US Strikes Iran as Cyber Threat to Utilities Climbs

This digest was compiled by AI from multiple sources — links to the originals are below.
US forces struck two rocket launchers on Iran's Larak Island on Sunday as IRGC crews prepared to fire rockets carrying sea mines into the Strait of Hormuz. Iran responded hours later with ballistic missiles aimed at two Jordanian air bases and explosive drones aimed at Al Minhad Air Base in the UAE. The exchanges ended a monthlong lull in a conflict that federal cyber officials warn could spill onto US water and energy control systems.
Key Facts
- US forces hit two rocket launchers on Iran's Larak Island on Sunday as IRGC crews prepared to fire rockets carrying sea mines into the Strait of Hormuz.
- Iran responded hours later with ballistic missiles aimed at the King Hussein and Azraq air bases in Jordan and explosive drones aimed at Al Minhad Air Base in the UAE.
- A coordinated campaign disrupted operational technology at more than 30 Minnesota community water systems on July 26 and 27, forcing utility crews into manual operations.
- CISA later said it observed more than 100 internet-exposed water systems targeted during July.
- The FBI and EPA told critical infrastructure owners and operators in a July 30 joint alert that water systems in at least seven states had reported incidents since July 27.
Kinetic Escalation
US forces hit two rocket launchers on Iran's Larak Island on Sunday as Islamic Revolutionary Guard Corps crews prepared to fire rockets carrying sea mines into the Strait of Hormuz, according to US Central Command. Iran responded hours later with ballistic missiles aimed at the King Hussein and Azraq air bases in Jordan and explosive drones aimed at Al Minhad Air Base in the United Arab Emirates. The exchanges ended a monthlong lull in a war that federal cyber officials have spent the summer warning could spill onto the control systems running American water and energy utilities.
Cyber Threat to Utilities
Cyber activity has closely followed the kinetic phases of the US-Iran conflict, with federal advisories about Iranian-linked probing of industrial control systems often arriving shortly after missile exchanges. The US Cybersecurity and Infrastructure Security Agency, the FBI, the NSA and cyber units from the Department of Defense warned in April that Iranian-linked actors were exploiting internet-facing programmable logic controllers and misconfigured operational technology across US critical infrastructure. The agencies expanded the advisory on July 22 to cover Siemens and Schneider Electric devices alongside Rockwell Automation equipment just days before the largest wave of reported intrusions since the conflict began. A coordinated campaign disrupted operational technology at more than 30 Minnesota community water systems on July 26 and 27, forcing utility crews into manual operations. CISA later said it observed more than 100 internet-exposed water systems targeted during July.
Federal Response
The FBI and the Environmental Protection Agency told critical infrastructure owners and operators in a July 30 joint alert that water systems in at least seven states had reported incidents since July 27, and that some of the activity disrupted water operations. The agencies issued a broader advisory with CISA and the NSA describing the threat to the sector as urgent and ongoing. Analysts have described recent Iranian activity as a hybrid threat spanning physical destruction and network intrusion, with targeting that can be difficult to anticipate.