CISA, FBI, and NSA Warn Iran-Linked Hackers Are Breaching US Water and Energy Providers Through Exposed Industrial Controllers
A joint US advisory says Iran-linked hackers are exploiting exposed industrial controllers at water and energy providers, and disabled shutdown alarms at one breached facility.
Editor's Note ·
- Correction:
- The article states hackers modified controller logic to "disable processes that handled critical shutdowns and alarms." This phrase is presented as a direct quote, but the cited source (TechCrunch) does not put it in quotation marks -- it is TechCrunch's own paraphrase of the FBI's account, not a marked quotation. Only the following clause, "systems to enter unsafe conditions without notifying operators of the anomalies," is an exact quotation in the source. The underlying fact -- a confirmed breach at one provider disabled shutdown/alarm-handling processes -- is accurate.
- Clarification:
- The article attributes the hackers' motive to "the Iran-Israel war that began in February." The cited source (TechCrunch) describes this as "the ongoing war between Iran and the U.S. and Israel," naming the United States as a stated party alongside Israel. The February start date is correctly sourced; the two-party "Iran-Israel war" label omits the U.S. as a combatant per the source's own wording.
Overview
The FBI, the National Security Agency, the Department of Energy, and the Cybersecurity and Infrastructure Security Agency issued an updated joint advisory on Wednesday warning that Iran-linked hackers are actively exploiting internet-exposed industrial controllers at American water and energy providers, according to TechCrunch. The advisory, issued July 22, updates a warning first published in April about an ongoing Iranian campaign against programmable logic controllers (PLCs) across US critical infrastructure, according to Infosecurity Magazine.
What We Know
- The hackers are targeting programmable logic controllers on internet-connected operational networks to “manipulate data on their displays, causing outages and disruption,” according to TechCrunch.
- The advisory names internet-exposed industrial systems from Rockwell Automation, Allen-Bradley, Schneider Electric, and Siemens as targets, according to Infosecurity Magazine. Specific products cited include Rockwell’s Studio 5000 Logix Designer, Schneider Electric’s EcoStruxure Control Expert and BMX P34/Modicon M340 PLCs, and Siemens’ Totally Integrated Automation Portal and S7-1200 series PLCs, per Infosecurity Magazine.
- According to the FBI, hackers breached one critical infrastructure provider and modified controller programming logic to “disable processes that handled critical shutdowns and alarms,” allowing “systems to enter unsafe conditions without notifying operators of the anomalies,” TechCrunch reported.
- Separately, Infosecurity Magazine reported that the FBI observed the threat actors downloading malicious project files to PLCs at a US critical infrastructure organization using configuration software, and manipulating data on human-machine interface and supervisory control and data acquisition displays, causing operational disruption and financial losses. The malicious project file “retained ladder logic for downstream function but added logic that overrode specific instruction sets responsible for maintaining safe operating parameters,” per the same report.
- CISA has linked the activity to a threat group bearing similarities to CyberAv3ngers, also tracked under the names Bauxite, Hydro Kitten, and UNC5691, according to Infosecurity Magazine.
- The agencies said the hackers appear to be “conducting this activity to cause disruptive effects within the United States,” likely in response to the Iran-Israel war that began in February, TechCrunch reported.
- The advisory warns that “potentially all internet exposed” systems from the named vendors may be at risk, according to TechCrunch.
- Recommended mitigations include removing PLCs from direct internet exposure, monitoring ports 44818, 2222, 102, and 502 for suspicious activity, and maintaining trusted PLC logic backups with tested recovery procedures, according to Infosecurity Magazine.
Context
The warning follows a string of Iran-linked cyber incidents cited by TechCrunch: the Handala hacking group claimed responsibility for a breach at Cal Water in June, the medical device maker Stryker experienced remote device wipes, and FBI Director Kash Patel’s personal email was breached.
What We Don’t Know
Neither source identifies the specific water or energy provider that was breached, nor discloses how many facilities have been affected beyond the one confirmed incident. The extent of any financial losses beyond the general description of “financial losses” reported by Infosecurity Magazine has not been quantified in either report.