Iranian Cyber Attacks Hit US Energy, Water, and Government Networks

Iranian-Cyber-Attacks-Hit-US-Energy-Water-and-Government-Networks

Cyber Attacks Targeting US Critical Infrastructure

The US government has issued a warning to American organizations regarding ongoing cyber activity targeting Operational Technology (OT) and Programmable Logic Controller (PLC) devices.

  • This activity is attributed to Iranian-affiliated Advanced Persistent Threat (APT) actors who aim to disrupt operations in the United States.
  • The affected sectors include energy, water, and government, which are considered critical infrastructure.

Vulnerabilities Exploited

The APT actors have been exploiting vulnerabilities in devices manufactured by Rockwell Automation and Allen-Bradley.

  • They have accessed internet-exposed PLCs using overseas IP addresses.
  • Leveraging leased, third-party infrastructure to establish connections to victim devices.

Impact of Attacks

Once inside, the attackers extracted project files and manipulated data displayed on Human Machine Interface (HMI) and Supervisory Control and Data Acquisition (SCADA) systems, leading to:

  • Operational disruption.
  • Financial loss.

Recommendations for Mitigation

Federal authorities urge organizations to take immediate action to mitigate these threats, including:

  • Disconnecting PLCs from public-facing internet access.
  • Limiting remote connectivity.
  • Setting devices to “run” mode when possible.
  • Creating and regularly testing backups of PLC logic and configurations.
According to the advisory, federal officials emphasize the importance of validating suspicious IP addresses before taking defensive action.

Moreover, the advisory recommends that organizations follow the Cross-Sector Cybersecurity Performance Goals 2.0 (CPGs 2.0), developed by the Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST).

Conclusion

The heightened geopolitical tensions involving Iran, the United States, and Israel have contributed to the increased risk of cyber attacks.



About Author

en_USEnglish