❌

Reading view

There are new articles available, click to refresh the page.

America’s cyber strategy overlooks the infrastructure that actually keeps the military moving

There is little reason to believe the war with Iran will end anytime soon. Even as efforts to resolve the conflict continue, Iran remains unpredictable, with an enduring ability to disrupt shipping and energy markets via actions in the Strait of Hormuz.

So what does a prolonged conflict mean for cybersecurity here at home? U.S. agencies need to prepare for sustained Iranian cyber operations and conduct defensive wargames now.

I spent part of my career in Navy intelligence supporting expeditionary and special warfare operations. This experience taught me to look beyond individual attacks to the larger objectives they serve. Iran’s likely objectives are relatively straightforward: impose enough pain on critical infrastructure, businesses, and public services to increase pressure on Washington, while disrupting the industrial and civilian systems that allow the U.S. to sustain military operations.

Iran may not be a top-tier cyber power like China or Russia, but it doesn’t have to be. We recently mapped 130 documented attack techniques used by five Iranian threat groups. Much of their playbook relies on well-known, repeatable techniques rather than advanced capabilities. Success does not require extraordinary capabilities, only the ability to create enough disruption, uncertainty, and delay is enough.

America’s greatest vulnerability may not be any single network or piece of critical infrastructure, but the links in between. 

Critical infrastructure: Prepare for volume, not just catastrophe

When Americans imagine a cyberattack on critical infrastructure, we tend to think of catastrophic events, such as a large-scale blackout, a poisoned water supply, or some other digital Pearl Harbor.

But in an extended conflict, the more realistic possibility is persistent attacks across many targets. Small water systems, manufacturers, transportation providers, energy infrastructure, and local governments all serve as disruptive targets. The recent string of attacks on mostly smaller water utilities across 12 states is a prime example; so too is the four-day outage of a small-scale power plant in the UK.

Attackers do not need to destroy these systems. Any intrusion that manipulates industrial systems, interrupts operations, or forces operators to determine whether equipment can still be trusted consumes valuable time and resources. Multiply that across dozens of organizations, and federal, state, local, and private-sector response capacity will be stretched thin.

The cumulative strain on the country’s ability to respond may be more important than any single attack. Iran does not need the world’s most sophisticated cyber force if its affiliated hacking groups can generate problems faster than cyber defenders can investigate and remediate them.

Defense contractors must prepare for destructive attacks

Defense contractors have long faced espionage threats targeting military secrets.  While that threat remains, the war has significantly changed Iran’s motives and risk calculus.

The same access used to steal information from the defense industrial base (DIB) can also be used to destroy data and disrupt operations. Destructive malware such as wipers and ransomware could destroy engineering files, disable production systems or force manufacturers offline, directly affecting the military’s ability to replenish equipment and supplies.

An attacker does not have to shut down production to disrupt it. Consider a compromised calibration setting, altered test result, or unauthorized change to engineering data. Discovering that an adversary had persistent access to a manufacturing environment raises difficult questions: Which files were touched? Which designs can still be trusted? Which components were manufactured from them?

The incident quickly becomes a production problem as parts must be quarantined, engineering data re-validated, and products retested.

NIST SP 800-171 and CMMC provide an essential security baseline, which makes the current pause in CMMC implementation particularly concerning. However, contractors must also be prepared to operate through destructive attacks and establish that their systems, data, and products can still be trusted. This preparedness must extend down the supply chain, where a smaller manufacturer, software provider, or managed service provider may present a greater vulnerability than a well-defended prime.

The military attack surface extends far beyond DoD networks

The U.S. military is extraordinarily capable at defending its own networks, but its operations depend on infrastructure it doesn’t own or control. Troops and equipment move on commercial railroads, materiel flows through commercial ports, and military airlift can depend on commercial carriers. Military installations and defense contractors also depend on commercial power, telecommunications, and other infrastructure.

In an ongoing conflict, those dependencies become part of the attack surface. An adversary like Iran does not have to penetrate military command-and-control to interfere with these operations. At a time when speed matters most, cyberattacks that disrupt port scheduling, corrupt logistics information, or degrade power and communications can introduce critical delays and uncertainty that hamper operations.

This is why the line between civilian and military infrastructure becomes blurred during a conflict. A commercial railroad carrying military equipment to a strategic port may be civilian infrastructure administratively, but operationally it is part of the nation’s ability to operate its military power. The same is true of the utilities, communications providers, and other civilian infrastructure supporting military installations and defense production. Their resilience can quickly become a matter of military readiness.

Cyber defense must cross organizational boundaries

American cybersecurity is organized around sectors, organizations, and authorities that make administrative sense, but aren’t necessarily designed for wartime. The boundaries between them can become a serious liability.

