2026年8月24日 美国东部时间下午1:15 / 福克斯新闻网
此次事件发生在美国情报部门认定与伊朗有关的明尼苏达州30多个社区水务系统遭网络攻击之后
作者:摩根·菲利普斯 福克斯新闻网
史蒂夫·布奇警告美国水务基础设施面临日益严峻的网络威胁
美国前五角大楼高级官员、传统基金会访问学者史蒂夫·布奇做客《福克斯与朋友们早间版》,分析针对美国水务基础设施的网络攻击激增现象。布奇警告称,包括伊朗支持的黑客在内的国家支持行为体,正在利用市政公用事业中脆弱的数字系统。他强调地方政府迫切需要将关键控制系统与公共互联网隔离开来。
【新增】您现在可以收听福克斯新闻的文章了!
blob:https://www.foxnews.com/44f27c75-0b51-4213-b63f-60a439e95122
收听本文
4分钟
伊朗关联黑客疑似在上个月迫使英国一座小型发电机停运四天,这是最新迹象表明,与德黑兰有关的网络活动可能正从探测脆弱系统转向造成美国官员长期以来警告过的中断。
据向多家新闻媒体透露消息的英国安全官员称,此次停电事件系伊朗关联黑客所为。
英国能源大臣迈克尔·尚克斯在一份声明中表示:“明确一点:没有对更大范围电网构成威胁,也没有人断电。我们拥有世界上最具韧性的能源系统之一。”
他将该发电机描述为“微型”,但表示其部门已就此次入侵事件向企业高管通报了“他们应采取的安全防范措施”。
水务网络攻击波及至少7个州
英国安全官员认为伊朗关联黑客是此次停电事件的幕后黑手。(美联社照片)
此次英国停电事件发生数周前,黑客袭击了明尼苏达州30多个社区水务系统,侵入了用于远程监控和控制水泵及其他设备的技术系统。明尼苏达州官员并未公开点名攻击的实施者。多家新闻媒体援引美国官员和一份泄露的行业威胁共享备忘录的内容报道称,伊朗可能是罪魁祸首。唐纳德·特朗普总统公开驳斥了这一说法,称他不认为伊朗应为此负责。
这两起事件将民用基础设施置于美伊冲突的另一条战线的中心。随着军事对抗进入第六个月,规模相对较小、通常防御薄弱的水务和能源设施为黑客提供了一种途径,可以在不侵入大型电网或袭击军事目标的情况下造成物理破坏。
这些设施尤其容易受到攻击,因为许多设施依赖联网的工业控制系统,允许运营人员远程监控和管理物理设备。黑客一旦侵入,就能中断运营、将运营人员锁定在外或操纵水泵及其他机械的控制装置。
在7月份的一则警报中,美国联邦调查局和环境保护署表示,恶意行为者通过访问暴露在外的可编程逻辑控制器,并更改其互联网地址和密码,袭击了至少7个州的水务和废水处理公用事业机构。部分事件扰乱了水务运营,导致据报道的水压下降和洪水泛滥。
联邦机构还警告称,与伊朗有关联的行为体针对水务、能源和政府部门的类似工业设备发动了攻击,试图获取用于控制这些设备的软件权限。此类活动已经造成运营中断和经济损失。
伊朗的代理战争已跨越海洋,如今正叩响美国的大门
黑客袭击了明尼苏达州30多个水务系统的计算机化控制系统,迫使部分公用事业机构改用手动操作和备用程序。(托尼·韦伯斯特/维基共享资源)
伊朗黑客此前也曾针对美国基础设施发动过攻击。
威胁不仅限于工业系统。8月18日,美国司法部指控一家伊朗公司的17名成员实施了一场大规模网络盗窃行动,目标直指数百所大学、私营企业和政府机构。检察官表示,其中许多入侵行为是代表伊朗伊斯兰革命卫队及其他伊朗实体实施的,导致超过31太字节的学术数据和知识产权被盗。
2016年,美国司法部指控一名伊朗黑客侵入纽约州莱伊市一座水坝的控制系统。当时该水坝的闸门因维护处于断开状态,使其无法操纵水位和流速。
最近,美国机构将一场名为“CyberAv3ngers”的、与伊朗伊斯兰革命卫队有关联的行动,与2023年末至2024年初美国数十家设施的工业控制器遭入侵事件联系起来,这些设施包括水务和废水处理系统、能源公司、食品制造商和医疗保健机构。此次行动利用了暴露在公共互联网上且仍在使用默认密码的设备。
8月18日,美国司法部指控一家伊朗公司的17名成员实施了一场大规模网络盗窃行动,目标直指数百所大学、私营企业和政府机构。(Cyberguy.com)
订阅获取政治新闻简报
最近的这些攻击凸显了只需极少访问权限即可造成物理影响。在明尼苏达州,被入侵的控制器影响了用于追踪水位、水压、水泵运行和设备警报的系统;在部分社区,运营人员恢复系统期间,设备曾暂时停运。
点击此处下载福克斯新闻应用程序
目前尚不清楚德黑兰是否计划针对西方基础设施发动更广泛的行动。但英国为期四天的停运事件表明,一旦黑客侵入小型工业系统,他们可以在不侵入大型电网运营商或造成足以引发立即军事反应的大规模停电的情况下,扰乱物理运营。
Iran-linked hackers suspected in UK power-plant shutdown after alleged Minnesota water attack
2026-08-24 1:15pm EDT / Fox News
The incident follows cyberattacks on more than 30 community water systems in Minnesota that US intelligence linked to Iran
By Morgan Phillips Fox News
Steve Bucci warns of growing cyber threat to US water infrastructure
Former top Pentagon official and Heritage Foundation visiting fellow Steve Bucci joins ‘Fox & Friends First’ to analyze the surge of cyberattacks on U.S. water infrastructure. Bucci warns that state-sponsored actors, including Iran-backed hackers, are exploiting vulnerable digital systems in municipal utilities. He emphasizes the urgent need for local governments to isolate critical controls from the public internet.
