Critical Infrastructure Security

Cyberattacks on emergency systems have become a tool of psychological warfare

Dispatcher monitoring emergency map screens in control room. Concept of dispatch center, public safety, incident tracking and emergency response operations.

COMMENTARY: Cyberattacks against critical infrastructure have traditionally been measured by their ability to interrupt operations, damage physical assets, or deny essential services.

Increasingly, threat actors have pursued a different objective: influencing how civilians perceive and respond during moments of crisis.

[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]

Recent claims by the Iranian-linked threat actor CyberAv3ngers that it disrupted Israeli air raid sirens during missile attacks illustrate this evolution. While the group's claims have not been independently verified, analysis of publicly-available technical artifacts offers insight into the techniques reflected in the operation and underscores a broader trend.

Emergency communications infrastructure, including warning sirens, public address systems, and mass notification platforms, has emerged as an attractive target not simply because of its operational importance, but because of the trust people place in these systems during emergencies.

Rather than focusing solely on physical disruption, these attacks seek to undermine confidence, create uncertainty, and influence civilian behavior. In many ways, they blur the line between cyber operations and psychological warfare.

Trust has become the target

Emergency communications systems occupy a unique role within critical infrastructure. They don’t generate electricity, move trains, or treat water. Instead, they deliver trusted information that helps people make life-saving decisions under stressful conditions.

That trust makes them uniquely valuable to adversaries.

Even a temporary disruption, or simply the perception that warning systems have been compromised, can create confusion that extends well beyond the technical impact of an incident. If civilians begin questioning whether air raid sirens, evacuation notices, or emergency announcements are legitimate, the effectiveness of the entire public safety system begins to erode.

This represents an important shift in how we should evaluate cyber risk. Attackers no longer measure their activities solely by operational downtime or financial loss. Instead, influence itself becomes an objective.

Cyber operations increasingly support information operations

Modern geopolitical conflicts increasingly combine military activity with cyber campaigns and information operations. Rather than operating independently, these efforts often reinforce one another.

Cyber capabilities can amplify uncertainty by targeting the infrastructure people depend on for accurate information during rapidly evolving events. Even if the technical impacts are limited, widespread reporting, social media amplification, and public speculation can magnify the psychological effect.

This evolution reflects a broader reality: cyber operations are no longer confined to IT systems or industrial processes. They increasingly intersect with public perception.

As operational technology and cyber-physical systems become more connected, they also become more accessible to adversaries seeking opportunities beyond traditional disruption.

Why emergency communications are attractive targets

Like many cyber-physical environments, emergency communications infrastructure often consists of specialized devices that remain deployed for many years. Operational requirements may limit maintenance windows, hardware replacements, or software upgrades. In some cases, internet-connected devices intended to simplify remote administration inadvertently expand the attack surface.

Threat actors understand these realities.

Recent publicly-reported incidents involving emergency communications have highlighted recurring interest in internet-exposed devices, publicly-disclosed vulnerabilities, and externally accessible management interfaces. While the specific techniques vary from one campaign to another, the underlying objective remains consistent: exploit systems that communities rely upon during emergencies.

These attacks demonstrate that cyber-physical systems are increasingly viewed as instruments of influence rather than operational targets.

Extend security beyond availability

For years, organizations responsible for cyber-physical environments have emphasized availability and safety. Those priorities remain essential, but they are no longer sufficient.

Defenders must also consider how cyber incidents could affect public confidence and crisis response.

That begins with understanding which assets exist across the environment and identifying unnecessary internet exposure. Organizations should continuously inventory connected devices, assess externally accessible assets, and prioritize remediation efforts based on operational risk rather than vulnerability counts alone.

Reducing unnecessary exposure, implementing strong authentication for remote access, segmenting operational networks, and continuously monitoring cyber-physical assets all contribute to improving resilience. We also have to ensure incident response plans account for scenarios involving emergency communications infrastructure, including how trusted public messaging would continue if primary systems were unavailable or suspected of compromise.

As cyber and information operations continue to converge, organizations should expect emergency communications systems to remain attractive targets for sophisticated threat actors.

Our adversaries may not always look to induce widespread disruption. In many cases, they just may want to sow doubt.

For security leaders, that means broadening how cyber resilience gets defined. It’s no longer solely about keeping operations running. It’s also about preserving trust in the systems communities depend on during their most critical moments.

In an era in which perception is often as consequential as disruption, securing emergency communications infrastructure has become an essential component of national resilience.

Sean Tufts, chief technology officer, Claroty

SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Each contribution has a goal of bringing a unique voice to important cybersecurity topics. Content strives to be of the highest quality, objective and non-commercial.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds