<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/iranian-hackers-are-inside-us-water-and-energy-ics-and-the-shutdown-alarms-are-off-v6xqa7kgs" -->

---
title: Iranian hackers are inside US water and energy ICS, and...
description: The FBI, NSA, CISA, and Department of Energy issued a joint advisory warning that Iranian state-backed hackers have compromised internet-exposed PLCs from...
canonical: https://daily.dev/posts/iranian-hackers-are-inside-us-water-and-energy-ics-and-the-shutdown-alarms-are-off-v6xqa7kgs
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Iranian hackers are inside US water and energy ICS, and the shutdown alarms are off | daily.dev
og:description: The FBI, NSA, CISA, and Department of Energy issued a joint advisory warning that Iranian state-backed hackers have compromised internet-exposed PLCs from...
og:url: https://daily.dev/posts/iranian-hackers-are-inside-us-water-and-energy-ics-and-the-shutdown-alarms-are-off-v6xqa7kgs
og:image: https://api.daily.dev/og/posts/v6xQa7KGs.png
og:image:alt: Iranian hackers are inside US water and energy ICS, and the shutdown alarms are off
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Iranian hackers are inside US water and energy ICS, and the shutdown alarms are off

**[Trends](https://daily.dev/sources/trends)** · 2 min read · 1 upvotes · 0 comments

## Summary

The FBI, NSA, CISA, and Department of Energy issued a joint advisory warning that Iranian state-backed hackers have compromised internet-exposed PLCs from Rockwell, Schneider Electric, and Siemens in US water and energy infrastructure. The attackers are disabling shutdown processes and alarm systems to conceal their presence. The group Handala has claimed credit for incidents including a Stryker device wipe and a Cal Water breach. Analysts warn the real risk is 'access optionality' — footholds built for espionage can be repurposed for disruption. CISA has expanded the alert beyond initial scope, suggesting wider compromise. Recommended mitigations include removing internet-exposed PLCs, enforcing phishing-resistant MFA, and auditing identity and service-provider relationships.

## Content

On July 26-27, a coordinated cyberattack hit more than 30 community water utilities across Minnesota. The City of Braham's water plant went fully offline before being restored within hours. Other communities switched to manual operations. Minnesota IT Services activated statewide incident response and looped in federal partners.

No one has formally named a culprit yet, but the attack pattern points squarely at CyberAv3ngers, an IRGC-linked group with a documented history of hitting critical infrastructure. The FBI, NSA, CISA, and the Department of Energy had already issued a joint advisory warning that Iranian state-backed hackers were actively targeting industrial control systems at U.S. water and energy providers.

The technical angle is what makes this uncomfortable. The likely entry point is CVE-2021-22681, a CVSS 9.8 authentication bypass in Rockwell Automation Logix controllers. There is no vendor patch. The attackers aren't just poking around either: CISA's updated advisory documents PLC project file exfiltration and manipulation of Add-On Instructions to disable safety systems and alarm processes without triggering operator alerts. Four days before the Minnesota attack, CISA expanded the scope of that advisory to cover Schneider Electric and Siemens devices alongside Rockwell, which suggests the targeting surface is wider than anyone was treating it.

The broader threat intelligence picture is worse. A midyear assessment of Iranian cyber activity flags what it calls "access optionality": footholds gained for espionage can be quietly repurposed for disruption when tasking changes. The same infrastructure used to steal data becomes the infrastructure used to knock systems offline. That's not a hypothetical anymore.

The mitigations CISA is pushing are blunt but necessary: disconnect PLCs from the internet entirely, set physical mode switches to Run, segment IT and OT networks, audit cellular OT connections, and keep offline backups of PLC logic. The uncomfortable reality is that a lot of these systems are still internet-exposed because that's how they were deployed, and the authentication bypass they're vulnerable to has no fix coming.

Thirty-plus water utilities in one coordinated hit is a significant escalation. The fact that it worked this cleanly, against this many targets, on a vulnerability with no patch, is the part that should be keeping OT security teams up at night.

---

[View this post on daily.dev](https://daily.dev/posts/iranian-hackers-are-inside-us-water-and-energy-ics-and-the-shutdown-alarms-are-off-v6xqa7kgs)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Iranian hackers are inside US water and energy ICS, and the shutdown alarms are off","url":"https://daily.dev/posts/iranian-hackers-are-inside-us-water-and-energy-ics-and-the-shutdown-alarms-are-off-v6xqa7kgs","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/iranian-hackers-are-inside-us-water-and-energy-ics-and-the-shutdown-alarms-are-off-v6xqa7kgs"},"datePublished":"2026-07-23T18:37:01.102Z","dateModified":"2026-07-29T14:57:05.638Z","description":"The FBI, NSA, CISA, and Department of Energy issued a joint advisory warning that Iranian state-backed hackers have compromised internet-exposed PLCs from...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/b34a59b16d981af160e219a417b74462?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/b34a59b16d981af160e219a417b74462?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Trends","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Trends","logo":"https://media.daily.dev/image/upload/s--ZfSp3asX--/f_auto,q_auto/v1780996004/logos/trends?_a=BAMAMiWQ0","url":"https://daily.dev/sources/trends"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/iranian-hackers-are-inside-us-water-and-energy-ics-and-the-shutdown-alarms-are-off-v6xqa7kgs","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Trends","item":"https://daily.dev/sources/trends"},{"@type":"ListItem","position":3,"name":"Iranian hackers are inside US water and energy ICS, and the shutdown alarms are off"}]}
```

