
IT / OT Security News
Headlines: 2026
24 August 2026
Iran-Linked Hackers Shut Down UK Power Plant for Four Days
Iran-linked hackers reportedly managed to shut down a British power plant for four days in July 2026. The story was broken by the Telegraph newspaper on August 22, 2026. That it took so long to become public knowledge immediately says two things. Firstly, it was not a major power plant since the effect would have been immediately noticed, and secondly, the authorities wished to keep news of the attack as low key as possible.
21 August 2026
ISASecure and NSA develop HCSA certification scheme for high-criticality operational technology components
ISASecure, a wholly owned subsidiary of the International Society of Automation (ISA), is partnering with the U.S. National Security Agency (NSA) to develop a certification scheme for commercial operational technology (OT) components that manufacturers sell and the U.S. government procures for use in National Security Systems (NSS).
19 August 2026
US warns Siemens devices can be hacked amid fears Iran is breaching water plants
Several U.S. government agencies warned that unidentified hackers are trying to breach devices made by Siemens that are used to monitor and operate water facilities and other critical infrastructure systems, according to a cybersecurity advisory published on Wednesday.
10 August 2026
Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility
Poland’s computer emergency response team (CERT) has published a report detailing a second attack on the country’s power grid. The attackers targeted industrial control systems (ICS) and their objective was “purely destructive”.
7 August 2026
Cyber intrusion targets Childersburg Water, Sewer, and Gas system
The Childersburg Water, Sewer, and Gas Board reported that its computerized monitoring and control network was targeted in a cyberattack late last month, prompting officials to temporarily disconnect the system while additional safeguards are put in place.
6 August 2026
Hackers grow more willing to destroy, not just disrupt, OT systems
Cyberattacks on operational technology have shifted in recent years from extortion and espionage to destruction, a trend that should alarm those tasked with defending outdated industrial equipment, experts said on Thursday.
6 August 2026
At least 12 states report cyberattacks on water systems possibly linked to Iran-backed hackers, sources say
Cyberattacks on U.S. water systems that officials suspect may be linked to Iran-backed hackers have been reported in at least a dozen states, sources familiar with the matter told CBS News on Wednesday.
4 August 2026
US water facilities targeted by ‘malicious cyber actors’ – who’s to blame?
Late last week, federal authorities issued a stern warning saying “malicious cyber actors” were targeting water and wastewater facilities in at least seven states across the US. Minnesota appeared to be the hardest hit with 30 of its water systems hit by cyber-attacks, leading to disruptions in the state’s water supply.
30 July 2026
1 in 5 Data Center Assets Are Within Easy Reach of Attackers
Nearly one in five of the cyber-physical systems (CPS) that keep the world’s largest data centers running sits just a single network connection away from pathways that could let attackers reach them, according to new research from Claroty.
30 July 2026
Claroty’s Team82 reveals widespread CPS exposures across data center infrastructure, calls for zero trust measures
New research from cyber-physical systems (CPS) protection vendor Claroty’s Team82 threat research group warns that CPS (cyber-physical systems) supporting modern data centers face widespread and highly accessible security exposures.
23 July 2026
US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices
The US government has updated a recent cybersecurity advisory describing Iran-linked attacks on critical infrastructure organizations, warning that hackers have been targeting industrial control systems (ICS) made by Siemens, Schneider Electric, and Rockwell Automation.
22 July 2026
Hacker group RansomHouse claims responsibility for cyberattack on Nichirei
A hacker group calling itself RansomHouse has claimed responsibility for a cyberattack last week that disrupted operations at Japanese frozen-food and logistics company Nichirei, affecting restaurants, supermarkets and school lunch programs.
22 July 2026
Russian cyber espionage campaign exploits insecure IP cameras in Europe and Ukraine, Dutch agencies say
Dutch intelligence agencies warned that Russian state actors are systematically compromising internet-connected IP cameras across the Netherlands, other EU and NATO member states, and Ukraine to support cyber espionage, exposing organizations with vulnerable surveillance systems to intelligence-gathering operations.
16 July 2026
Legacy Systems, Real-World Impacts: The Reality of OT Security
At DEF CON, the ICS Village is one of the more popular places to hang out. It works well for folks who are either new to the field of infosec and cybersecurity, or old-hands in the industry, for the same reason: once you get close enough to a piece of OT technology with your modern IT vulnerability-hunting tooling and instincts, it often feels like you’re hacking like it’s 1999, all over again.
26 June 2026
NIST SP 1800-45 outlines remote access security as key priority for water, wastewater sector amid expanding OT cyber risks
The U.S. National Institute of Standards and Technology (NIST) is urging water and wastewater utilities to strengthen cybersecurity as the sector’s growing digital transformation expands exposure to cyber risk.
17 June 2026
Rockwell Automation Patches Vulnerabilities in ICS Controllers and Software
Rockwell Automation informed customers on Tuesday that patches are available for several vulnerabilities affecting its Logix and CompactLogix controllers, Flex I/O dual-port Ethernet/IP adapters, RSLinx industrial communication software, and FactoryTalk automation suite.
