
At least one American critical infrastructure provider has already had its safety systems quietly disabled by Iranian state-backed hackers, and the public is only hearing about it now. That’s the buried lead in a joint advisory issued this week by the FBI, NSA, CISA, and the Department of Energy. According to TechCrunch, the agencies confirmed that Iranian hackers broke into one provider’s systems and reprogrammed controllers to disable critical shutdown processes and silence alarms, allowing equipment to enter unsafe conditions without alerting anyone.
The advisory, updated Wednesday, describes Iranian hackers targeting programmable logic controllers on internet-connected operational networks at water and energy providers. These are not obscure backend databases. Programmable logic controllers are the hardware that physically operates infrastructure, opening valves, managing pressure, triggering emergency shutoffs. When someone rewrites that logic remotely, the consequences are physical, not just digital.
The scope of the threat has also grown. The attack originally focused on controllers made by Rockwell, but the advisory now includes products from Schneider Electric and Siemens. The agencies warned that “potentially all internet-exposed” industrial control systems may be at risk. That phrase should alarm anyone who has followed how poorly secured operational technology tends to be. Critical infrastructure operators have historically been slow to patch industrial systems, partly because taking them offline to update them carries its own risks.
The Iranian hacking group Handala has been especially active. The group claimed responsibility for a breach at California water provider Cal Water in June and said it could have disrupted the water supply, though it offered no supporting evidence. Cal Water said it found no proof of unauthorized access to operational networks. But Handala also took credit for remotely wiping tens of thousands of employee devices at US medical tech company Stryker, an attack that did cause documented damage.
The broader pattern here is important context. These attacks are not random. The agencies explicitly tied the activity to the ongoing conflict between Iran, the US, and Israel, noting the hackers were conducting disruption “likely in response to the ongoing war.” This puts cyberattacks on water and power squarely in the category of geopolitical retaliation, which means the threat level is tied to diplomatic conditions, not just technical vulnerabilities.
For ordinary people, the risk is not abstract. Water treatment, electrical grids, and hospital systems all depend on the kind of industrial controls being targeted. The fact that agencies are urging “critical infrastructure owners to take action” is also a quiet admission that many of these systems remain exposed right now.