CybersecurityJuly 26, 2026· via Security Affairs

Iranian hackers breach US water and energy systems, agencies warn

Iranian hackers breach US water and energy systems, agencies warn

Image : Security Affairs

US water and energy operators are facing a fresh wave of Iranian cyber threats after federal agencies reported that state-linked hackers have already breached control systems and altered their programming to bypass safety mechanisms. The joint advisory from CISA, the FBI, NSA, and the Department of Energy confirms that actors affiliated with Iran have gained access to programmable logic controllers (PLCs) that run pumps, valves, and alarms in critical infrastructure. Once inside, they manipulate human-machine interfaces and SCADA displays, sometimes rewriting controller logic to disable shutdown and alarm functions, leaving systems operating in unsafe states without operators noticing.

A widening campaign with familiar tactics

This isn’t the first alert about Iranian activity in industrial networks. In April, the same agencies flagged attacks on Rockwell Automation controllers. The updated advisory now includes Schneider Electric and Siemens equipment, widening the potential attack surface. Attackers typically access exposed devices via OT ports (44818, 2222, 102, 502) or modem connections over SSH (port 22), then exfiltrate PLC project files using vendor tools such as Studio 5000, EcoStruxure Control Expert, and TIA Portal. They modify or delete project logic, including Add-On Instructions, before pushing malicious updates back to the controllers.

What defenders should do right now

Agencies recommend taking exposed PLCs off the public internet by routing traffic through secure gateways and firewalls. They also advise monitoring logs for indicators of compromise on OT ports and reviewing vendor security best practices. Rockwell users are urged to set controllers to Run mode, while any suspected victim should immediately contact both the vendor and federal agencies. The advisory stresses that any internet-exposed industrial control system could be in the crosshairs.

Why it matters

These intrusions go beyond espionage. By altering control logic to override safety parameters, attackers can turn routine operations into hazards without triggering alarms. The fact that agencies updated their guidance to include multiple vendors shows this is a scalable threat, not an isolated incident. For plant operators and utilities, the takeaway is clear: if your PLCs are reachable from the public internet, assume you’re a target—and act accordingly.

Read the full advisory from CISA


Source: Security Affairs. AI-assisted editorial synthesis — TechnoExpress.

Read the original source on Security Affairs →

← Back to home