惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 叶小钗
雷峰网
雷峰网
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Martin Fowler
Martin Fowler
MyScale Blog
MyScale Blog
博客园 - 聂微东
有赞技术团队
有赞技术团队
The Cloudflare Blog
T
Tailwind CSS Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
月光博客
月光博客
T
The Blog of Author Tim Ferriss
D
Docker
L
LangChain Blog
Vercel News
Vercel News
C
Check Point Blog
博客园 - Franky
博客园 - 三生石上(FineUI控件)
Recent Announcements
Recent Announcements
H
Hackread – Cybersecurity News, Data Breaches, AI and More
量子位
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
V
V2EX
人人都是产品经理
人人都是产品经理

Security Latest

British Police Built a Sprawling Crime-Prediction Machine. Some Results Couldn’t Be Trusted Dialog Claims It Was Hacked. A Misconfigured Website Left Its Members Exposed OpenAI Launches Full-Scale Effort to Patch Open-Source Bugs as It Takes on Anthropic’s Mythos World Cup Scams Are Getting Harder to Spot A Critical Deadline Is Approaching for Windows and Linux Security Hackers Claim to Leak Stolen Madison Square Garden Data How the Peter Thiel-Linked Dialog Club Secretly Ranks Its Members How to Watch the Knicks Parade on NYC Traffic Surveillance Cameras The UK Will Scan Asylum-Seekers’ Faces for Age Checks—Despite Knowing the Tech Is Flawed Leak Exposes Members of Peter Thiel’s Secretive ‘Dialog’ Society ‘Dangerous’ AI Models Are Coming No Matter What Meta Tapped a Pentagon Supplier to Prototype Face Recognition for Its Glasses The FCC Wants to Kill Burner Phones Grok Is Still Hosting Sexualized Deepfakes of Famous Women Drug Sites Hijacked Spotify’s Search Ranking Through Fake Podcasts Signal Alums Reveal ‘Encrypted Spaces,’ a System for Making Private Collaboration Apps CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats Trump Risks Key Surveillance Authority Over ‘Unqualified’ Spy-Chief Pick Wrongful Arrest Exposes Failures in One of the Oldest Police Face-Recognition Tools in the US Soccer Fans, You’re Being Watched Mapping Every Flock License Plate Reader Near US World Cup Stadiums Amnesty International Warns That World Cup Fans Face Potential Human Rights Violations Anthropic Offers Mythos Upgrade for Cyber Partners and a ‘Safe’ Version for the Rest of You Meta Deletes Face-Recognition System From Its Smart Glasses App After WIRED Report All the Ways Europe Is Ditching American Technology Crypto-Funded Chinese Peptide Labs Are Booming Meta Silently Added Face-Recognition Code for Its Smart Glasses to Millions of Phones xAI Asks Court to Strip Alleged Grok Deepfake Nudes Victims of Anonymity Android Is Fighting Phone Scams With a New Feature to Prove Who’s Calling The Manhattan Institute Helped Kill DEI. Now It’s Coming for Protests
Iran-Linked Hackers Are Sabotaging US Energy and Water In...
2026-04-07 · via Security Latest

As US President Donald Trump threatens wholesale demolition of Iran's infrastructure in the midst of an escalating war, Iran now appears to have already reciprocated with its own form of infrastructure sabotage: A hacking campaign hitting industrial control systems across the United States, including energy and water utilities, that US agencies say has had disruptive and costly effects.

In a joint advisory published Tuesday, a group of US agencies including the FBI, the National Security Agency, the Department of Energy, and the Cybersecurity and Infrastructure Security Agency warned that a group of hackers affiliated with the Iranian government has targeted industrial control devices used in a series of critical infrastructure targets including in the energy sector, water and wastewater utilities, and unspecified “government facilities.” According to the agencies, the hackers have targeted programmable logic controllers (PLCs)—a type of device designed to allow digital control of physical machinery—in those facilities, including those sold by industrial tech firm Rockwell Automation, with the apparent intention of sabotaging their systems.