Our adversaries in Tehran do not care about administrative boundaries. They care about weak spots. A vulnerability anywhere in the chain connecting civilian infrastructure, industrial production, transportation, communications, and military operations can affect everything downstream.

We need to ask: Who is responsible for the cyber resilience of a commercial railroad essential to a military deployment? Who ensures the utility serving a critical defense manufacturer can withstand a sustained nation-state campaign? Who identifies the supplier whose failure could disrupt multiple defense programs? And who coordinates the response when several are attacked simultaneously?

Those questions should shape how we prepare. Critical infrastructure exercises should assume simultaneous incidents across multiple sectors and regions. We should also be extremely cautious about weakening the incentives driving cybersecurity improvements across the DIB, such as the current pause on CMMC. Additionally, defense manufacturers should also test their ability to operate through destructive attacks and determine whether their engineering data, production systems, and finished products can still be trusted.

DoD exercises should treat civilian infrastructure, including rail, ports, energy, and communications, as a routine part of the operating environment and an attractive target for adversaries. Catastrophic scenarios deserve attention, but exercises should also account for lower-level attacks that are less spectacular but still highly consequential.

Iran does not need overwhelming cyber capability to impose significant costs. Persistent disruption at home can increase political and economic pressure surrounding the war, while disruption of defense production and military logistics can make it harder for the U.S. to sustain operations abroad.

We have spent years strengthening the individual pieces of America’s cyber defenses. A prolonged war with Iran may test the links between them.

The post America’s cyber strategy overlooks the infrastructure that actually keeps the military moving appeared first on CyberScoop.

Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks

The Coast Guard and FBI boarded two foreign vessels coming to the United States last month to investigate potential cyberattacks on the ships, according to a joint statement from the agencies Wednesday.

The “joint offshore security boardings” of the two commercial ships in the Gulf of Mexico on Aug. 21 and Aug. 24 “were designed to ensure integrity of the vessel’s operational and information technology systems following indications that the networks of both vessels were compromised,” according to the joint statement.

“Currently, there are no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts,” the statement reads. “The Coast Guard is actively managing communications with port operators, vessel owners, and local maritime stakeholders to ensure port operations continue safely and without interruption.”

The vessels were reportedly tankers carrying oil and natural gas, and the first got hacked in the Strait of Gibraltar and lost communication for over 30 hours. Authorities were said to be  investigating whether Iran, or perhaps another group seeking to exploit the conflict between Iran and the United States, was behind the attacks.

Coast Guard cyber teams have been investigating “dark fleets” carrying sanctioned oil from Iran and Russia, which rely on digital masking to hide their operations and carry enhanced cyber risks, The Wall Street Journal reported in June.

Then-President Joe Biden signed an executive order in 2024 giving the Coast Guard additional authorities to respond to cybersecurity incidents, citing the risks that a maritime cyber incident could cause “cascading” harm to the global supply chain.

The Aug. 21 boarding party included Coast Guard law enforcement personnel, Coast Guard Cyber Protection Team members, a vessel inspector and FBI Cyber Action Team operators, who boarded “to conduct a comprehensive cyber security boarding and investigation,” according to the agencies’ joint statement. A similar team made up the Aug. 24 boarding party.

“The captain, crew, and shore-side corporate staff were critical partners in helping to ensure the threats were mitigated,” the statement reads.

Top Trump administration cyber officials have refused to answer questions from reporters recently about Iranian cyberattacks during the Middle East conflict. Trump himself has rejected the idea that Iran was behind a recent spate of attacks on U.S. water facilities.

The post Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks appeared first on CyberScoop.

‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help

The Trump administration rolled out a six-month test program in Texas on Monday that will draw on volunteer expertise and technology from cyber and artificial intelligence companies to protect the water sector.

“Project Watershed 250” is the first of the state-based, industry-centric pilot projects to cross the finish line that the Office of the National Cyber Director has previewed since the publication of its national cybersecurity strategy earlier this year. Water systems have long been viewed as among the most vulnerable and neediest critical infrastructure sectors, and in recent months the sector has been the victim of a spree of attacks.

“Project Watershed 250 is a commitment from the states, industry and federal government that we will continue to prioritize our nation’s safety and deliver on America-first policies for the American people,” National Cyber Director Sean Cairncross said at a rollout event in San Antonio Monday.

“U.S. companies are providing world-class cyber capabilities, red teaming that tests utilities’ current defenses, system hardening using the latest private sector cyber tools and AI tooling that helps utilities’ frontier cyber defenders to protect Texas water systems and scale proven solutions across the country,” he said. “This six-month pilot program is designed to make our water and wastewater critical infrastructure more resilient and resistant to cyber attacks by proactively finding and fixing system weaknesses.”

