DTWdailytechwire
Tech Intelligence, Wired Daily
Policy

Industrial Control Systems Under Siege as Iranian Hackers Target US Critical Infrastructure

Federal agencies warn that state-backed actors are manipulating PLCs at water and energy facilities, disabling safety systems and causing operational disruptions across the country.

AS
Arjun S. Mehta
Staff Writer · Singapore
Jul 24, 2026
5 min read
Industrial Control Systems Under Siege as Iranian Hackers Target US Critical Infrastructure
Industrial Control Systems Under Siege as Iranian Hackers Target US Critical InfrastructureCredit: Bing Guan / Bloomberg

The Scope of the Threat

Iranian state-backed hackers have escalated their attacks on American critical infrastructure, actively breaching and disrupting industrial control systems at water and energy facilities across the United States. The FBI, NSA, Department of Energy, and the Cybersecurity and Infrastructure Security Agency jointly updated their advisory this week, expanding the list of vulnerable systems and urging immediate action from infrastructure operators.

The hackers are focusing on programmable logic controllers, the specialized computers that manage industrial processes in everything from water treatment plants to power distribution networks. By compromising these internet-connected operational networks, the attackers can manipulate data displays, trigger outages, and create dangerous operational conditions without alerting facility operators.

What began as targeted attacks on Rockwell automation controllers earlier this year has now broadened significantly. The federal advisory now identifies industrial control systems from Schneider Electric and Siemens as confirmed targets, with agencies warning that potentially all internet-exposed industrial control systems may be vulnerable to similar intrusions.

Disabling Safety Mechanisms

The most alarming aspect of these attacks involves the manipulation of core safety protocols. In at least one documented incident, Iranian-backed hackers penetrated a critical infrastructure provider and altered the programming logic of controllers to disable processes responsible for critical shutdowns and emergency alarms.

This allowed industrial systems to operate under unsafe conditions without triggering the warnings that operators rely on to prevent catastrophic failures. The ability to blind operators to system anomalies while simultaneously degrading safety controls represents a significant evolution in the sophistication and intent of these operations.

According to federal agencies, the hackers are conducting this activity specifically to cause disruptive effects within the United States, likely as a response to ongoing geopolitical tensions involving Iran, the US, and Israel. The timing and nature of these attacks suggest a deliberate strategy to undermine public confidence in critical services and demonstrate reach into sensitive operational environments.

A Pattern of Escalation

These infrastructure attacks fit within a broader campaign of cyber operations that Iranian government hackers and their regional proxies have launched since February. At DailyTechWire, we've tracked a notable shift in Iranian cyber activity over the past five months, moving beyond traditional espionage toward more destructive and disruptive operations.

The range of targets and tactics has been striking. Iranian actors have conducted hack-and-leak operations, including the compromise and public release of personal email contents belonging to FBI director Kash Patel. These information operations aim to embarrass officials and erode institutional credibility.

More concerning from an operational standpoint are the destructive attacks that have caused measurable damage. The Iranian hacking group known as "Handala" breached medical technology company Stryker, remotely wiping tens of thousands of employee devices and disrupting business operations. The same group claimed responsibility for a data breach at Cal Water, a California water provider, in June, asserting they could have disrupted water supplies, though the company stated it found no evidence of unauthorized access to operational networks controlling water distribution.

The Industrial Control System Vulnerability

The current wave of attacks exploits a fundamental weakness in how many critical infrastructure operators have modernized their systems. Programmable logic controllers were historically air-gapped, isolated from internet connectivity and therefore largely immune to remote attacks. But efficiency demands and the push toward remote monitoring and management have led many facilities to connect these systems to corporate networks and, in some cases, directly to the internet.

This connectivity creates attack surface. Once an adversary gains initial access through phishing, credential theft, or exploitation of unpatched vulnerabilities, they can move laterally within networks to reach operational technology environments. From there, they can study system behavior, identify critical processes, and craft attacks designed to cause maximum disruption while evading detection.

The federal advisory emphasizes that the Iranian actors are targeting systems that remain exposed to the internet without adequate segmentation or monitoring. Many smaller water utilities and regional energy providers lack the cybersecurity resources and expertise that larger operators can deploy, making them particularly vulnerable to these intrusions.

Regional Implications and Response Posture

The infrastructure attacks on American facilities mirror cyber operations that Iranian actors have conducted across the Middle East and Asia in recent years. We've seen similar controller manipulation attacks targeting industrial facilities in Gulf states and attempted intrusions into water systems in Israel. The techniques being deployed in the US reflect lessons learned and capabilities refined in those regional operations.

For infrastructure operators across Asia, these attacks offer a preview of likely tactics. Iranian cyber capabilities have matured significantly, and the willingness to cross thresholds from espionage into disruption signals a broader shift in how state actors view critical infrastructure as a domain for coercive operations.

The federal advisory urges critical infrastructure owners to implement network segmentation, removing industrial control systems from direct internet exposure, deploying robust monitoring for anomalous behavior, and ensuring that safety systems have independent verification mechanisms that cannot be disabled through a single point of compromise.

The Broader Context

These incidents underscore the fragility of systems that underpin modern life. Water treatment, energy distribution, and industrial processes depend on automation and remote management, but the security architecture protecting these systems has not kept pace with the threat environment.

Iranian actors are not alone in developing capabilities to target industrial control systems. Chinese, Russian, and North Korean state hackers have all demonstrated interest in and access to critical infrastructure networks in the US and allied nations. The difference in recent months has been the willingness to move from reconnaissance and pre-positioning to active disruption.

For policymakers and infrastructure operators, the question is no longer whether adversaries can reach these systems, but how to detect and respond when they do. The attacks documented in the federal advisory demonstrate that defensive measures focused solely on perimeter security are insufficient. Adversaries are already inside networks, studying systems, and preparing for contingencies.

The updated advisory from FBI, NSA, DOE, and CISA represents an acknowledgment that the threat has evolved beyond isolated incidents into a sustained campaign. The expansion of targeted vendors from Rockwell alone to include Schneider Electric and Siemens, with warnings that all internet-exposed systems may be at risk, reflects the breadth of the problem.

Critical infrastructure security has long been treated as a secondary concern, subordinate to operational efficiency and cost management. These attacks make clear that the era of treating industrial control system security as optional has ended. The consequences of inaction are no longer hypothetical, they are playing out in real time across American water and energy networks.

Read next
Policy

Frontier AI Safety Limits Are Blocking Security Researchers Who Defend Networks

Arjun S. Mehta · 5 min
Policy

Meta Exits Major Renewable Energy Initiative Amid Fossil Fuel Expansion

Arjun S. Mehta · 5 min
Policy

Saudi Arabia's $55 Billion EA Buyout Clears First European Hurdle

Arjun S. Mehta · 4 min
Spot something wrong? Email corrections@dailytechwire.com. We log every correction publicly.