---
title: "Iranian state hackers targeting OT: why offline… | Firevault"
url: https://fire-vault.com/news/iran-ot-ics-targeting-offline-golden-copies-cni
description: "A new Congressional Research Service report names Iran alongside China, Russia and North Korea as a leading cyber adversary, with operations now reaching deep…"
lang: en-GB
---

News · Insight · 21 June 2026

# Iranian state hackers targeting OT: why offline golden copies decide the recovery

A new Congressional Research Service report names Iran alongside China, Russia and North Korea as a leading cyber adversary, with operations now reaching deep into industrial control systems. The recovery problem is no longer about backups. It is about whether your golden copies are reachable by the attacker.

Image: Mark Fermor (https://fire-vault.com/assets/mark-fermor-DWFWqeWL.jpg)

Mark Fermor CTO, CMO & Founder, Firevault

5 min read

Share

Share on LinkedIn: https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Firan-ot-ics-targeting-offline-golden-copies-cni
Share on X: https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Firan-ot-ics-targeting-offline-golden-copies-cni&text=Iranian%20state%20hackers%20targeting%20OT%3A%20why%20offline%20golden%20copies%20decide%20the%20recovery%0A%0AA%20new%20Congressional%20Research%20Service%20report%20names%20Iran%20alongside%20China%2C%20Russia%20and%20North%20Korea%20as%20a%20leading%20cyber%20adversary%2C%20with%20operations%20now%20reaching%20deep%20into%20industrial%20control%20systems.%20The%20recovery%20problem%20is%20no%20longer%20about%20backups.%20It%20is%20about%20whether%20your%20golden%20copies%20are%20reachable%20by%20the%20attacker.
Share on Facebook: https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Firan-ot-ics-targeting-offline-golden-copies-cni

Image: Industrial control room with PLCs and HMI screens, an Ethernet cable physically disconnected mid-air representing an air gap (https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/iran-ot-offline-golden-copies-hero.jpg)

Industrial control room with PLCs and HMI screens, an Ethernet cable physically disconnected mid-air representing an air gap

Why it matters

## What this means for organisations holding critical data

> _I came across this story in **Industrial Cyber**, written by Anna Ribeiro, reporting on an updated Congressional Research Service review of nation-state cyber operations against US networks. What stopped me was not another headline about ransomware. It was the explicit OT and ICS targeting: Iranian operators going after programmable logic controllers in water and wastewater facilities. When a state-backed actor reaches the control layer, the conversation changes from prevention to recovery._

> **Key takeaways**
>
> - Iran now sits alongside China, Russia and North Korea as a top-tier state-backed cyber adversary, with explicit OT and ICS targeting confirmed by the Congressional Research Service.
> - The IRGC-affiliated CyberAveng3rs campaign hit programmable logic controllers in water and wastewater facilities, the same class of device used across UK and European utilities.
> - Online backups reachable from the compromised network are not recovery copies. They are a second target.
> - Physically disconnected golden copies of PLC configurations, HMI projects and incident response runbooks are the layer that decides recovery time.

The Congressional Research Service has updated its multi-year review of nation-state cyber operations against US networks, and the headline is uncomfortable for anyone responsible for operational technology. Iran sits alongside China, Russia and North Korea as one of the four leading state-backed cyber adversaries tracked by US intelligence, and the report is explicit that Iranian operations now reach the control systems that run water, wastewater and energy.

The campaign attributed to the Islamic Revolutionary Guard Corps affiliated CyberAveng3rs group is the clearest signal. Those operators went after programmable logic controllers in water and wastewater facilities, the same class of device that sits inside thousands of UK and European utilities. Separately, Iranian actors exploited known vulnerabilities in Microsoft Exchange and Fortinet products to establish footholds inside critical infrastructure (https://fire-vault.com/control-for-critical-infrastructure) organisations, then moved on to data theft, ransomware and extortion. A parallel operation used Log4Shell to drop cryptocurrency miners and harvest credentials from federal networks.

## What the report is really saying

Strip away the country labels and a consistent pattern emerges. State-aligned actors are not relying on novel zero days. They are exploiting unpatched perimeter products, weak authentication and exposed internet-facing systems to gain quiet, persistent access. Volt Typhoon, the China-linked campaign also cited by CRS, is the textbook case: compromise critical infrastructure now, sit dormant, and retain the option to disrupt later. Iranian operators are running a similar play with a sharper appetite for OT.

For an OT security lead, that changes the question. The question is no longer whether the perimeter will hold. It is whether the systems that let you recover are themselves clean.

