The US government has issued a warning that Iranian state-backed hackers are actively disrupting American water and energy providers by exploiting industrial control systems. This alert comes amid an escalation in hacking from Iranian actors amid the ongoing war between Iran, the US, and Israel.
The hackers are targeting programmable logic controllers on internet-connected operational networks, allowing them to manipulate data on their displays and cause outages and disruption. The US government has expanded the types of industrial control systems under attack to include products from Schneider Electric and Siemens, in addition to those from Rockwell.
The agencies warn that potentially all internet-exposed industrial control systems may be affected and have urged critical infrastructure owners to take action. According to the FBI, the hackers have broken into one critical infrastructure provider and changed the controllers' programming logic to disabled processes that handled critical shutdowns and alarms.
This has allowed 'systems to enter unsafe conditions without notifying operators of the anomalies'. The US government has warned that the hackers are conducting this activity to cause disruptive effects within the United States.
The latest alert is part of a series of cyberattacks launched by Iranian government hackers and their proxies across the region since the start of the war in February. The hacks have ranged from typical espionage and hack-and-leak operations to more atypical destructive hacks that have caused large-scale damage or disruption.