All posts tagged: Critical infrastructure

Russian spooks hack Wi-Fi routers to spy on West – POLITICO

Russian spooks hack Wi-Fi routers to spy on West – POLITICO

Officials believe the hacking group used the stolen data to conduct cyberattacks, information sabotage and intelligence gathering and focused on military, government and critical infrastructure targets. “The Russians tried their best to cover all vulnerable routers, while redirecting requests only to domains they were interested in. For example, *.gov.ua, or with names corresponding to Microsoft Outlook, military systems,” said a law enforcement official taking part in the joint operation, granted anonymity to disclose more details. Ukraine’s SBU said “the Russian special services paid special attention to information exchanged between employees and servicemen of state bodies, units of the Ukrainian Defense Forces and enterprises of the defense-industrial complex.” Agencies tied the campaign to hacking group Fancy Bear (also known as APT28 and Forest Blizzard), which has previously been identified by Western officials as part of the Russian military intelligence service GRU. Hackers exploited weaknesses in routers since at least 2024, including in popular TP-Link routers. By hacking the routers, they were able to snoop on data exchanges from mobile devices and laptops and bypass encryption protocols, …

Iran-Linked Hackers Are Sabotaging US Energy and Water Infrastructure

Iran-Linked Hackers Are Sabotaging US Energy and Water Infrastructure

As US President Donald Trump threatens wholesale demolition of Iran’s infrastructure in the midst of an escalating war, Iran now appears to have already reciprocated with its own form of infrastructure sabotage: A hacking campaign hitting industrial control systems across the United States, including energy and water utilities, that US agencies say has had disruptive and costly effects. In a joint advisory published Tuesday, a group of US agencies including the FBI, the National Security Agency, the Department of Energy, and the Cybersecurity and Infrastructure Security Agency warned that a group of hackers affiliated with the Iranian government has targeted industrial control devices used in a series of critical infrastructure targets including in the energy sector, water and wastewater utilities, and unspecified “government facilities.” According to the agencies, the hackers have targeted programmable logic controllers (PLCs)—a type of device designed to allow digital control of physical machinery—in those facilities, including those sold by industrial tech firm Rockwell Automation, with the apparent intention of sabotaging their systems. By compromising those PLCs, the advisory warns, the hackers …

Iranian hackers are targeting American critical infrastructure, US agencies warn

Iranian hackers are targeting American critical infrastructure, US agencies warn

The U.S. government is warning that Iran-backed hackers are escalating their tactics by targeting American critical infrastructure systems with the aim of causing disruption. In a joint advisory published Tuesday, the FBI, the National Security Agency, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), and the U.S. Department of Energy collectively warned that Iranian government hackers have been exploiting internet-facing systems used across a range of sectors. These include water and wastewater utilities, as well as energy and local government facilities. The agencies did not specifically name any of the targets but said that the hacks were aimed at causing “disruptive effects within the United States” and had already resulted in “operational disruption and financial loss.” The hackers targeted programmable logic controllers and supervisory control and data acquisition (SCADA) products, which are used to control and manage industrial equipment and systems in critical infrastructure operations, the agencies said. The agencies said that the hackers were able to manipulate information displayed on these devices and maliciously interact with project files that store important device configurations. The …

Ukraine deepens Gulf security ties as Kyiv exports air defense expertise – POLITICO

Ukraine deepens Gulf security ties as Kyiv exports air defense expertise – POLITICO

Ukraine has been pushing to bolster security agreements with Gulf states and on Friday signed a defense cooperation pact with Saudi Arabia, during a visit by Zelenskyy to Riyadh. That accord, Zelenskyy said, “lays the foundation for future contracts, technological cooperation, and investment. It also strengthens Ukraine’s international role as a security donor.” The outreach reflects Kyiv’s broader push to leverage its battlefield experience following Russia’s full-scale invasion of Ukraine, positioning itself as a security partner to countries facing rising regional threats, particularly from Iran. Since the start of the Iran war, Kyiv has been pitching its unique experience and interceptors to the Middle Eastern countries, which rely on costly PAC-3 and other systems to shoot down Iranian drones, capabilities which Ukraine lacks. Ukraine has also sent more than 200 of its own drone-сountering experts to Saudi Arabia, the UAE and Qatar. Some 30 more were heading to Jordan and Kuwait, Zelenskyy told reporters via a WhatsApp chat last week. Ukraine’s Foreign Minister Andrii Sybiha told Reuters on Friday that Kyiv is close to finalizing security agreements with …

