ALIQUIPPA, PENNSYLVANIA — President Donald Trump declared "total and complete victory" over Iran on April 7 and announced a two-week ceasefire while negotiators worked on a peace plan. The announcement came on the 38th day of Operation Epic Fury.
The same day, the Cybersecurity and Infrastructure Security Agency issued a warning that Iranian regime–affiliated cyber actors had gained access to internet-connected programmable logic controllers used by American critical-infrastructure sectors. The CISA advisory stated that the actors were "conducting this activity to cause disruptive effects within the United States." The intrusions into the industrial programmable logic controllers resulted in business disruptions and financial losses.
While being bombed by Israel and the U.S., Iran launched cyberattacks against Qatar, the United Arab Emirates, Saudi Arabia, and other Arab states. Iran also launched cyberattacks against American allies in Europe and companies across the Middle East to pressure American leadership to cease attacks. Iran conducted drone strikes that damaged Amazon Web Services data centers in the region.
Weeks before the first Israeli and U.S. bombs were dropped on Iran, researchers from Symantec and Carbon Black reported that the hacking group Seedworm had infiltrated the networks of an American airport, a bank, and a U.S. software company that does business in Israel as a defense and aerospace contractor. The researchers wrote that the group was in "a potentially dangerous position to launch attacks." They added, "While we have disrupted these breaches, other organizations could still be vulnerable to attack." According to the FBI and CISA, Seedworm also goes by the names MuddyWater, Static Kitten, and Mango Sandstorm, and is a front for the Iranian Ministry of Intelligence and Security.
Prior Iranian-linked intrusions have targeted U.S. infrastructure. According to the Department of Justice, in 2013 a hacker affiliated with the Islamic Revolutionary Guard Corps infiltrated the control system of a dam in New York State. In 2023, Iranian-backed hackers breached the Aliquippa, Pennsylvania, water system and gained access to the programmable logic controller that controlled water pressure. The Aliquippa intrusion set off an alarm, alerting workers who then switched to a manual system.
James Turgal, Vice-President of Optiv, said, "We don't live in a world where there is not going to be an impact on U.S. citizens at home." He added, "From a cyber perspective, we're very early on."
Alex K. Jones, Chair of the Department of Electrical Engineering and Computer Science at Syracuse University, said of the prospect of a broader Iranian cyberattack on American infrastructure, "It's unlikely that they have the capacity to do so."
forum Comments (0)
No comments yet. Be the first to comment.