Iranian Hackers Targeting US Water and Energy Infrastructure: A Growing Concern

TL;DR
- U.S. agencies have warned that Iran-linked hackers are targeting water and energy infrastructure by exploiting internet-facing industrial control systems, especially programmable logic controllers, or PLCs.
- Officials say the activity has already caused operational disruption and financial losses, though they have not publicly named specific victims or locations.
- The advisory urges operators to remove exposed devices from the public internet, enable multifactor authentication, and harden OT/SCADA systems to reduce risk.
A fresh warning from Washington
U.S. cybersecurity and critical-infrastructure agencies have issued an urgent alert about Iranian-affiliated hackers targeting American water and energy providers. The joint warning came from the FBI, CISA, the NSA, the EPA, the Department of Energy, and U.S. Cyber Command, and it says the attackers are focusing on operational technology used to control industrial processes.
According to the advisory, the threat actors have been exploiting internet-facing devices, including Rockwell Automation/Allen-Bradley programmable logic controllers, and manipulating data shown on human-machine interface and SCADA screens. Officials say the activity has led to disruptions across multiple critical-infrastructure sectors.
What the hackers are doing
The campaign appears designed to create disruptive effects rather than simply steal data. The agencies say the attackers have targeted devices that sit between the internet and physical infrastructure, giving them a path to interfere with pumps, switches, monitoring systems, and other equipment used in water and energy operations.
Reports on the advisory note that the incidents have involved malicious interaction with project files and tampering with SCADA and HMI displays, which can confuse operators or alter how systems appear to be functioning. The agencies also said some victims experienced financial losses and operational disruption.
Why water and energy systems are exposed
Water utilities and energy providers often rely on industrial control systems that were built to keep physical processes running, not to withstand modern internet-scale attacks. Many of these environments still have legacy devices, limited segmentation between business and operations networks, and remote-access tools that can be difficult to secure without disrupting service.
The advisory highlights a specific risk: publicly reachable PLCs. When controllers are exposed to the internet, attackers may be able to probe for known flaws, weak credentials, or bypasses in authentication and use them to alter industrial processes. That is especially concerning in small and midsize utilities, which may have fewer staff and fewer resources for continuous monitoring.
The national security angle
The warning lands in a politically sensitive moment. U.S. officials linked the increase in hostile activity to tensions involving U.S. and Israeli strikes against Iran, and the agencies described the actors as Iranian-affiliated or supported by Iran’s Islamic Revolutionary Guard Corps.
That makes the campaign more than a routine cyber incident. Attacks on drinking water and energy infrastructure can affect public health, emergency response, and confidence in basic services. Even when systems are not physically destroyed, the disruption of treatment processes, monitoring, or power delivery can create cascading consequences for local communities.
How serious is the threat?
The current warning does not publicly identify specific facilities, and officials have not said whether the attacks caused widespread outages. But the fact that multiple federal agencies issued a coordinated advisory suggests the threat is being treated as credible and active.
The bigger concern is that the same weaknesses targeted in this campaign are common across many industrial environments: exposed internet services, weak authentication, incomplete logging, and insufficient separation between IT and operational networks. Once attackers gain a foothold, they may be able to move from remote access into systems that directly affect physical operations.
What operators are being told to do
Federal agencies are urging utilities and industrial operators to take immediate defensive steps. Those include removing operational technology from public internet exposure, securing remote access through mediated gateways, enabling multifactor authentication, checking logs for suspicious activity, and ensuring PLCs are set to the proper physical mode to prevent remote tampering.
The agencies also recommend stronger backup practices for controller logic and configuration files, along with closer coordination between utilities, cybersecurity teams, and local emergency services. For organizations already using vulnerable Rockwell systems, the guidance emphasizes patching, segmentation, and rapid reporting of suspicious activity.
Why this matters beyond utilities
The latest advisory is a reminder that cyber risk is now inseparable from physical infrastructure risk. Water systems, power facilities, and local government services increasingly depend on connected industrial devices that can be reached remotely, monitored centrally, and, if poorly defended, manipulated by outsiders.
For consumers, the immediate impact may never be visible. But for operators and policymakers, the message is clear: attackers are probing the connective tissue of critical infrastructure, and the gap between a network breach and a real-world service disruption can be very short.
Get All The Latest Updates Delivered Straight To Your Inbox For Free!