By early morning April 25, crews at Israeli water facilities realized that something unusual was going on. According to reports, one pump began operating non-stop. At another facility, something seemed to have taken over the operating system, and the technicians couldn’t access its regulating interface. A third station reported “irregularities resulting from unplanned changes to the dataflow.”
About an hour later, Israel’s National Cyber Directorate released an unusual announcement. It admitted that the facilities were under attack and asked companies involved in the water and energy sectors to “immediately change internet passwords to access the control system, limit internet connections and verify that the most up-to-date version of the regulatory system is installed.”
The Security Cabinet met for a special session on May 7, with each participating minister required to sign a confidentiality form. Reports claim that the meeting discussed possible responses to the cyberattack, which was allegedly attributed to Iran. Senior officials said after the meeting that they regard the attack as a significant escalation of hostilities by Iran and that the Islamic Republic had crossed a red line by targeting civilian water resources.
On May 9, just two days after the meeting, The Washington Post reported that Israel responded with a massive cyberattack against an Iranian port that left it paralyzed for several days. According to the report, the target was the country’s major port, the Shahid Rajaee port terminal in the southern Iranian city of Bandar Abbas. A source quoted by the paper said, “The attack targeted the container terminal at the port and paralyzed loading and unloading at the port for several days.”
AL-MONITOR All-Access gives you unlimited access to all our journalism, the full Daily Briefing, exclusive interviews, premium newsletters, and live events — for less than $2/week.