The pilot program, featuring collaboration between federal and state governments, stands in contrast to how the Biden administration tried to tackle the issue, with audit requirements that some GOP states challenged in court, forcing Biden’s Environmental Protection Agency to withdraw its rule.

“For too long, at least on the federal level, the government has admired the problem of cybersecurity in water systems,” Cairncross said. “We are going to find out what works. We’re going to target that, and we are going to scale off of this and learn lessons.”

A dozen companies — Parsons, Microsoft, Fortinet, Google Cloud, Palo Alto Networks, Amazon Web Services, Reflection AI, Cloudflare, Zscaler, Forescout, Abnormal AI and Dragos — appeared at the rollout Monday to praise the initiative and tout their contributions to it.

Not everyone praised the initiative elsewhere, however. One cyber professional who works on water security issues, speaking on condition of anonymity, said the program was “all smoke” and that “there’s no real money behind it.”

“The White House did what it always does — reached out to industry with their hands out asking for industry to pay for things the government should be doing, at least in part,” the person said.

Texas Gov. Greg Abbott said the program would be overseen by Cairncross’s office and Texas Cyber Command, which was established just last year. Abbott cited the need for the program by mentioning “an Iranian-backed cyberattack” on 30 water systems across 12 states and a 2024 attack on the water system in Muleshoe, Texas, suspected to be the work of Russian hackers.

“The need for cyber resilience is overwhelming,” Abbott said. “Many rural providers simply don’t have the resources they need to be able to protect themselves.”

Watershed 250 isn’t the only federal effort to bolster water cybersecurity, with lawmakers introducing legislation in the aftermath of the recent attacks. Past legislation that Congress has enacted also sought to tackle the problem.

Updated 8/31/26: with comment from cyber professional.

The post ‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help appeared first on CyberScoop.

Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’

As part of its “economic D-Day” against Iran, the Treasury Department designated four Iranians for sanctions Monday stemming from their alleged role in hacking critical infrastructure targets and waging cybertheft against the United States.

It’s the second time in as many weeks that the Trump administration has taken aim at the same group of alleged hackers, following on an indictment recently unsealed against cybercriminals that federal law enforcement authorities say are affiliated with the Tehran-based Mabna Institute.

A Treasury Department release points the finger at three people — Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda’i and Mojtaba Ghal’eh-Kuhi — as specifically conducting the hacks.

“Since at least late 2023, these three individuals have successfully compromised and exfiltrated data from multiple U.S. companies in various critical infrastructure sectors, including energy companies, defense contractors, healthcare institutions, information technology companies, and financial institutions,” the release states.

A fourth individual included in Monday’s sanctions, Mojtaba Ghal’eh-Kuhi, is listed as one of the leaders of the gang carrying out the Ministry of Intelligence and Security (MOIS)-directed attacks. Another listed leader, Behzad Mesri, first faced sanctions in 2018, as part of another round of sanctions focused on the Mabna Institute.

Finally, the Treasury Department designated one additional person Monday over related activity, Arman Kahzadian, for his alleged role in receiving or using business information stolen via cyber-enabled means.

The department said the Iranian hackers sometimes turn their gaze to domestic targets.

“The members of this group are also heavily motivated by personal enrichment and greed, leading some members to prioritize their own profits over operations that benefit the MOIS,” it said. “This has driven some of the group to target Iranian companies.“

Hackers that the U.S. government has identified as Iranian have been behind a spate of attacks on U.S. water facilities, despite denials from President Donald Trump himself about Iranian culpability.  The Treasury Department did not immediately respond to a request for comment Monday about whether the sanctions designees were involved in those attacks, nor has the National Security Agency responded to requests for comment on whether Iran was responsible for attacks at the center of an alert about attacks on water facilities.

Treasury Secretary Scott Bessent announced a fuller list of sanctions Monday as the war with Iran nears its five-month anniversary with no end in apparent sight.

“In the Second World War, D-Day marked the historic beginning of a campaign with our allies to target and drive the enemy from its positions, including those in third countries,” he said. “Today, in that same spirit, we are launching an economic onslaught against Iran’s financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime until Tehran stands alone.”

There are questions about whether the sanctions themselves are likely to change any behavior, particularly based on how they will be enforced. Iran has vowed “consequences” for the United States.

As part of the sanctions announced Monday, according to the department, “Treasury is expanding the categories of Iran-related conduct that may be subject to secondary sanctions in the future, making it easier to take action against those facilitating the regime. Treasury has issued determinations against five critical sectors –– digital assets, technology, gold, aviation, and shipping––  that the Iranian regime uses to try to prop up its failing economy.”

The post Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’ appeared first on CyberScoop.

AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn

Hackers are targeting water, food, energy, chemical, manufacturing and commercial facilities by taking aim at Siemens S7 Series programmable logic controllers (PLCs) and making use of artificial intelligence in the attacks, U.S. government agencies warned Wednesday.

