US Government Warns of Iranian Hackers Disrupting American Water and Energy Providers


Source: Zack Whittaker / techcrunch.com

US Government Warns of Iranian Hackers Disrupting American Water and Energy Providers

The US government has issued a stern warning to American water and energy providers about the increasing threat of Iranian state-backed hackers disrupting their industrial control systems. This alert comes on the heels of federal agencies warning of an escalation in hacking from Iranian actors amid the ongoing war between Iran and the US, along with its ally, Israel.

The FBI, NSA, Department of Energy, and CISA (Cybersecurity and Infrastructure Security Agency) have jointly issued an advisory, warning that Iranian hackers are actively breaking into and disrupting industrial control systems at American water and energy providers. According to the advisory, the hackers are targeting programmable logic controllers on internet-connected operational networks, allowing them to manipulate data on their displays and cause outages and disruption.

The Iranian hackers were initially discovered earlier this year to be targeting controllers made by Rockwell Automation. However, the advisory has now expanded the types of industrial control systems under attack to include products from Schneider Electric and Siemens. The agencies warn that potentially all internet-exposed industrial control systems may be affected, and urge critical infrastructure owners to take action to prevent these disruptions.

The advisory highlights the potential for widespread disruption, stating that the Iranian-backed hackers were ‘conducting this activity to cause disruptive effects within the United States.’ This is likely in response to the ongoing war between Iran and the US, along with its ally, Israel. The FBI has also revealed that the hackers broke into one critical infrastructure provider and changed the controllers’ programming logic to disable processes that handled critical shutdowns and alarms. This allowed ‘systems to enter unsafe conditions without notifying operators of the anomalies.’

This is the latest in a series of cyberattacks launched by Iranian government hackers and their proxies across the region since the start of the war in February. The hacks have ranged from typical espionage and hack-and-leak operations, such as leaking the contents of the FBI director’s personal email account, to more atypical destructive hacks that have caused large-scale damage or disruption.

One notable incident was a hack on the US medical tech giant Stryker, which allowed the Iranian hacking group ‘Handala’ to remotely wipe tens of thousands of employee devices. Handala also took credit for a data breach affecting California water provider Cal Water in June, claiming it could have disrupted the water supply. However, the water provider stated that it saw no evidence of unauthorized access to its operational networks, which control the water supplies.

The US government’s warning serves as a stark reminder of the growing threat of cyberattacks on critical infrastructure. As the world becomes increasingly dependent on technology, the potential for disruption and damage grows exponentially. It is essential that critical infrastructure owners and operators take proactive measures to protect their systems and prevent these types of disruptions.

By staying vigilant and taking action to prevent these disruptions, we can minimize the risk of widespread damage and ensure the continued safety and security of our critical infrastructure.

Additional Information

The advisory provides further details on the types of industrial control systems that may be affected and offers guidance on how to prevent these disruptions. It also emphasizes the importance of regular security updates and patches to prevent exploitation of known vulnerabilities.

The US government’s warning serves as a critical reminder of the importance of cybersecurity in protecting our nation’s critical infrastructure. By working together, we can prevent these types of disruptions and ensure the continued safety and security of our nation’s critical infrastructure.