US warns Iran-linked hackers are targeting water and energy providers

The US government has updated its warning that Iran-linked hacking groups are targeting systems used by water and energy providers. The advisory says these groups have been infiltrating critical infrastructure operators' networks in ways that can disrupt operations.
The attacks typically target industrial control systems (ICS) and supervisory control and data acquisition (SCADA) technology — the systems that manage physical infrastructure such as pump stations, treatment plants and power grids. These systems are considered especially vulnerable because they often run on older software not designed to modern cybersecurity standards.
According to experts, the real danger in this kind of attack isn't data theft but the risk of operational disruption. Breaching a water treatment plant's control system could, in theory, let attackers manipulate chemical dosing, pressure or other critical parameters — with serious potential consequences for public health.
State-linked cyberattacks of this kind aren't new, but experts note that the frequency and targeting of such attempts tends to track closely with periods of heightened geopolitical tension. Critical infrastructure is viewed by adversarial states as both a deterrent message and genuine leverage.
Many water and energy companies, particularly smaller municipal utilities, operate with far more limited cybersecurity budgets than large private companies. That means some of the infrastructure most critical to national security is also among the least protected.
The advisory recommends that operators implement multi-factor authentication, keep software updated, segment their networks to prevent a breach from spreading across an entire system, and test their incident-response plans regularly.
Experts say critical infrastructure operators typically face a two-sided problem: fully modernising legacy systems is prohibitively expensive, but applying security patches without taking those systems offline can be technically complex. That bind leaves many facilities carrying known vulnerabilities for years.
Federal officials say they are working to improve information-sharing with the private sector, but stress that ultimate responsibility for securing a network rests with each operator. That produces an uneven security landscape across organisations ranging from major city utilities to small rural water cooperatives.
Experts say publicly disclosing advisories like this one serves an important function on its own — both prompting operators to act and signalling to attackers that their activity has been detected. But the real test, they add, is how quickly such warnings translate into concrete security investment.
Ultimately, this development underscores that critical infrastructure has become an increasingly digital front, not just a physical one; experts argue investment in this area should be treated as an urgent national security priority.
Read next

Why writing by hand is still better for your brain than typing
Keyboards and touchscreens dominate everyday writing, but a growing body of research shows that putting pen to paper engages the brain differently — and more deeply — than typing does. Here's why that difference emerges, and when it actually matters.

How Google's selfie login works, and how safe it actually is
Google is rolling out a feature that lets people use a short selfie video instead of a password to access their account, verify their age, or generate AI avatars. Here's how the underlying technology works and what it means for privacy.

What is negative cash flow, and why did Google just post its first one
Google continues to report record quarterly revenue, but its spending on AI infrastructure has ballooned so sharply that the company posted negative free cash flow for the first time in its history. Here's what cash flow actually measures, and why it matters even for a hugely profitable company.

AMD's Helios rack-scale system takes direct aim at Nvidia's AI dominance
AMD is challenging its chipmaker rival Nvidia with Helios, a new rack-scale AI system that will begin shipping to customers later this year. The launch intensifies competition in the market for infrastructure built to train and run large AI models.

Science Corporation's vision-restoring chip wins EU approval
Science Corporation, the biotech startup founded by former Neuralink president Max Hodak, has won European regulatory approval for a retinal implant designed to restore partial vision to people blinded by age-related macular degeneration. The approval marks a milestone for a company still working to prove a viable business around implantable neurotechnology.