Full story
Iranian Cyber Assault
Iran-backed hackers escalated their campaign against American critical infrastructure.
“Iranian government hackers are launching disruptive cyberattacks on American energy and water infrastructure”
Federal agencies identified the attackers as Iran-affiliated advanced persistent threat actors.

They exploited vulnerabilities in Rockwell Automation's Allen-Bradley programmable logic controllers.
Some victims experienced operational disruption and financial loss.
The Treasury Department imposed sanctions on Iranian intelligence officials and Handala associates.
Operational Impact
Hackers caused disruptions at multiple US oil and gas and water sites.
Facilities were forced to operate manually.

Iran demonstrated capability to intrude into critical infrastructure systems.
Handala's tactics evolved from espionage to destructive operations.
Wider Cyber War
The Iranian cyberthreat emerged as part of a broader tit-for-tat escalation.
“US-Israeli strikes targeted 1,600 locations in Iran over 40 days”
Foreign Minister Amir-Abdollahian called the strikes illegal and offensive.
The multiagency advisory marked the first public warning since the war began.
Targeting Medical and Government Sites
Handala expanded its targeting to medical and municipal government sites.
The LA police arrested a suspect linked to LAX cyberattacks.

Cybersecurity experts warned the campaign was highly sophisticated.
Industry and Policy Response
Security firms backed coordinated defenses.
Lawmakers proposed bills requiring greater transparency on hacking costs.

The US wrestled with how to integrate cyber defense and public communication.