## Why OT recovery is the harder problem

IT estates have a recovery muscle. OT estates often do not. Programmable logic controllers, human machine interfaces, engineering workstations and historian databases cannot be patched on a monthly cadence without risking process integrity. The crown jewels are not the devices themselves. They are the configuration files, the HMI projects, the ladder logic, the engineering backups and the incident response runbooks that let an operator rebuild a process safely after compromise.

Lose those, or have them tampered with by an attacker who has been resident for months, and recovery stops being a technical exercise. It becomes a forensic reconstruction project measured in weeks.

## The gap most operators do not see

Most CNI operators back up OT configuration data to network attached storage that sits on the same routable network the attacker is already living on. Some replicate to a cloud bucket reached over the same federated identity that has just been phished. A handful keep tapes, but rotate them through the same domain credentials.

If the recovery copies are reachable from the compromised network, they are not recovery copies. They are a second target.

## The Firevault viewpoint

Physical disconnection is the only control that survives a determined, well-resourced adversary with months of dwell time. An air gap by policy is not an air gap. An air gap by wire is.

Firevault Offline Secure Storage (https://fire-vault.com/offline-secure-storage) exists for exactly this class of asset: a physically disconnected vault for the configuration files, engineering backups, HMI projects and incident response material that decide how quickly a CNI operator can restore safe operation. It cannot be reached from the IT network. It cannot be reached from the OT network. It cannot be reached from the internet. Restore is a deliberate, witnessed act, not an API call.

This is not a replacement for network segmentation, patching discipline or OT monitoring. It is the layer underneath them. When those controls are bypassed, and the CRS report makes clear they will be, the offline copy is what stands between an incident and an outage.

## Three actions for OT security leads this quarter

1. Inventory the recovery data that matters. PLC configurations, HMI projects, engineering workstation images, historian exports, IR runbooks and safety system parameters. If you cannot list them, you cannot protect them.
2. Sever the path between IT and OT recovery copies. Recovery data for OT must not live on storage reachable by a compromised IT identity, and vice versa.
3. Test restore from offline media every quarter. A golden copy you have never restored is a hypothesis, not a control.

The CRS report is a useful prompt, but the underlying message is older than this week. State-aligned operators are patient, they are inside critical infrastructure already, and the network controls that were meant to stop them have known limits. The recovery layer is where the next decade of CNI resilience is going to be decided. Make sure yours is somewhere the attacker cannot reach.

_Further reading: Firevault for OT and ICS (https://fire-vault.com/solutions/ot-cyber-security), NIS2 alignment for Offline Secure Storage (https://fire-vault.com/solutions/oss/compliance/nis2), NCSC ransomware-resistant backup guidance (https://fire-vault.com/compliance/ncsc-ransomware-resistant-backups)._

_Mark Fermor, Co-Founder, Firevault_

About the author

### Mark Fermor

Mark Fermor on LinkedIn (https://www.linkedin.com/in/mfermor)

CTO, CMO & Founder

Founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

Get started: https://fire-vault.com/get-started
Talk to the team: https://fire-vault.com/demo

**Hardware**Your copy sits on dedicated encrypted hardware

**Disconnect**Offline by default, connected only when you say so

**Recovery**A known-clean copy to rebuild from, on your timetable

**Location**Held in a secure Firevault Bunker

Related Reading

## You may also find these useful

Insight

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. New research shows no hacking was required: server-side marketing API keys sat in the public JavaScript of all three airport websites, unrotated, for more than four years.

27 Aug 2026 8 min
https://fire-vault.com/news/manchester-airports-group-data-breach-87-million-customers-2026

Insight

### T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

27 Aug 2026 7 min
https://fire-vault.com/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026

Insight

### Beacon breach: 1,500 charities exposed and an HIV charity's health data stolen

People supported by a Manchester HIV charity have been told sensitive health information may have been stolen after a breach at Beacon, the shared database platform used by more than a thousand UK charities. One supplier, one connected database, national exposure.

26 Aug 2026 3 min
https://fire-vault.com/news/beacon-charity-database-breach-hiv-charity-health-data-2026

Insight

### Iran-linked hackers shut down a UK power plant for four days

A small British generator was taken offline for four days after an Iran-linked cyber attack, reported as the first successful intrusion of its kind against UK power generation. The grid held. The control layer did not.

23 Aug 2026 4 min
https://fire-vault.com/news/iran-linked-hackers-uk-power-plant-shutdown-2026

Insight

### GTA 6 leaks: a nightmare or a blip for the biggest video game of the year?

Unreleased Grand Theft Auto 6 footage has appeared online ahead of Rockstar's official preview, and Take-Two is now in court seeking the identities behind the accounts sharing it. The game will still sell. The material that leaked can never be unseen.

