Cyberattacks on operational technology (OT) systems have shifted from data theft and ransom demands toward outright physical destruction, according to experts speaking at the Black Hat USA cybersecurity conference in Las Vegas. This trend poses a serious threat to critical infrastructure operators, many of whom are already underfunded and understaffed while managing aging industrial equipment amid heightened geopolitical tension.
From espionage to physical sabotage
Cheri Benedict, a cybersecurity and supply chain adviser at the White House's Office of the Federal Chief Information Officer, said OT attacks are increasingly targeting physical operations rather than just data. Matthew Rogers, the operational technology cybersecurity lead at CISA, echoed this concern, noting a "real desire and willingness to cause this impact at scale". Recent Iran-linked intrusions into U.S. water systems have failed to compromise drinking water safety, but Iran has also worked to disable safety monitoring systems across water and other sectors—an escalation Rogers called "what should actually scare you".
A CISA advisory updated on July 22 revealed that Iran-linked actors planted malware on a programmable logic controller that overrode instruction sets responsible for maintaining safe operating parameters. This tactic traces back to 2017, when malware called Triton disabled safety equipment at a Saudi Arabian power plant, marking one of the earliest known examples of this attack style. Because operators rarely inspect PLCs unless they malfunction, such malware can remain undetected for years, making each compromised controller what Rogers described as "a ticking time bomb".
Wipers replace ransomware
Neal Pollard, a partner at consulting firm Control Risks, said wiper malware has become more prevalent than ransomware in some cases, reflecting "a change in intent and understanding" among threat actors even as overall attack volume stays consistent. Rogers added that hackers are increasingly deploying code designed to permanently cripple industrial control systems, warning that the U.S. lacks sufficient replacement equipment to recover at scale from such destruction.
The panel emphasized that longstanding weaknesses—default passwords, unpatchable legacy devices, and unencrypted communications—remain the primary entry points for attackers. Vu Nguyen, CISO at the Department of Justice, noted that isolated OT environments with limited connectivity make log collection and incident response especially difficult. Notably, Rogers said none of the recent malicious activity relied on a single CVE or advanced AI tools, since OT systems remain so vulnerable that sophisticated exploits simply aren't necessary.
Read the original article: