Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Attack Feeds
  • Iranian hackers launching disruptive attacks at U.S. energy, water targets, feds warn  – CyberScoop
AttackFeed by Joe Wagner | Iranian hackers launching disruptive attacks at U.S. energy, water targets, feds warn  - CyberScoop

Iranian hackers launching disruptive attacks at U.S. energy, water targets, feds warn  – CyberScoop

Posted on April 7, 2026 By Tim Starks
Attack Feeds

Iranian government hackers are launching disruptive cyberattacks on American energy and water infrastructure, U.S. government agencies “urgently” warned Tuesday.

The hackers are taking aim at devices and systems that control industrial processes, and have harmed victims in the last month following the onset of U.S.-Israel strikes against Iran, according to the joint alert from the FBI, National Security Agency, Cybersecurity and Infrastructure Security Agency, Environmental Protection Agency, Energy Department and Cyber Command.

“Iran-affiliated advanced persistent threat (APT) actors are conducting exploitation activity targeting internet-facing operational technology (OT) devices, including programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley,” the alert states. “This activity has led to PLC disruptions across several U.S. critical infrastructure sectors through malicious interactions with the project file and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays.”

U.S. government agencies have warned before about Iranian hackers going after similar targets with those similar methods. The first such warning came after an Iranian government-linked group took credit for attacking a Pennsylvania water facility in late 2023.

Since March of this year, however, the agencies said they have seen new victims emerge from an advanced persistent threat group tied to Iran.

“The authoring agencies identified (through engagements with victim organizations) an Iranian-affiliated APT-group that disrupted the function of PLCs,” the alert reads. “These PLCs were deployed across multiple U.S. critical infrastructure sectors (including Government Services and Facilities, WWS, and Energy sectors) within a wide variety of industrial automation processes. Some of the victims experienced operational disruption and financial loss.”

The earlier campaign compromised at least 75 devices, the alert states.

The latest disruptions include “maliciously interacting with project files, and manipulating data displayed on HMI and SCADA displays,” according to the agencies’ warning.

After the U.S.-Israel conflict with Iran began, Tehran-connected hackers claimed victims including major medtech company Stryker, local governments and more.

The FBI warned last month that Iranian hackers were deploying malware over the Telegram app, although that campaign also predated the current Iran conflict.

The post Iranian hackers launching disruptive attacks at U.S. energy, water targets, feds warn appeared first on CyberScoop.

  –

Read More  – CyberScoop 

Post navigation

❮ Previous Post: Tech giants launch AI-powered ‘Project Glasswing’ to identify critical software vulnerabilities  – CyberScoop
Next Post: Hackers Pose as Non-Profit Developers to Deploy Monero Mining Malware  – Hackread – Cybersecurity News, Data Breaches, AI and More ❯

You may also like

AttackFeed by Joe Wagner | Iranian hackers launching disruptive attacks at U.S. energy, water targets, feds warn  - CyberScoop
Attack Feeds
pcTattleTale stalkerware maker sentence includes fine, supervised release  – CyberScoop
April 6, 2026
AttackFeed by Joe Wagner | The Hidden Cost of Recurring Credential Incidents  - The Hacker News
Attack Feeds
The Hidden Cost of Recurring Credential Incidents  – The Hacker News
April 7, 2026
AttackFeed by Joe Wagner | Mustang Panda’s New LOTUSLITE Variant Targets India Banks, South Korea Policy Circles  - The Hacker News
Attack Feeds
Mustang Panda’s New LOTUSLITE Variant Targets India Banks, South Korea Policy Circles  – The Hacker News
April 22, 2026
AttackFeed by Joe Wagner | One Click, Total Shutdown: The "Patient Zero" Webinar on Killing Stealth Breaches  - The Hacker News
Attack Feeds
One Click, Total Shutdown: The “Patient Zero” Webinar on Killing Stealth Breaches  – The Hacker News
May 7, 2026
  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.