US government says Iran-linked hackers are disrupting American water and energy providers
US government says Iran-linked hackers are disrupting American water and energy providers
美国政府称伊朗相关黑客正在干扰美国水务和能源供应商
The U.S. government is warning that Iranian state-backed hackers are actively breaking in and disrupting industrial control systems at American water and energy providers. This new alert comes months after federal agencies warned of an escalation in hacking from Iranian actors amid the ongoing war. 美国政府发出警告称,伊朗政府支持的黑客正在积极入侵并干扰美国水务和能源供应商的工业控制系统。在联邦机构因当前战争局势警告伊朗黑客活动升级数月后,这一新的警报随之发布。
In an advisory updated Wednesday, the FBI, the NSA, the Department of Energy, and CISA said Iranian hackers were targeting programmable logic controllers on internet-connected operational networks, allowing them to manipulate data on their displays, causing outages and disruption. 在周三更新的一份公告中,联邦调查局(FBI)、国家安全局(NSA)、能源部和网络安全与基础设施安全局(CISA)表示,伊朗黑客正在针对连接互联网的运营网络中的可编程逻辑控制器(PLC)进行攻击,这使他们能够篡改显示屏上的数据,从而导致停电和系统中断。
The Iranian hackers were initially discovered earlier this year to be targeting controllers made by Rockwell, but the advisory has now expanded the types of industrial control systems under attack to include products from Schneider Electric and Siemens. The agencies warn that “potentially all internet exposed” industrial control systems may be affected, and urged critical infrastructure owners to take action. 今年早些时候,人们首次发现伊朗黑客针对罗克韦尔(Rockwell)制造的控制器进行攻击,但该公告现已将受攻击的工业控制系统类型扩大到包括施耐德电气(Schneider Electric)和西门子(Siemens)的产品。相关机构警告称,“所有暴露在互联网上的”工业控制系统都可能受到影响,并敦促关键基础设施所有者采取行动。
Per the advisory, the Iranian-backed hackers were “conducting this activity to cause disruptive effects within the United States,” likely in response to the ongoing war between Iran and the U.S. and Israel. According to the FBI, the hackers broke into one critical infrastructure provider and changed the controllers’ programming logic to disable processes that handled critical shutdowns and alarms. The feds said this allowed “systems to enter unsafe conditions without notifying operators of the anomalies.” 根据公告,这些伊朗支持的黑客“进行此项活动是为了在美国境内造成破坏性影响”,这很可能是对当前伊朗与美国及以色列之间战争的回应。据联邦调查局称,黑客入侵了一家关键基础设施供应商,并更改了控制器的编程逻辑,禁用了处理关键停机和警报的程序。联邦机构表示,这使得“系统在进入不安全状态时,不会向操作员发出异常通知”。
This is the latest in a series of cyberattacks launched by Iranian government hackers and their proxies across the region since the start of the war in February. The hacks have ranged from the country’s typical espionage and hack-and-leak operations, such as leaking the contents of FBI director Kash Patel’s personal email account, to more atypical destructive hacks that have caused large-scale damage or disruption. 这是自二月份战争开始以来,伊朗政府黑客及其代理人在该地区发起的一系列网络攻击中的最新一起。这些黑客攻击的范围从该国典型的间谍活动和“黑客入侵并泄露”行动(例如泄露联邦调查局局长卡什·帕特尔的个人电子邮件内容),到造成大规模破坏或干扰的非典型破坏性攻击。
Among the more notable incidents was a hack on the U.S. medical tech giant Stryker, which allowed the Iranian hacking group “Handala” to remotely wipe tens of thousands of employee devices. Handala also took credit for a data breach affecting California water provider Cal Water in June, and claimed it could have disrupted the water supply (without providing evidence). The water provider said that it saw no evidence of unauthorized access to its operational networks, which control the water supplies. 其中较引人注目的事件是对美国医疗科技巨头史赛克(Stryker)的黑客攻击,该攻击使伊朗黑客组织“Handala”能够远程擦除数万台员工设备。Handala 还声称对六月份影响加州水务供应商 Cal Water 的数据泄露事件负责,并声称其本可以中断供水(但未提供证据)。该水务供应商表示,没有发现其控制供水的运营网络遭到未经授权访问的证据。