Iranian-linked hackers are reportedly probing critical American infrastructure as Tehran searches for new ways to retaliate against the United States.
The latest threat reportedly targets water systems, telecommunications networks, energy infrastructure, and
other internet-connected automated equipment across the country.
Four people with access to government and industry cyberthreat information told NBC News the attempted intrusions occurred during recent weeks.
Those sources said the newest efforts have so far failed, offering some reassurance amid the escalating confrontation with Iran.
Still, cybersecurity experts warn relatively simple attacks can cause serious problems when outdated industrial equipment remains directly connected online.
A Telegram channel presenting itself as an Iranian cyberoperations voice issued a stark warning Sunday about potential attacks against America.
“Soon, the United States will witness unexpected and critical events in the energy, water, and telecommunications industries,” APT IRAN declared.
The group offered no public evidence proving that it had successfully breached any American system when issuing that ominous statement.
The warning follows heightened concern surrounding municipal water utilities already struck by disruptive cyber activity across multiple states during July.
The FBI and Environmental Protection Agency said water utilities in at least seven states reported cyber incidents beginning July 27.
Hackers remotely accessed internet-facing programmable logic controllers, devices responsible for monitoring and controlling essential industrial operations at affected facilities.
Federal investigators said attackers changed IP addresses and passwords, causing some utilities to lose monitoring and control functionality temporarily.
Officials later said malicious actors targeted more than 100 internet-exposed water and wastewater systems during the July cyber campaign.
Federal authorities have investigated possible Iranian involvement, but the FBI has not publicly made a definitive attribution for those attacks.
Nevertheless, Iranian state-backed hackers have a documented history of targeting American organizations and exploiting poorly protected operational technology.
CISA repeatedly warned infrastructure operators this summer to reduce internet exposure and strengthen protections around equipment controlling physical processes.
Federal guidance recommends removing controllers from direct internet exposure while using firewalls, secure gateways, unique passwords, and strict access controls.
Smaller municipal utilities remain particularly vulnerable because many operate aging technology without the cybersecurity resources available to major corporations.
That weakness makes basic intrusion techniques dangerous when hackers can reach devices
controlling pumps, valves, pressure, and treatment equipment.
The latest reported Iranian activity arrives as military hostilities between Washington and Tehran sharply intensify following renewed American strikes.
U.S. Central Command said American forces struck Iranian Revolutionary Guard Corps targets across Iran on September 1.
Targets included air-defense sites, radar systems, maritime assets, mine-laying capabilities, communications facilities, and other military infrastructure, CENTCOM said.
CENTCOM said the strikes followed attempted IRGC attacks on commercial shipping and American service members near the Strait of Hormuz.
More than 50,000 American troops are currently operating across the Middle East amid the continuing confrontation, according to CENTCOM.
The command said those forces remain “vigilant, lethal, and prepared” to carry out additional operations ordered by President Donald Trump.
The cyber threat opens another front where Tehran could seek retaliation without directly confronting America’s overwhelming conventional military power.
America’s power grid, water plants, pipelines, communications networks, hospitals, and transportation systems increasingly depend upon interconnected digital technologies.
Cyberattacks against civilian infrastructure also allow hostile governments or affiliated groups to create fear far beyond traditional military battlefields.
A successful attack disrupting electricity, communications, or water could impose enormous economic costs without requiring missiles to reach American territory.
So far, the newest reported attempts have failed, and officials have announced no successful nationwide compromise of critical infrastructure.
CISA’s findings suggest the central weakness is often preventable exposure rather than an unstoppable technological advantage possessed by America’s adversaries.
The White House referred NBC’s questions about the latest cyber activity to the FBI, which did not provide a response.
CISA also did not respond to NBC’s request for comment, while the CIA declined to discuss the reported activity.
That official silence leaves major questions unanswered, including who launched each intrusion and whether coordinated Iranian-linked campaigns remain underway.
But Washington cannot afford complacency while foreign hackers actively hunt weaknesses in systems Americans depend upon every day.
America’s message must remain unmistakable: harden vulnerable networks, identify hostile operators, and impose consequences when adversaries attack critical infrastructure.