EU sanctions Iran group that hacked Charlie Hebdo – POLITICO

EU sanctions Iran group that hacked Charlie Hebdo – POLITICO

Capitals also sanctioned Chinese company Integrity Technology Group and Chinese firm Anxun Information Technology, also known as i-Soon, and its co-founders Chen Cheng and Wu Haibo, who are banned from entering the EU, the EU sanctions listing showed. According to the details of the sanctions, Anxun Information Technology targeted “critical infrastructure and critical state functions” of EU countries and sold classified information as part of so-called hack-for-hire services.  The United States Department of Justice in March 2025 indicted 12 people involved in i-Soon for cyberattacks the U.S. said it had carried out at the behest of Chinese security services. Chinese security services “paid handsomely” for the data the groups stole, the department said.  Integrity Technology Group, the other Chinese company, facilitated the activities of a Chinese state hacking group dubbed Flax Typhoon, which security officials say has targeted organizations in Taiwan for espionage purposes. Flax Typhoon used Integrity’s products and technology to hack into more than 65,000 devices in six EU member countries, the Council of the EU said on Monday. The U.S. Treasury Department …

Why Europe can’t defend what it can’t connect  – POLITICO

Why Europe can’t defend what it can’t connect  – POLITICO

Europe enters a more contested decade than any since the end of the Cold War. Yet the frontline shaping its security is no longer limited to land, sea, air or even space.   It runs directly through the digital backbone that powers modern life: the networks, data infrastructures and connectivity systems on which governments, economies and armed forces depend.  But Europe will not be secure until it takes this digital backbone’s security seriously, and governs its openness through risk-based, verifiable sovereignty rather than isolationism or complacency.   Europe will not be secure until it takes this digital backbone’s security seriously, and governs its openness through risk-based, verifiable sovereignty A digital frontline that remains dangerously exposed  Hybrid threats no longer sit at the margins of European security. In reality, they cut straight through its core systems. Hospitals, energy grids, transport networks, financial markets and military command-and-control all rely on constant, resilient connectivity.   Via Vodafone. Joakim Reiter, group chief external and corporate affairs officer, Vodafone. And when those systems falter, nations falter. Recent blackouts in Portugal and Spain revealed what this means in practice. A ‘digital failure’ is not an …

Spain is handing ‘crown jewels’ to Huawei, lawmakers warn – POLITICO

Spain is handing ‘crown jewels’ to Huawei, lawmakers warn – POLITICO

The Spanish government has defended the contract it struck for storing wiretaps. Spain’s Interior Ministry said in a statement that the government had awarded a contract to “European companies,” which then bought storage products. “There is no risk to security, technological and legal sovereignty, nor is there any foreign interference or threat to the custody of evidence,” the ministry said. Interior Minister Fernando Grande-Marlaska told the Spanish parliament last September that Telefónica, the country’s telecom champion, operated a state surveillance system called SITEL and that storage “cabinets” had been integrated into that system.   Bloomberg reported last July that Huawei equipment is not used for classified information, with one government official saying the storage “represents a minor part of a watertight, audited, isolated and certified system.” On Monday, Juan Fernando López Aguilar, a prominent member of the European Parliament for the Socialists and Democrats group and a member of Prime Minister Pedro Sanchéz’s party in Spain, defended Madrid’s contract and pushed back on EU moves to intervene on the issue. In terms of “security, espionage, or …

Washington pushes back against EU’s bid for tech autonomy – POLITICO

Washington pushes back against EU’s bid for tech autonomy – POLITICO

Europe and the U.S. “face the same sort of threat and the same threat actors,” said Cairncross, who advises Trump on cybersecurity policy. Rather than weaning off America, wean off China, he said: “There is a clean tech stack. It is primarily American. And then there is a Chinese tech stack.” Claiming that U.S. tech is as risky as Chinese tech is “a giant false equivalency,” according to Cairncross. “Personal data doesn’t get piped to the state in the United States,” he said, referencing concerns that the Beijing government has laws requiring firms to hand over data for Chinese surveillance and espionage purposes. The attempt to quell concerns is notable even if it may not change the direction of travel in Europe. The European Commission wants to boost homegrown technology with a “tech sovereignty” package this spring. It presented a cybersecurity proposal in January that, if approved, could be used to root out suppliers that pose security risks — including from America. “We want to ensure that we don’t have risky dependencies when it comes to …

Russian offensive appears to be slowing after Musk blocks Starlink access, Ukraine says – POLITICO

Russian offensive appears to be slowing after Musk blocks Starlink access, Ukraine says – POLITICO

“In fact, they [Russian units] have problems now. They are like blind kittens,” a Ukrainian General Staff commanders told POLITICO separately, also granted anonymity to discuss sensitive matters. On Friday, Russian military bloggers, who in the past have praised Musk for his anti-Ukrainian rhetoric, complained about the mass failure of terminals for the Starlink satellite service that began on the evening on Feb. 4 on the frontline in Ukraine.  “The Russian Armed Forces used gray Starlinks to organize communications at the front. The danger is that it was an easy way compared to doing something new, pulling an ever-breaking optical fiber, setting up ‘bridges,’ or even working en masse with digital stations to organize the transmission of small data packets,” Russian pro-war military Telegram channel Dva Mayora, said in a post on Thursday. “Gray” Starlink terminals are ones that are not authorized or verified. “Now it’s either the old-fashioned way, or they’ll come up with something of their own urgently,” the bloggers added, blaming Musk for assisting the Ukrainian army. Earlier this week, Ukraine’s Defense …