It’s the latest government warning about attacks on critical infrastructure as the United States wages war against Iran, which the government blamed for a recent campaign against water and wastewater systems— but doesn’t mention in Wednesday’s alert. 

The National Security Agency didn’t immediately respond to a request for comment about who was behind the attacks on the PLCs, which are used to control manufacturing processes.

The agencies said the attacks were an “active threat,” rather than a theoretical one. The attacks could disrupt critical industrial processes, cause safety incidents or lead to the compromise of sensitive data.

Wednesday’s alert from the NSA, Cybersecurity and Infrastructure Security Agency, FBI, Energy Department and Environmental Protection Agency makes special note of the hackers using AI-generated exploitation scripts in the attacks.

“Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools,” the alert states. “In addition, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures. Threat actors can easily collect public information about vulnerabilities and weaknesses, find exposed and exploitable PLCs, and use AI-generated scripts to act on that information.”

A former top CISA official, Michael Garcia, thought that it was a first for the agency in one of its cybersecurity advisories (CSAs) about operational technology (OT).

“It is the first alert I have seen where CISA is saying in a CSA that a malicious actor is using AI scripts to target OT systems,” Garcia, now vice president of the cybersecurity practice at Monument Policy Advocacy, said on LinkedIn. But the advisory doesn’t recommend using AI in response, instead focusing on well-known, traditional defensive measures, he added.

Frenos, an OT penetration testing company, found another element of the alert troubling: The method by which the attackers could use the approach beyond Siemens-made PLCs.

“Siemens S7 is the subject here, but the exposure pattern is not brand specific,” Brian Proctor, CEO of the company, said in an email. “An adversary who has mapped your data blocks understands your process. They know what normal looks like, which means they know what an operator would fail to notice.”

The AI-generated scripts are disguised as legitimate monitoring tools, the advisory said of the hackers behind them.

“The actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected,” the advisory reads.

Siemens said it was “aware” of the alert and “is coordinating closely with CISA.”

“This advisory does not describe new vulnerabilities within the S7 Series programmable logic controllers (PLC). Instead, this reflects threat actors employing new techniques to exploit potential misconfigurations,” the company continued, noting a security bulletin it issued last month.

“Siemens will provide updates around this issue to potentially affected customers through our ProductCERT team,” it said. “At this point in time, we have not identified increased attack levels or unknown vulnerabilities in Siemens ICS products.”

Updated 8/20/2026: to include Siemens comment.

The post AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn appeared first on CyberScoop.

Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute

Federal authorities on Tuesday unsealed an indictment against 17 Iranians affiliated with the tech firm Mabna Institute, alleging a campaign of vast cybertheft on behalf of the Iranian government against universities, governments and companies.

It’s a second wave of indictments against the Tehran-based firm, expanding on and replacing a 2018 indictment of nine of the defendants from then and adding others. 

“Today’s charges, which include eight additional defendants, reveal the broader network allegedly behind a sweeping, state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions,” said Jamie McDonald, U.S. Attorney for the Southern District of New York. “More than eight years after making the original indictment public, these charges make clear that the passage of time will not deter us from identifying and pursuing those who target the United States from abroad.”

Unlike in 2018, the United States is currently waging a war against Iran that recently saw a 60-day negotiation deadline pass with no progress.

“Cyber operations have become a central instrument of national power, and attacks on American and allied institutions carry direct consequences for our security and economic strength,” McDonald continued.

According to the Justice Department, Gholamreza Rafatnejad and Ehsan Mohammadi founded the Mabna Institute around 2013 with the goal of helping Iranian universities and scientific and research organizations to steal from foreign scientific efforts. In doing so, it paid hackers-for-hire listed in the indictment.

The institute has compromised more than 100,000 professors’ email accounts globally, the indictment alleges, and successfully compromised 8,000 accounts at 144 U.S. universities and 178 universities in other parts of the world.

Its hackers used stolen credentials to take academic journals, dissertations and e-books across all fields of research, at least 31.5 terabytes worth in total. The institute sometimes sold stolen data, according to the indictment. 

“Through the course of the conspiracy, U.S.-based universities spent more than approximately $3.4 billion to procure and access such data and intellectual property,” a press release on the indictment states.

The defendants also have compromised and stolen from email accounts for at least five U.S. federal and state government agencies, 42 U.S. companies and 11 foreign companies, among them HBO. 

In all, the indictment brings 14 separate, sometimes overlapping charges against the 17 defendants, with sentences for each offense ranging from two to 20 years.

In conjunction with the indictment, the State Department’s Rewards for Justice program is offering up to $10 million for information leading to the location of four of the defendants.

The post Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute appeared first on CyberScoop.

❌