FBI: Iran-linked hackers disrupted US oil, gas, water sites
The Hill's Headlines — April 8, 2026
Iran-linked hackers were responsible for recent disruptions to internet access for companies tied to U.S. oil, gas and water infrastructure, the FBI said in a report published Tuesday.
The report warned that similar companies across the country should be aware of an increased push by hackers to take over programmable logic controller (PLC) systems, which can be used to digitally control physical machinery from remote locations.
Secure internet access for PLCs from one company, Rockwell Automation, were removed by Iran-linked coders who then “maliciously interacted with project files and altered data,” according to the report.
Hackers first gained access to some of the platforms in January of last year. All access to compromised platforms ended in March, the report said.
The FBI said the move resulted in “operational disruption” and “financial loss.”
In 2019, Rockwell Automation partnered with SLB, formerly Schlumberger, to create Sensia, which provides automation solutions for the oil and gas industry.
The partnership was dissolved last week, but the company still works with major international oil companies including the Saudi-owned Aramco. Aramco is the world’s largest oil-producing company.
Rockwell Automation wasn’t the only company to recently face cyberattacks from Iran-linked hackers. Stryker, a major U.S. medical device maker, was targeted by Iran-affiliated coders in mid-March. It was unclear if physical operations were affected by the security breach.
FBI Director Kash Patel was personally impacted by hackers who leaked his emails and records related to his personal travels and business from more than 10 years ago.
“We have seen both state and non-state actors in Iran pose real risk and show willingness to hurt people through compromising these systems. I fully expect them to keep up the pressure and target those sites they can get access to,” Rob Lee, the co-founder and CEO of the cybersecurity firm Dragos, told Wired.
The FBI urged companies to adopt network defenders and multifactor authentication to prevent future attacks. Tuesday’s report was published alongside the National Security Agency, the Department of Energy, and the Cybersecurity and Infrastructure Security Agency.
“Government and experts have been warning about internet connected systems for years, and how vulnerable they are,” one source familiar with the federal investigation into the hacks told CNN.
Many companies have “already removed those systems and followed the guidance,” the person added.
The conflict between the U.S. and Iran appears to be cooling after the two countries agreed to a temporary ceasefire on Tuesday pending a longer-term peace deal.
The Trump administration has heavily bombed Iranian gas and energy infrastructure throughout the war.
Copyright 2026 Nexstar Media Inc. All rights reserved. This material may not be published, broadcast, rewritten, or redistributed.
Conversation
All Comments
Active Conversations
The following is a list of the most commented articles in the last 7 days.