Iran Conflict Draws Cyberattacks on Global Critical Infrastructure
Graeme Stewart
Recent cyberattacks on the UK power grid and US water systems expose severe vulnerabilities in essential infrastructure, prompting urgent calls for government action. The incidents, linked to Iran, signal a shift toward targeting physical systems. Governments and operators must prioritize resilience, not just defense.
Reports of a cyberattack that forced a UK power plant to shut down for four days have sounded alarm bells for governments and businesses worldwide. The incident shows how the Iran conflict could spill over into a new battlefield in cyberspace.
The facility targeted by hackers linked to Iran was relatively small, and the UK government stressed there was no risk to the broader energy system. However, assessing the attack's significance solely by the amount of power lost would be a mistake. The question for every nation operating critical infrastructure is: what happens when the target is larger?
According to reports, water and wastewater systems in at least 12 US states have also recently suffered cyberattacks. In Minnesota alone, more than 30 community water systems were affected; one incident in Georgia caused a drop in water pressure and led to a boil-water advisory.
The US government has not publicly accused Iran, but multiple sources point to hacker groups linked to Iran's Islamic Revolutionary Guard Corps (IRGC). These incidents mark a significant shift in cybersecurity: for years, threats have revolved around data, but when attacks hit critical infrastructure, the systems being targeted control part of the physical world.
For society to function, electricity must be generated and distributed, water must be pumped and treated, transportation must operate, and telecommunications must remain connected. Technology increasingly underpins all these systems, creating great efficiency but also opening opportunities for attackers. US authorities have specifically warned about Iran-linked actors targeting internet-connected programmable logic controllers (PLCs)—industrial technology used to control physical equipment—and have observed disruptive activity in the water, energy, and government services sectors.
This is part of the Iran conflict that countries outside the Middle East need to consider. Geography offers little protection in cyberwarfare. Infrastructure thousands of kilometers away can become a target because of the country it operates in, the technology it uses, its suppliers, or simply because attackers see an opportunity to cause disruption.
Caution is needed in assuming every attack aims to cause catastrophic damage. Attackers may want to gather information, cause disruption, send a message, create leverage, or even just prove their ability to penetrate. That is why even small incidents matter: gaining access to even a small facility reveals capability and intent.
Another issue governments cannot ignore is that critical infrastructure does not operate in isolation. Energy supports communications, transportation, healthcare, finance, and industry; communications underpin payments and emergency services; water systems need electricity and digital controls. A successful attack does not necessarily have to bring down an entire national system if disruption begins to cascade through interdependent organizations.
That is why resilience today is as important as defense. A strategy focused solely on preventing intrusion is dangerous; every government and business must assume they cannot block every attack. Operators must know what happens after hackers get in: do essential services continue? Can systems be isolated? Is there manual control when needed? How fast is recovery? What suppliers and connected systems do they depend on?
The FBI has recommended that US water companies practice switching to manual operation if automated systems are compromised—a meaningful suggestion that acknowledges the reality that resilience ultimately must include keeping the physical world running when technology fails. Governments and operators need to review their exposure immediately, especially regarding operational technology accessible via the internet, check supply-chain security, and prepare for the scenario where attackers succeed despite defenses.
The uncomfortable lesson of recent weeks is that cybersecurity is no longer just about protecting information. When cyberattacks can interfere with electricity and water, cybersecurity becomes part of protecting the essential systems that keep society running. Discovering vulnerabilities when an attack is underway is too late—preparation must happen now.