infrastructure provider and rewrote the controllers' programming logic to disable processes responsible for critical shutdowns and alarms. That change allowed "systems to enter unsafe conditions without notifying operators of the anomalies," according to the feds. The agencies assessed the activity was "conducting this activity to cause disruptive effects within the United States," likely in retaliation for the ongoing conflict.

What Was Taken

This campaign centers on disruption and physical manipulation rather than data theft. The attackers altered controller programming logic, manipulated data shown on operator displays, and disabled safety and alarm functions, causing outages and unsafe operating conditions rather than exfiltrating records.

The broader Iranian campaign since the war began in February has, however, included significant data theft. Iranian operators leaked the contents of FBI director Kash Patel's personal email account. The Handala group remotely wiped tens of thousands of employee devices at U.S. medical tech giant Stryker, and in June claimed a breach of California water provider Cal Water, asserting it could have disrupted the water supply without providing evidence. Cal Water said it saw no evidence of unauthorized access to its operational networks.

Why It Matters

This is a shift from espionage and hack-and-leak operations toward destructive attacks aimed at physical infrastructure. By disabling shutdown routines and alarms, attackers can push systems into unsafe states while keeping operators blind to the danger, raising the risk of equipment damage, service outages, and public safety consequences. The expansion from Rockwell to Schneider Electric and Siemens shows the campaign is broadening, and the "potentially all internet exposed" warning means nearly any utility with reachable controllers is a candidate target.

The Attack Technique

The hackers are reaching PLCs directly over the internet on operational networks. Once they have access, they rewrite controller programming logic to disable critical shutdown processes and alarm handling, and manipulate the data rendered on operator HMIs and displays. This gives them the ability to induce outages and unsafe conditions while suppressing the notifications that would normally alert staff to anomalies. The reliance on internet-exposed controllers suggests weak network segmentation and default or absent authentication are key enablers.

What Organizations Should Do

Sources: US government says Iran-linked hackers are disrupting American water and energy providers