Summary
U.S. agencies report an uptick in Iranian-directed cyber activity aimed at devices that interact with or control critical infrastructure systems. The campaigns have targeted publicly reachable programmable logic controllers (PLCs) and supervisory control and data acquisition (SCADA) displays, and in certain instances have caused disruptions and monetary harm.
Details of the advisory
On Tuesday multiple U.S. federal entities released a joint advisory describing a pattern of intrusions directed at equipment used across a range of critical infrastructure sectors. The advisory states that the attackers have sought to access PLCs and SCADA displays that are publicly exposed on the internet - the types of devices operators use to monitor and control infrastructure components.
The agencies said the threat actors are pursuing actions intended to produce "disruptive effects within the United States." The advisory notes that in a few cases the activity has led to operational disruption and financial loss.
Observed attacker behaviors
According to the advisory, the intrusions in some incidents included interaction with system data files in order to change what is shown on control displays, in addition to extracting device project data. The advisory identifies targeted organizations only by sector, naming government services and facilities, water and wastewater systems, and energy as affected areas.
Agencies involved and response
The advisory was published jointly by the Federal Bureau of Investigation, the National Security Agency, the Cybersecurity and Infrastructure Security Agency, the Environmental Protection Agency, the Department of Energy and U.S. Cyber Command's Cyber National Mission Force. The FBI declined to provide any additional comment beyond the advisory.
The warning was issued amid heightened rhetoric between the United States and Iran. The advisory followed public statements including a warning by President Donald Trump that "a whole civilization will die tonight" if Iran fails to reach a deal with the U.S., and comments from Iran that it would target additional infrastructure across neighboring Gulf states.
Context and implications
The advisory makes clear the attackers are focusing on operational technology components that bridge digital networks and physical infrastructure. By targeting PLCs and SCADA displays, the intrusions are aimed at elements that can influence the operation and monitoring of systems in government, water and energy sectors. The advisory links the recent increase in activity to hostilities but does not provide additional attribution detail beyond its characterization of the campaigns.