Hackers Linked to Iran Are Tampering With Safety Systems at American Water and Energy Plants

On July 22, 2026, the FBI, NSA, Department of Energy, and CISA issued a joint warning that Iranian state-backed hackers are targeting computer systems that control water and energy plants across the United States. These computers, called programmable logic controllers or PLCs, are the machines that directly operate physical equipment — opening and closing valves, regulating chemical levels in drinking water, and managing pressure in energy pipelines. The warning states that the hackers are manipulating what plant operators see on their screens, causing outages and disruption, and that they are doing this on purpose to cause disruption within the United States. The Environmental Protection Agency also joined the updated warning, which CISA published on its site alongside a coordinated FBI alert. TechCrunch CISA
The warning initially focused on controllers made by Rockwell Automation and was later expanded to include products from Schneider Electric and Siemens. The agencies warned that "potentially all internet exposed" industrial control systems may be affected, broadening the scope well beyond the named vendors.
According to the FBI, the hackers breached one critical infrastructure provider and changed the controllers' programming to disable the processes that handle critical shutdowns and alarms. PLCs have built-in safety rules: if something goes wrong, like a chemical dose rising too high or pressure building beyond a safe limit, the system is supposed to sound an alarm or shut down automatically. The hackers turned those safety rules off. With those processes disabled, systems could enter unsafe conditions without notifying operators of anomalies. The advisory does not specify which provider was breached or when the intrusion occurred.
The TechCrunch reporting on the advisory does not name a specific Iranian hacking group responsible for the PLC attacks. A group called "Handala" is mentioned in the article only in connection with separate incidents: a device wipe at Stryker and a data breach at Cal Water. The Department of Justice announced the seizure of domains linked to Handala on April 7, 2026.
This is not the first US government warning about Iranian-affiliated hackers targeting PLCs in critical infrastructure. The FBI published an alert on April 7, 2026, titled "Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure," describing the threat actors as an "Iranian-affiliated advanced persistent threat" group targeting devices spanning multiple US Water and Wastewater Systems. The FBI's Internet Crime Complaint Center (IC3) published a related cybersecurity advisory PDF the same date, and the FBI publicized the warning on its official Facebook page on April 24. FBI
CISA had previously issued an advisory addressing IRGC-affiliated cyber actors exploiting PLCs across multiple sectors, with the most recent update to that advisory dated December 18, 2024. AP News reported as far back as December 2023 that a small western Pennsylvania water authority was among multiple US organizations breached by Iran-affiliated hackers. AP News
The pattern described in the July advisory is straightforward in its mechanics. The actors are not merely changing what operators see on their screens or making symbolic gestures. By modifying the PLC programming to disable shutdown and alarm processes, they are removing the last line of defense that operators rely on to detect and respond to problems. In a water treatment facility, a silenced alarm on a chemical dosing loop could mean dosing continues past safe thresholds with no operator awareness. In an energy context, the failure of automatic shutdown logic on pressurized or thermal systems carries obvious physical safety consequences.
The attack surface is not narrow. PLCs from three major vendors, Rockwell Automation, Schneider Electric, and Siemens, are explicitly named, and the advisory's language about "potentially all internet exposed" industrial control systems suggests the agencies view the vulnerability class as broader than any single product line. PLCs and other operational technology devices have historically been designed for reliability and ease of remote access, not for strong security. Internet-exposed PLCs with default or weak passwords remain common across the water and wastewater sector in particular, where small utilities often lack dedicated cybersecurity staff.
The escalation from an initial focus on Rockwell controllers to a multi-vendor scope, combined with the confirmation that at least one provider had its safety logic actively modified, distinguishes this advisory from earlier awareness-level warnings. The April FBI alert framed the threat as exploitation of PLCs across multiple sectors. The July advisory, issued jointly by four agencies plus the EPA, documents a confirmed breach resulting in the disabling of safety-critical processes and characterizes the activity as deliberately intended to cause disruption on US soil.
For operators of water, wastewater, and energy infrastructure, the immediate implications are operational. The advisory's existence at this level of interagency coordination signals that the threat has moved from generalized concern to documented, active exploitation with demonstrated impact on safety systems. Utilities running internet-exposed PLCs from any of the named vendors, or from vendors not yet named, should treat the advisory as a directive to audit external exposure, verify controller programming integrity, and confirm that alarm and shutdown logic has not been tampered with.
The broader context here is that these industrial control systems were built for an era when they were never meant to be reachable from the public internet. Many were installed decades ago and have gradually become connected as utilities modernized, often without adding the security measures that connection requires. Agencies have been warning about this exposure since at least 2023, and the shift from general warnings to a confirmed breach with safety systems disabled suggests the time for voluntary fixes may be running short. For small water and energy utilities that operate with limited staff and budgets, that is a difficult signal — but one that is hard to ignore.


