The U.S. government has issued an urgent warning that state-backed Iranian hackers are actively penetrating and disrupting industrial control systems (ICS) at American water and energy providers. According to an advisory from the FBI, NSA, Department of Energy, and CISA, the latest attacks directly target internet-connected operational networks. This development marks a serious escalation in cyber-disruption activities aimed at critical U.S. infrastructure.
Diễn biến chi tiết
According to the security advisory updated on July 22, 2026, by federal agencies, the Iranian hackers' campaign initially focused on controllers manufactured by Rockwell Automation. However, the scope of the attacks has now expanded significantly to include industrial control systems from Schneider Electric and Siemens.
The security agencies warn that "potentially all internet exposed" industrial control systems could be affected. The primary goal of this campaign is to cause disruptive effects within the United States, likely in response to ongoing geopolitical tensions and conflicts in the Middle East.
Phân tích kỹ thuật & Công nghệ
Technically, the hackers target programmable logic controllers (PLCs) exposed to the public internet. Once they gain access, they alter the programming logic of the PLCs, disabling critical processes responsible for emergency shutdowns and safety alarms.
An FBI investigation revealed that this method allows "systems to enter unsafe conditions without notifying operators of the anomalies." By manipulating the data shown on control displays, the hackers keep operators in the dark about the real-time status of the plant, creating severe risks of accidents or failures.
Ý kiến chuyên gia & Nhận định
This campaign is part of a broader wave of disruptive cyberattacks launched by Iranian state hackers and their proxies since early 2026. Previously, a hacking group calling itself "Handala" claimed responsibility for a destructive attack that wiped data across tens of thousands of devices at medical tech giant Stryker.
The Handala group also claimed to have breached California water provider Cal Water, alleging they could disrupt the water supply. However, Cal Water stated that it found no evidence of unauthorized access to its operational networks controlling the water supplies. Experts advise caution regarding hackers' exaggerated claims while emphasizing that existing security vulnerabilities must not be ignored.
Tác động & Tương lai
The incidents at U.S. water and energy plants serve as an urgent wake-up call for nations worldwide, including Vietnam, regarding the vulnerability of operational technology (OT). As digital transformation drives the connection of industrial control systems to the internet for easier management, cyber risks multiply exponentially.
Securing PLC systems, implementing network isolation barriers (air-gaps), and building independent monitoring systems will be mandatory tasks to protect national security in an era of increasingly complex digital conflicts.