Technology

US Agencies Warn Iranian Hackers Are Disabling Safety Systems in Water and Energy Networks

Martin HollowayPublished 2w ago5 min readBased on 9 sources
Reading level
US Agencies Warn Iranian Hackers Are Disabling Safety Systems in Water and Energy Networks

On July 22, 2026, the FBI, NSA, Department of Energy, and CISA issued a joint cybersecurity advisory warning that Iranian state-backed hackers are targeting programmable logic controllers, or PLCs, on internet-connected operational networks at US water and energy providers. PLCs are specialized industrial computers that directly control physical processes — opening valves, regulating chemical doses, managing pressure in pipelines. The advisory, designated AA26-097A, states that the actors are manipulating data on PLC displays, causing operational outages and disruption, and that they are doing so specifically to cause disruptive effects within the United States. The Environmental Protection Agency also joined the updated warning, which CISA published on its site alongside a coordinated FBI alert. TechCrunch CISA

The advisory initially focused on Rockwell Automation controllers and was subsequently expanded to include industrial control system products from Schneider Electric and Siemens. The agencies warned that "potentially all internet exposed" industrial control systems may be affected, broadening the scope well beyond the named vendors.

According to the FBI, the hackers breached one critical infrastructure provider and altered the controllers' programming logic to disable processes handling critical shutdowns and alarms. Think of a PLC's shutdown and alarm logic as the pressure-release valve on a boiler — the last mechanism that prevents a dangerous situation from becoming a catastrophe. With those safety processes disabled, systems could enter unsafe conditions without notifying operators of anomalies. The advisory does not specify which provider was breached or when the intrusion occurred.

The TechCrunch reporting on the advisory does not name a specific Iranian hacking group responsible for the PLC attacks. A group called "Handala" is mentioned in the article only in connection with separate incidents: a device wipe at Stryker and a data breach at Cal Water. The Department of Justice announced the seizure of domains linked to Handala on April 7, 2026.

This advisory is not the first US government warning about Iranian-affiliated actors exploiting PLCs in critical infrastructure. The FBI published an alert on April 7, 2026, titled "Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure," describing the threat actors as an "Iranian-affiliated advanced persistent threat" group targeting devices spanning multiple US Water and Wastewater Systems. The FBI's Internet Crime Complaint Center (IC3) published a related cybersecurity advisory PDF the same date, and the FBI publicized the warning on its official Facebook page on April 24. FBI

CISA had previously issued advisory AA23-335A, addressing IRGC-affiliated cyber actors exploiting PLCs across multiple sectors, with the most recent update to that advisory dated December 18, 2024. AP News reported as far back as December 2023 that a small western Pennsylvania water authority was among multiple US organizations breached by Iran-affiliated hackers. AP News

The operational pattern described in the July advisory is straightforward in its mechanics. The actors are not merely defacing HMI screens — the interfaces operators use to monitor plant equipment — or rendering symbolic gestures. By modifying PLC programming logic to disable shutdown and alarm processes, they are removing the last-line-of-defense safety interlocks that operators rely on to detect and respond to anomalous conditions. In a water treatment facility, a silenced alarm on a chemical dosing loop could mean dosing continues past safe thresholds with no operator awareness. In an energy context, the failure of automatic shutdown logic on pressurized or thermal systems carries obvious physical safety consequences.

The attack surface is not narrow. PLCs from three major vendors, Rockwell Automation, Schneider Electric, and Siemens, are explicitly named, and the advisory's language about "potentially all internet exposed" industrial control systems suggests the agencies view the vulnerability class as broader than any single product line. PLCs and other operational technology devices have historically been designed for reliability and ease of remote access, not for authenticated, zero-trust network architectures — the security model where no device or connection is trusted by default. Internet-exposed PLCs with default or weak credentials remain common across the water and wastewater sector in particular, where small utilities often lack dedicated cybersecurity staff.

The escalation from initial focus on Rockwell controllers to a multi-vendor scope, combined with the confirmation that at least one provider had its safety logic actively modified, distinguishes this advisory from earlier awareness-level warnings. The April FBI alert framed the threat as exploitation of PLCs across multiple sectors. The July advisory, issued jointly by four agencies plus the EPA, documents a confirmed breach resulting in the disabling of safety-critical processes and characterizes the activity as deliberately intended to cause disruption on US soil.

For operators of water, wastewater, and energy infrastructure, the immediate implications are operational. The advisory's existence at this level of interagency coordination signals that the threat has moved from generalized concern to documented, active exploitation with demonstrated impact on safety systems. Utilities running internet-exposed PLCs from any of the named vendors, or from vendors not yet named, should treat the advisory as a directive to audit external exposure, verify controller programming integrity, and confirm that alarm and shutdown logic has not been tampered with.

The broader context here is that industrial control systems have been slowly migrating toward better security for years, but the pace of that migration has not matched the pace at which state-backed actors are probing them. Agencies have warned about this class of exposure since at least 2023, and the trajectory from awareness-level advisories to a confirmed breach with safety systems disabled suggests the window for voluntary remediation may be closing. For a sector where many utilities operate with limited IT staff and budgets, that is a difficult but unavoidable signal to act on.