The Threat Is Expanding
The U.S. government put out a warning on Wednesday, July 23, 2026. The FBI, NSA, Department of Energy, and CISA jointly updated their advisory. Government agencies report that hackers supported by Iran are currently breaching and interfering with industrial control networks at U.S. water and energy companies.
These attackers focus on programmable logic controllers linked to internet-connected operational networks, which lets them alter display data and trigger service interruptions. Earlier this year, the hackers were spotted targeting controllers made by Rockwell. The updated warning broadens the list of targeted industrial control equipment to now cover Schneider Electric and Siemens products, in addition to earlier Rockwell controllers.
The agencies warn that "potentially all internet exposed" industrial control systems may be affected.
Get the market news that matters in a five-minute read with Market Briefs, our free daily newsletter
Why Now? The War Connection
The advisory indicates that the Iranian-backed attackers were, in the words of the agencies, "conducting this activity to cause disruptive effects within the United States," and this is thought to be a reaction to the ongoing conflict involving Iran, the U.S., and Israel. Since hostilities began in February, this incident marks the most recent in a string of cyber assaults.
The FBI reported that attackers penetrated a single critical infrastructure facility and altered the controllers' code to turn off processes responsible for essential shutdowns and alarms. According to federal authorities, this situation allowed "systems to enter unsafe conditions without notifying operators of the anomalies."
The attacks span a spectrum from intelligence gathering and data leaks - for example, exposing emails from FBI director Kash Patel's personal account - to destructive operations that inflicted significant harm or disruption. The Iranian hacking group "Handala" remotely wiped tens of thousands of employee devices at U.S. medical tech giant Stryker. The group Handala additionally claimed responsibility for a June breach at California's Cal Water, asserting it could have interrupted water service, though it offered no proof. Cal Water stated that it found no indications of any unauthorized entry into its operational networks.
Broader Implications for Critical Infrastructure
These incidents highlight the growing threat to critical infrastructure amid the ongoing conflict. The ability to disable safety alarms and shutdowns poses a direct danger to public health and safety. Water and energy providers, which often rely on legacy systems with minimal security, are particularly vulnerable.
The advisory urges organizations to isolate control systems from the internet and implement robust monitoring. The Handala group's earlier wipe of Stryker devices demonstrates their capability to cause widespread operational disruption beyond data theft.
Join Market Briefs, our free daily newsletter, for a quick daily rundown of the markets