22 Aug 2026 3 min
https://fire-vault.com/news/gta-6-leaks-rockstar-development-footage-2026

Insight

### Nine PBS: 50 Terabytes of History Trapped by a Cloud Vendor That Closed

A public broadcaster lost access to fifty terabytes of archival footage, spanning seventy years of regional history, when its cloud storage supplier suddenly went out of business. The files are still trapped in a Denver data centre.

18 Aug 2026 4 min
https://fire-vault.com/news/nine-pbs-archives-cloud-vendor-shutdown-2026

## Suggested Reading

- What is Offline Secure Storage The foundation of physical disconnection: https://fire-vault.com/how-it-works/offline-secure-storage
- Why Offline Secure Storage The case for physical control: https://fire-vault.com/why-oss
- Ransomware Defence Hold gold copies offline: https://fire-vault.com/oss-for-ransomware-recovery
- Control Physical path control for IT and OT: https://fire-vault.com/solutions/control
- Knowledge Vault All articles, guides and whitepapers: https://fire-vault.com/learn/knowledge
- Book a Demo See Firevault in action: https://fire-vault.com/demo

Back to Knowledge Vault: https://fire-vault.com/learn/knowledge

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/news/iran-ot-ics-targeting-offline-golden-copies-cni#webpage",
    "url": "https://fire-vault.com/news/iran-ot-ics-targeting-offline-golden-copies-cni",
    "name": "Iranian state hackers targeting OT: why offline…",
    "description": "A new Congressional Research Service report names Iran alongside China, Russia and North Korea as a leading cyber adversary, with operations now reaching deep…",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/iran-ot-offline-golden-copies-hero.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/news/iran-ot-ics-targeting-offline-golden-copies-cni#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/news/iran-ot-ics-targeting-offline-golden-copies-cni#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Learn",
        "item": "https://fire-vault.com/learn"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Knowledge Vault",
        "item": "https://fire-vault.com/learn/knowledge"
      },
      {
        "@type": "ListItem",
        "position": 4,
        "name": "Iranian state hackers targeting OT: why offline golden copies decide the recovery",
        "item": "https://fire-vault.com/news/iran-ot-ics-targeting-offline-golden-copies-cni"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "NewsArticle",
    "headline": "Iranian state hackers targeting OT: why offline golden copies decide the recovery",
    "description": "A new Congressional Research Service report names Iran alongside China, Russia and North Korea as a leading cyber adversary, with operations now reaching deep into industrial control systems. The recovery problem is no longer about backups. It is about whether your golden copies are reachable by the attacker.",
    "url": "https://fire-vault.com/news/iran-ot-ics-targeting-offline-golden-copies-cni",
    "image": [
      {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/iran-ot-offline-golden-copies-hero.jpg",
        "width": 1200,
        "height": 1200
      },
      {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/iran-ot-offline-golden-copies-hero.jpg",
        "width": 1200,
        "height": 900
      },
      {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/iran-ot-offline-golden-copies-hero.jpg",
        "width": 1200,
        "height": 675
      }
    ],
    "thumbnailUrl": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/iran-ot-offline-golden-copies-hero.jpg",
    "author": {
      "@type": "Person",
      "name": "Mark Fermor",
      "jobTitle": "CTO, CMO & Founder",
      "worksFor": {
        "@id": "https://fire-vault.com/#organization"
      },
      "url": "https://fire-vault.com/why-oss/about"
    },
    "publisher": {
      "@type": "NewsMediaOrganization",
      "name": "Firevault",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 600,
        "height": 60
      }
    },
    "datePublished": "2026-06-21T18:59:08.436281+00:00",
    "dateModified": "2026-08-28T08:03:22.256672+00:00",
    "mainEntityOfPage": {
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/iran-ot-ics-targeting-offline-golden-copies-cni"
    },
    "inLanguage": "en-GB",
    "articleSection": "Insight",
    "wordCount": 955,
    "keywords": "Iranian, Insight, data breach, cyber security, offline secure storage, data protection, physical air gap",
    "articleBody": "> _I came across this story in **Industrial Cyber**, written by Anna Ribeiro, reporting on an updated Congressional Research Service review of nation-state cyber operations against US networks. What stopped me was not another headline about ransomware. It was the explicit OT and ICS targeting: Iranian operators going after programmable logic controllers in water and wastewater facilities. When a s",
    "dateline": "United Kingdom",
    "speakable": {
      "@type": "SpeakableSpecification",
      "cssSelector": [
        "h1",
        ".article-summary",
        "h2"
      ]
    },
    "isAccessibleForFree": true,
    "copyrightHolder": {
      "@id": "https://fire-vault.com/#organization"
    },
    "copyrightYear": 2026
  }
]
```