
Cyber Sabotage: Iranian Hackers Target US Water and Power Systems
Iranian state-backed hackers are actively breaking into industrial control systems that run American water facilities and energy providers. Federal agencies issued a joint warning highlighting an escalation in digital attacks against critical utilities across the country.
The updated advisory comes directly from the FBI, the NSA, the Department of Energy, and CISA. Federal investigators report that Iranian threat groups are targeting programmable logic controllers connected directly to the internet. These specialized industrial computers manage heavy machinery, water valves, power distribution, and pressure regulators. By compromising these devices, attackers can alter operational displays, manipulate system data, trigger power outages, and disrupt physical services.
Security teams initially spotted the hackers targeting controllers made by Rockwell earlier this year. The latest government warning expands that threat list significantly. Agencies now report that hackers are hitting equipment built by other major manufacturers, including Schneider Electric and Siemens.
Federal officials warn that any industrial control system exposed directly to the public internet sits at immediate risk. Government investigators urged utility managers and facility operators to disconnect vulnerable hardware and secure their networks immediately. Intelligence analysts believe Iranian groups execute these attacks to cause physical disruptions inside the United States, responding directly to ongoing military and political conflicts involving the US, Israel, and Iran.
In one confirmed intrusion, hackers broke into a critical infrastructure provider and modified the core programming logic inside its controllers. The attackers intentionally disabled safety protocols that handle automatic emergency shutdowns and high-pressure alarms. Federal officials stated that this tampering allowed equipment to run under unsafe conditions without sending alert notifications to plant operators.
This ongoing campaign marks the latest in a long series of cyber operations launched by Iranian government hackers and proxy groups. Attacks over recent months range from routine political espionage to destructive network breaches. Earlier this year, hackers leaked private emails belonging to FBI director Kash Patel. In another high-profile attack against medical technology vendor Stryker, an Iranian group named Handala wiped data from tens of thousands of corporate devices. Handala also claimed credit for a breach at California Water Service, though plant managers reported no evidence of unauthorized access to physical water controls.
When foreign state actors target operational technology, the risks go far beyond stolen passwords or leaked documents. Altering physical control systems puts public health, drinking water safety, and power grid stability at risk. Water treatment plants and electric sub-stations often run on legacy hardware that lacks modern cybersecurity protections, making them soft targets for skilled foreign hackers.
As geopolitical battles spill into cyberspace, utility operators must isolate control networks from the public internet. Municipalities and utility providers must audit their hardware setups, enforce multi-factor authentication, and update system software to defend against rising state-sponsored cyber threats.