NEW You can now listen to Fox News articles!
blob:https://www.foxnews.com/44f27c75-0b51-4213-b63f-60a439e95122
Listen to this article
4 min
Iran-linked hackers are suspected of forcing a small British power generator offline for four days last month, the latest sign that Tehran-linked cyber activity may be moving from probing vulnerable systems to causing disruptions U.S. officials have long warned about.
Iran-linked hackers were behind the outage, according to British security officials who spoke with multiple news outlets.
“To be clear: there was no threat to the wider grid and nobody lost power. We have one of the most resilient energy systems in the world,” UK Energy Minister Michael Shanks said in a statement.
He described the generator as “tiny” but said his department had briefed CEOs following the intrusion on “steps they should take to stay secure.”
WATER CYBERATTACK HITS AT LEAST 7 STATES
British security officials believe Iran-linked hackers were behind the power outage.(AP Photo)
The British shutdown came weeks after hackers struck more than 30 community water systems in Minnesota, accessing technology used to remotely monitor and control pumps and other equipment. Minnesota officials have not publicly attributed the attacks. Several news outlets, citing U.S. officials and a leaked industry threat-sharing memo, reported that Iran was the likely culprit. President Donald Trump has publicly rejected that assessment, saying he did not believe Iran was to blame.
Together, the incidents are putting civilian infrastructure at the center of another front in the conflict between the U.S. and Iran. As the military confrontation stretches into its sixth month, relatively small and often lightly defended water and energy facilities offer hackers a way to cause physical disruption without penetrating a major power grid or striking a military target.
Those facilities can be especially vulnerable because many rely on internet-connected industrial control systems that allow operators to monitor and manage physical equipment remotely. Once inside, hackers can interrupt operations, lock out operators or manipulate controls for pumps and other machinery.
In a July alert, the FBI and Environmental Protection Agency said malicious actors had targeted water and wastewater utilities in at least seven states by accessing exposed programmable logic controllers and changing their internet addresses and passwords. Some incidents disrupted water operations, causing reported pressure loss and flooding.
Federal agencies have also warned that Iranian-affiliated actors have targeted similar industrial devices across water, energy and government sectors, seeking access to the software used to control them. That activity has already caused operational disruptions and financial losses.
IRAN’S PROXY WAR HAS CROSSED OCEANS AND IS NOW KNOCKING ON AMERICA’S DOOR
Hackers targeted computerized controls at more than 30 Minnesota water systems, forcing some utilities to use manual operations and backup procedures.(Tony Webster/Wikimedia Commons)
Iranian hackers have pursued U.S. infrastructure before.
The threat extends beyond industrial systems. On Aug. 18, the Justice Department charged 17 members of an Iran-based company with carrying out a sweeping cyber theft campaign targeting hundreds of universities, private companies and government agencies. Prosecutors said many of the intrusions were conducted on behalf of the IRGC and other Iranian entities and resulted in the theft of more than 31 terabytes of academic data and intellectual property.
In 2016, the Justice Department charged an Iranian hacker with gaining access to the control system for a dam in Rye, New York. The dam’s sluice gate had been disconnected for maintenance at the time, preventing him from manipulating water levels and flow rates.
More recently, U.S. agencies linked an IRGC-affiliated campaign known as CyberAv3ngers to compromises of Israeli-made industrial controllers at dozens of U.S. facilities in late 2023 and early 2024, including water and wastewater systems, energy companies, food manufacturers and healthcare organizations. The campaign exploited devices exposed to the public internet that were still using default passwords.
On Aug. 18, the Justice Department charged 17 members of an Iran-based company with carrying out a sweeping cyber theft campaign targeting hundreds of universities, private companies and government agencies.(Cyberguy.com)
SIGN UP TO GET THE POLITICS NEWSLETTER
The more recent attacks underscore how little access may be required to produce a physical effect. In Minnesota, compromised controllers affected systems used to track water levels, pressure, pump operations and equipment alarms; in some communities, equipment was temporarily taken offline while operators restored systems.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Whether Tehran intends a wider campaign against Western infrastructure remains unclear. But the four-day shutdown in Britain illustrates what hackers can do once they gain access to a small industrial system: disrupt physical operations without breaching a major grid operator or triggering a blackout large enough to invite an immediate military response.
发表回复