Here is the complete intel brief:
title: "US Water and Energy Providers: Iranian State-Backed ICS Disruption" date: 2026-07-23 slug: iran-hackers-us-water-energy-ics-disruption
US Water and Energy Providers: Iranian State-Backed ICS Disruption
The U.S. government is warning that Iranian state-backed hackers are actively breaking into and disrupting industrial control systems (ICS) at American water and energy providers. In an advisory updated Wednesday, the FBI, NSA, Department of Energy, and CISA confirmed the intrusions target internet-connected programmable logic controllers (PLCs), letting attackers manipulate operator displays and trigger outages. The alert follows earlier federal warnings of escalating Iranian cyber activity amid the ongoing war between Iran and the U.S. and Israel.
What Happened
Federal agencies say Iranian hackers are targeting PLCs exposed on internet-connected operational networks at critical infrastructure providers. Initially discovered earlier this year targeting Rockwell controllers, the campaign has since expanded to include products from Schneider Electric and Siemens. The agencies warn that "potentially all internet exposed" ICS may be affected.
In at least one confirmed case, the FBI says the hackers broke into a critical infrastructure provider and rewrote the controllers' programming logic to disable processes responsible for critical shutdowns and alarms. That change allowed "systems to enter unsafe conditions without notifying operators of the anomalies," according to the feds. The agencies assessed the activity was "conducting this activity to cause disruptive effects within the United States," likely in retaliation for the ongoing conflict.
What Was Taken
This campaign centers on disruption and physical manipulation rather than data theft. The attackers altered controller programming logic, manipulated data shown on operator displays, and disabled safety and alarm functions, causing outages and unsafe operating conditions rather than exfiltrating records.
The broader Iranian campaign since the war began in February has, however, included significant data theft. Iranian operators leaked the contents of FBI director Kash Patel's personal email account. The Handala group remotely wiped tens of thousands of employee devices at U.S. medical tech giant Stryker, and in June claimed a breach of California water provider Cal Water, asserting it could have disrupted the water supply without providing evidence. Cal Water said it saw no evidence of unauthorized access to its operational networks.
Why It Matters
This is a shift from espionage and hack-and-leak operations toward destructive attacks aimed at physical infrastructure. By disabling shutdown routines and alarms, attackers can push systems into unsafe states while keeping operators blind to the danger, raising the risk of equipment damage, service outages, and public safety consequences. The expansion from Rockwell to Schneider Electric and Siemens shows the campaign is broadening, and the "potentially all internet exposed" warning means nearly any utility with reachable controllers is a candidate target.
The Attack Technique
The hackers are reaching PLCs directly over the internet on operational networks. Once they have access, they rewrite controller programming logic to disable critical shutdown processes and alarm handling, and manipulate the data rendered on operator HMIs and displays. This gives them the ability to induce outages and unsafe conditions while suppressing the notifications that would normally alert staff to anomalies. The reliance on internet-exposed controllers suggests weak network segmentation and default or absent authentication are key enablers.
What Organizations Should Do
- Remove PLCs and other ICS/OT devices from direct internet exposure; place them behind firewalls and segmented networks with no public reachability.
- Inventory all Rockwell, Schneider Electric, and Siemens controllers and audit them for internet-facing exposure and unauthorized logic changes.
- Enforce strong authentication and change default credentials on all controllers and engineering workstations; require MFA for remote OT access.
- Validate the integrity of controller programming logic, safety interlocks, and alarm configurations against known-good baselines.
- Monitor OT networks for unexpected logic uploads, configuration changes, and anomalies in HMI data, and cross-check operator displays against independent sensor readings.
- Review the FBI/NSA/DOE/CISA advisory, apply its indicators of compromise, and report suspected intrusions to CISA and the FBI.
Sources: US government says Iran-linked hackers are disrupting American water and energy providers