TheVortiq
Empresas

US warns: Iranian hackers target water and energy

An updated government alert indicates that Iran-linked groups are exploiting industrial control systems in US water and energy providers.

July 24, 2026 · 3 min read

Close-up of an industrial control panel with colorful buttons in a factory setting.

TL;DR: The US government issued a warning about Iranian cyberattacks on critical water and energy infrastructure. Hackers exploit vulnerabilities in industrial control systems, potentially causing disruptions to essential services. Companies are advised to strengthen security.

What happened?

On July 23, 2026, a joint advisory from the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the National Security Agency (NSA) revealed that hackers linked to the Iranian government are actively targeting water and energy providers in the United States. According to TechCrunch, the attackers exploit vulnerabilities in industrial control systems (ICS) and operational technologies (OT) used in these facilities. The alert updates one issued in 2023, indicating an intensification of Iranian cyber operations against US critical infrastructure. The attacks are not limited to the US: reports from Mandiant and Dragos indicate that groups like APT33 (also known as Elfin) have targeted similar objectives in Europe and the Middle East since 2020.

Why is it important?

This type of attack represents a direct threat to national security and public welfare. Critical water and energy infrastructure is fundamental to daily life and the economy: according to the Environmental Protection Agency (EPA), over 80% of the US population relies on public water systems that could be vulnerable. A disruption in these services could cause anything from supply cuts to environmental damage or health risks, as occurred in the attack on the Oldsmar, Florida water treatment plant in 2021, where a hacker attempted to raise sodium hydroxide levels to dangerous levels. Moreover, attribution to Iranian state actors raises geopolitical tensions, in a context where nuclear negotiations with Iran are stalled and economic sanctions have been tightened. DHS Deputy Under Secretary for Cybersecurity Robert Silvers stated: “We are facing a persistent threat that requires a coordinated response from the entire public and private sector.”

Consequences and context

Historically, Iran has used cyberattacks as a tool for pressure and retaliation. In 2013, Iranian hackers took control of the Bowman Dam in New York, though without causing serious damage. In 2012-2013, the APT33 group attacked banks and transportation systems in a wave of denial-of-service attacks. However, the focus on critical water and energy infrastructure marks a significant escalation. According to a 2025 Dragos report, attacks on ICS/OT increased by 40% in the past year, with Iran as one of the main actors. Immediate consequences include the need for companies to bolster defenses: implement multi-factor authentication, segment networks, update patches, and establish continuous OT traffic monitoring. CISA also recommends adopting the NIST cybersecurity framework and conducting incident response exercises. In the long term, sanctions on Iran could be tightened and investment in cybersecurity for critical infrastructure could increase; President Biden has already proposed a $10 billion budget to modernize water and energy systems by 2027. Additionally, greater international collaboration is expected, such as the NATO initiative to share cyber threat intelligence.

What should readers know?

  • The attacks target industrial control systems (ICS/OT), not personal data; they aim to disrupt operations or cause physical damage.
  • Affected companies should follow CISA recommendations: apply security patches, monitor networks for anomalous activity, segment OT networks from IT, and have updated incident response plans.
  • There is no evidence of physical damage so far, but the risk of disruption is real. In 2024, a similar attack on a Texas water plant managed to disable pumps for several hours.
  • Public-private collaboration is key: CISA offers free vulnerability assessment services and tabletop exercises for critical sectors.
  • Citizens can contribute by reporting suspicious activity through the CISA portal or to the FBI.
“It is crucial that critical infrastructure operators update their systems and adopt robust security measures to prevent intrusions,” said a CISA spokesperson. “We cannot allow hostile state actors to put American lives at risk.”

In summary, the US government warning underscores the need for constant vigilance and proactive preparation against hostile state actors who see cyberspace as a battlefield. The escalation of Iranian attacks on critical infrastructure demands a coordinated response combining technology, policies, and international cooperation to protect the essential services on which modern society depends.

Keep reading