U.S. authorities have issued a fresh cybersecurity alert after identifying Iranian-linked hackers attempting to interfere with industrial control systems used by American water and energy providers. The warning was released by the FBI, NSA, Department of Energy, and CISA, highlighting growing attention on internet-connected operational networks.
According to the advisory, the attackers have focused on programmable logic controllers, the systems that help manage essential infrastructure operations. By altering display data and control logic, such intrusions can create disruptions and affect how facilities monitor and manage processes.
The agencies said the activity now appears to extend beyond earlier targets and may involve equipment from Rockwell, Schneider Electric, and Siemens. Officials stressed that any internet-exposed industrial control system could be at risk, and urged operators to strengthen access controls, review configurations, and monitor for unusual behavior.
The alert also noted that one critical infrastructure provider was compromised in a way that changed controller programming and disabled certain shutdown and alarm functions. That kind of manipulation can reduce visibility for operators and make systems harder to manage safely.
Cyber activity linked to Iranian actors has continued to evolve, ranging from espionage to more disruptive operations. The latest warning underscores how digital resilience is becoming central to the protection of essential services. As infrastructure grows more connected, security innovation will likely shape the future of reliable public systems.