Tehran is likely to increase its cyberattacks on American infrastructure, which the United States must prepare for on a new front in the Iran war, a former White House adviser has told Newsweek. The warning by former acting Principal Deputy National Cyber Director Jake Braun comes as tensions between the U.S. and Iran are expected to spike more after Washington announced new “D-Day” sanctions punishing those who do business with the Islamic Republic. Braun, who served in the Biden administration, has long warned that U.S. water utilities, of which there are around 150,000, are at risk from Iranian hackers.
Reports last week that Iranian hackers had temporarily shut down a British power plant follow Tehran-linked hackers recently targeting water systems across the U.S. Braun, now executive director of the Cyber Policy Initiative at the University of Chicago Harris School of Public Policy, said that the reported attack on the British power plant signaled Tehran’s intent. Cybersecurity and Infrastructure Security Agency (CISA) has warned of cyberattacks on critical infrastructure by hackers linked to Iran's Islamic Revolutionary Guard Corps (IRGC).
U.S. officials suspect Tehran was behind the targeting of U.S. water systems in at least a dozen states, including New Jersey, Minnesota, Georgia and South Dakota. Minnesota officials have not publicly attributed the attacks, although news outlets, citing U.S. officials and a leaked industry threat-sharing memo, reported Tehran was to blame. President Donald Trump has rejected this.
It places civilian infrastructure as another front in the Iran war, with small and lightly defended water and energy facilities offering hackers a way to cause disruption without penetrating a major power grid or striking a military target. CISA reported earlier in April that Iranian-linked actors are using simple techniques like scanning for exposed devices and exploiting default credentials rather than sophisticated exploits of holes companies may not know exist. CISA also said individual plant operators are largely responsible for securing equipment, but often small utilities have few to no dedicated cybersecurity staff for devices that were never built with security as a priority.
Braun co-founded DEF CON Franklin to mobilize volunteer cybersecurity experts to defend water systems with free support for local providers and technology firms, such as help changing default passwords and enabling multifactor authentication. Until then, he said most hacks involved nation-state pre-positioning, like China or espionage and hacktivism by Russia. Artificial intelligence makes this possible much faster because it can scan tens of thousands of utilities at once to see which do not have their security configuration set up correctly, he said.
The Iran-linked hackers suspected of forcing a small British power generator offline did so for four days last month, according to The Telegraph. The hacking unit linked to the IRGC known as CyberAv3ngers was behind the attack, the Financial Times reported. Neither the British government nor the National Cyber Security Centre would give further details about the affected site, but the United Kingdom's Department for Energy Security and Net Zero (DESNZ) said the incident affected a small-scale generator and posed no risk to the wider energy system.
Extract — continue reading at the source.