The Braindump Blog

Our critical infrastructure seems increasingly subject to effective cyber attacks.

· Braindump

What were once science-fiction style state cyber attacks on important national infrastructure seem now to be increasingly common.

Iran-linked hackers blamed for cyber-attack that shut down UK power plant.

The power station was down for 4 days.

Of course this isn’t a brand new venture, nor one confined to the UK. Elsewhere there have been similar acts of proxy warfare with more immediate consequences.

Iran has been accused for years of carrying out cyber-attacks on various countries, including in relation to a massive power outage in Turkey in 2015 and several possible breaches of Israeli government websites in 2022.

Iranian hackers are also suspected of recent attacks on US energy and water facilities:

…a group of hackers affiliated with the Iranian government has targeted industrial control devices used in a series of critical infrastructure targets including in the energy sector, water and wastewater utilities, and unspecified “government facilities.” According to the agencies, the hackers have targeted programmable logic controllers (PLCs)–a type of device designed to allow digital control of physical machinery–in those facilities, including those sold by industrial tech firm Rockwell Automation, with the apparent intention of sabotaging their systems.

By compromising those PLCs, the advisory warns, the hackers sought to change information on the displays of industrial control systems, which can in some scenarios cause system downtime, damage, or even dangerous conditions.

Similar to an earlier attack in 2023 wherein:

CyberAv3ngers set the names of the Unitronics devices to read “Gaza”–in a reference to Israel’s invasion of the territory in retaliation for Hamas’s October 7 attacks–and changed the devices' displays to show an image of the CyberAv3ngers logo. Despite the initial appearance of mere vandalism, industrial cybersecurity firms that tracked the attacks, including Dragos and Claroty, told WIRED that the hackers corrupted the Unitronics' devices' code deeply enough to disrupt services in water utility networks from Israel to Ireland to a Pittsburgh, Pennsylvania, facility in the US.

Iran of course isn’t the only state accused of such actions:

Foreign-backed cyber-attacks have repeatedly targeted water infrastructure in recent years. In 2024, several rural Texas towns were hit with Russian-linked cyber-attacks that briefly caused the tiny town of Muleshoe’s water system to overflow

And it’s not all in the same direction of course. Remember 2009’s Stuxnet worm that appeared to target Iranian nuclear facilities, which is thought most likely to have been created as a jointt operation by the US and Israel. Once again it targeted programmable logic controllers.

Stuxnet specifically targets programmable logic controllers (PLCs), which allow the automation of electromechanical processes such as those used to control machinery and industrial processes including gas centrifugesfor separating nuclear material. Exploiting four zero-day flaws in the systems, Stuxnet functions by targeting machines using the Microsoft Windows operating system and networks, then seeking out Siemens Step7 software. Stuxnet reportedly compromised Iranian PLCs, collecting information on industrial systems and causing the fast-spinning centrifuges to tear themselves apart. Stuxnet’s design and architecture are not domain-specific and it could be tailored as a platform for attacking modern SCADA and PLC systems (e.g., in factory assembly lines or power plants), most of which are in Europe, Japan and the United States. Stuxnet reportedly destroyed almost one-fifth of Iran’s nuclear centrifuges. Targeting industrial control systems, the worm infected over 200,000 computers and caused 1,000 machines to physically degrade