16 June 2026
Iran-linked Handala group targets Cal Water, exposing potential pathways between IT and OT environments
Dataminr disclosed that an Iran-linked threat group known as Handala has claimed responsibility for breaching systems belonging to California Water Service (Cal Water), one of the largest water utilities in the U.S., serving approximately two million customers across California.
12 June 2026
Cyberattack disrupts Mackay Sugar operations, exposing growing agri-industrial cyber risks
A cyberattack has disrupted operations at Mackay Sugar, Australia’s second-largest raw sugar producer, forcing the shutdown of its Farleigh and Racecourse mills in Queensland and bringing harvesting operations to a standstill.
10 June 2026
Critical HVAC and UPS Vulnerabilities Could Let Hackers Disrupt Data Centers
Researchers at cyber-physical systems security firm Claroty have uncovered multiple vulnerabilities in two widely deployed HVAC and UPS products used in data centers, demonstrating how attackers could exploit them to launch disruptive remote attacks.
24 May 2026
The War Between Wars: How an IRGC Cyber Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire
On a May afternoon, refrigeration engineers were called to a food-production plant. The cold rooms and freezers were warming up, and the product inside them was fresh. The engineers expected what they usually find: a failed compressor, a leaking valve, a tripped protection. They arrived ready to fix a machine.
20 May 2026
Real-World ICS Security Tales From the Trenches
Industrial control systems (ICS) and operational technology (OT) environments are often described as quiet, highly controlled worlds. In reality, they contain a range of risks, unexpected configurations, and operational complexities that are difficult to fully uncover through standard penetration testing or conventional risk assessments.
17 May 2026
State-backed ransomware activity raises new concerns over escalating threats to OT, critical infrastructure operations
Ransomware groups are increasingly being used as proxy weapons in geopolitical cyber warfare, enabling nation-states to exert pressure on their adversaries while maintaining plausible deniability.
8 May 2026
Polish Security Agency Reports ICS Breaches at Five Water Treatment Plants
Poland’s Internal Security Agency (ABW) has documented a significant escalation in cyberattacks targeting industrial control systems (ICS) and other operational technology (OT) infrastructure during 2024 and 2025, with state-sponsored threat actors increasingly shifting focus toward the physical disruption of critical services.
7 May 2026
Claude AI Guided Hackers Toward OT Assets During Water Utility Intrusion
Cybersecurity firm Dragos has released a threat intelligence report detailing an intrusion into a municipal water and drainage utility in Monterrey, Mexico, in which an unidentified threat actor made extensive use of AI tools to assist its operation.
15 April 2026
$10 Domain Could Have Handed Hackers 25k Endpoints, Including in OT and Gov Networks
The scale of infection among high-value targets proved particularly concerning. Of the hosts observed, 324 belonged to sensitive networks, including 221 universities and colleges, 41 operational technology (OT) networks, 35 government entities, and three healthcare organizations.
7 April 2026
Russian Hackers Exploiting Home and Small-office Routers in Massive DNS hijacking Attack
A large-scale campaign by Forest Blizzard, a Russian military-linked threat actor, targeting home and small-office routers to hijack DNS traffic and intercept encrypted communications with over 200 organizations and 5,000 consumer devices already compromised.
30 March 2026
Team Cymru warns exposed ICS and OT devices targeted by nation-state actors raise industrial, critical infrastructure risks
Following last month’s post highlighting its capabilities for protecting ICS (industrial control systems) and OT (operational technology) environments, Team Cymru published new research examining three case studies that reveal the extent of exposed ICS and OT devices known to be targeted by hostile nation-state actors. The findings underscore a critical concern: many of these systems remain directly exposed and vulnerable to exploitation.
24 March 2026
Iran Built a Vast Camera Network to Control Dissent. Israel Turned It Into a Targeting Tool
The role of Israel’s hijacking of Iran’s street cameras in the killing of the country’s supreme leader underscores how surveillance systems are increasingly being targeted by adversaries in wartime.
12 February 2026
CISA issues new OT security guidance to overcome cost and complexity barriers in critical infrastructure
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released new guidance aimed at closing long-standing gaps in OT (operational technology) security across critical infrastructure sectors, including water and wastewater, transportation, chemical, energy, and food and agriculture.
9 February 2026
Leaked technical documents show China rehearsing cyberattacks on neighbors’ critical infrastructure
China appears to be using a secret training platform to rehearse cyberattacks against the critical infrastructure of its closest neighbors, according to a cache of leaked technical documents reviewed by Recorded Future News.
30 January 2026
ICS Devices Bricked Following Russia-Linked Intrusion Into Polish Power Grid
The recent attack on Poland’s power grid, believed to have been conducted by Russian threat actors, targeted communication and control systems across roughly 30 sites and in some cases resulted in permanent industrial control system (ICS) damage, according to industrial cybersecurity firm Dragos.
26 January 2026
Poland repels data-wiping malware attack on energy systems
According to information shared by the Polish government earlier this month, the attacks happened on 29 and 30 December 2025, and targeted two combined heat and power (CHP) plants and a system enabling the management of electricity generated from wind turbines and photovoltaic farms.
15 January 2026
Chinese hackers targeting ‘high value’ North American critical infrastructure, Cisco says
Chinese hackers successfully breached multiple critical infrastructure organizations in North America over the last year using a combination of compromised credentials and exploitable servers, researchers at Cisco Talos found.