Cyber warfare

Is the recent accident at Iran Natanz nuclear plant a cyber attack?

On Sunday, an “accident” occurred in the electricity distribution network at Iran’s Natanz nuclear facility, experts speculate it was caused by a cyberattack.

A mysterious incident occurred on Sunday at the Natanz nuclear enrichment site and the media speculate it was caused by a cyber attack.

The “accident” impacted the electricity distribution network at Iran’s Natanz nuclear facility, Atomic Energy Organization of Iran spokesman Behrouz Kamalvandi told the Iranian Fars News Agency. 

According to The Jerusalem Post, the extent of the incident and damages caused are much graver than what Iran is publicly disclosed.

“A so-called “accident” at Iran’s Natanz nuclear facility on Sunday was the result of a “terrorist” act, the country’s nuclear chief Ali Akbar Salehi said, according to state TV.” reads the post published by Jerusalem Post.

“Based on reports, it seems that the so-called accident was caused by a cyberattack, possibly by Israel.”

Reports claim that the attack was launched by Israel-linked hackers, the same state is suspected to have had a main role in the Stuxnet attack that hit the same nuclear plant back in 2010.

In 2010, threat actors hit the Natanz plant to destroy the Iranian nuclear enrichment program, they developed the Stuxnet virus that destroyed over 1,000 centrifuges in the nuclear utility. 

Back to the present, the Iranian authorities are still investigating the accident, they only revealed that no injuries or pollution were caused by the attack.

“Malek Shariati Niasar, an Iranian MP and spokesman for a parliamentary energy commission, wrote that the incident is highly suspected as “sabotage,” as it occurred on Iran’s National Nuclear Technology Day and amid the renewal of talks between the Islamic Republic and Western nations on the JCPOA nuclear deal.” continues the JP.

The Iranian parliament is closely following the evolution of the investigation and will provide a public opinion on the matter, meantime Iranian MP Ali Haddady blamed Israel for the incident.

The incident took place, a day after Iranian President Hassan Rouhani announced that Iran had begun injecting uranium hexaflouride gas into advanced IR-6 and IR-5 centrifuges at Natanz.

In March, Iran announced that it has yet to recover from an explosion at its Natanz nuclear facility last July, but according to IAEA reports, Iran has started enriching uranium at its new underground Natanz facility using advanced IR-4 centrifuges.

Last week, a spokesman for the Iranian military blamed Israel and the US for an explosion on the Islamic Revolutionary Guards Corps’ Saviz vessel in the Red Sea.

If you want to receive the weekly Security Affairs Newsletter for free subscribe here.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Iran)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

U.S. CISA adds Wazuh, and WebDAV flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Wazuh, and WebDAV flaws to its Known…

2 hours ago

Exposed eyes: 40,000 security cameras vulnerable to remote hacking

Over 40,000 internet-exposed security cameras worldwide are vulnerable to remote hacking, posing serious privacy and…

4 hours ago

Operation Secure: INTERPOL dismantles 20,000+ malicious IPs in major cybercrime crackdown

INTERPOL announced that a joint operation code-named Operation Secure took down 20,000+ malicious IPs/domains tied…

14 hours ago

Over 80,000 servers hit as Roundcube RCE bug gets rapidly exploited

A critical remote code execution (RCE) vulnerability in Roundcube was exploited days after patch, impacting…

23 hours ago

A flaw could allow recovery of the phone number associated with any Google account

A vulnerability could allow recovery of the phone number associated with a Google account by…

1 day ago

Texas Department of Transportation (TxDOT) data breach exposes 300,000 crash reports

Hackers breached Texas DOT (TxDOT), stealing 300,000 crash reports with personal data from its Crash…

2 days ago