By compromising those PLCs, the advisory warns, the hackers sought to change information on the displays of industrial control systems, which can in some scenarios cause system downtime, damage, or even dangerous conditions. “In a few cases, this activity has resulted in operational disruption and financial loss,” it reads, though it offers no details about the severity of those effects.

“It’s well documented that Iranian actors target industrial control systems and see them as a nexus to apply pressure,” says Rob Lee, the co-founder and CEO of Dragos, a cybersecurity firm that focuses on industrial control systems, who says that his firm has responded to multiple incidents targeting industrial systems since the war against Iran began last month. “We have seen both state and non-state actors in Iran pose real risk and show willingness to hurt people through compromising these systems. I fully expect them to keep up the pressure and target those sites they can get access to.”

When WIRED reached out to Rockwell Automation, a company spokesperson responded in a statement that it “takes seriously the security of its products and solutions and has been closely coordinating with government agencies in connection with” Tuesday's advisory, and pointed to documents it has published for customers on how to better secure their PLCs.

Though the advisory doesn’t specify a particular group responsible for the hacking campaign, it notes that the attacks are similar to those carried out in by the Iran-linked group known as CyberAv3ngers, or the Shahid Kaveh Group, starting in late 2023. That team of hackers, believed to work in the service of the Iranian Revolutionary Guard Corps, inflicted several waves of attacks against Israeli and US targets in recent years, including gaining access to more than a hundred devices sold by industrial control system technology firm Unitronics and most commonly used in water and wastewater utilities.

In that hacking campaign, CyberAv3ngers set the names of the Unitronics devices to read “Gaza”—in a reference to Israel’s invasion of the territory in retaliation for Hamas’s October 7 attacks—and changed the devices’ displays to show an image of the CyberAv3ngers logo. Despite the initial appearance of mere vandalism, industrial cybersecurity firms that tracked the attacks, including Dragos and Claroty, told WIRED that the hackers corrupted the Unitronics’ devices’ code deeply enough to disrupt services in water utility networks from Israel to Ireland to a Pittsburgh, Pennsylvania, facility in the US.

“The Unitronics attacks demonstrated the IRGC does have industrial control systems hacking capabilities,” says Grant Geyer, Claroty’s chief strategy officer. “If you look at the IRGC playbook, they know they can't compete on the traditional military field. So they attempt to cause disruption within the cyber domain using asymmetric warfare techniques.”

Despite the US State Department putting a $10 million bounty on the group and the US Treasury sanctioning six IRGC officials with links to it, CyberAv3ngers went on to breach a US oil and gas company in 2024, according to Dragos, and to infect industrial control and internet-of-things devices with a piece of malware known as IOControl. The group appeared to be transitioning from “opportunistic attackers where their whole goal was spreading a message into the realm of a persistent threat,” Claroty researcher Noam Moshe told WIRED last year. In that IOControl malware campaign, he said, “they wanted to be able to infect all kinds of assets that they identify as critical and just leave their malware there as an option for the future.”

The news that Iranian hackers have disrupted US infrastructure targets may signal that disruptive hacking operations from Iran are intensifying as the war extends into its second month. Ahead of the initial air strikes that the US and Israel carried out against Iran, US Cyber Command publicly took credit for disabling Iranian defenses through cyberattacks.

Iran's counterattacks have since largely been carried out by a group known as Handala—a “hacktivist” group widely believed to work on behalf of Iran's ministry of intelligence—which has launched scattershot attacks including a crippling breach of medical technology firm Stryker and a hack-and-leak operation targeting an older, personal Gmail account of FBI director Kash Patel.

Following Trump's hyper-aggressive message Tuesday morning that an “entire civilization will die tonight,” posted to his social media platform Truth Social in an apparent threat to indiscriminately destroy Iranian civilian infrastructure, Handala seemed to respond with threats of its own.

“Tonight, cyber and missile soldiers will fight side by side for one nation,” a message on Handala's Telegram posted Tuesday afternoon reads. “We have a spectacular night ahead!”

Updated at 5:09 pm ET, April 7, 2026: Added additional contextual information about Iran-linked cyberattacks and groups.

Updated at 5:45 pm ET, April 7, 2026: Added comment from Claroty's Grant Geyer.