Hacking America
Cyberwarfare
Last time, I talked about Iran’s missile capabilities. Missile retaliation is the most obvious of available options.
But the US has explicitly threatened cyberattacks on Iran, which is foolish because the Iranians have been preparing for this for years. If a tech-savvy adversary like Iran responds to a US cyberattack, the situation could escalate to a coordinated, unrestricted takedown of U.S. civilian networks, which the United States is absolutely not prepared to handle. The immediate result would be chaotic.
Iranian hackers have spent years quietly infiltrating networks in the US. IRGC Cyber groups such as Cyber Av3ngers and Mint Sandstorm specialize in breaking into systems and then remaining completely silent, using legitimate, built-in network administration tools rather than writing obvious malware, making them nearly invisible to standard antivirus software.
They have mapped out the operational technology (OT) of thousands of U.S. municipal water systems, regional electrical substations, and transport networks, in fact, digitally dependent systems of all kinds. They are not waiting to hack in; they are already inside, holding access codes and ready to activate them simultaneously.
The biggest vulnerability is America’s mindset . Its overconfidence.
Part of the reason for AI is to digitize everything —moving to a cashless economies, automated water treatment, smart electrical grids, and cloud-dependent logistics: it is an unending list – but all for convenience and profit. the Pentagon and Wall Street are well protected, of course but the critical infrastructure daily life relies on is decentralized and necessarily “open” to facilitate AI automation. Financial support “trickles down”.
A small-town water utility or a regional cargo rail network cannot afford super expensive cyber security.
Iran’s hackers don’t waste time trying to crack the NSA; they target undefended, underfunded infrastructure that actually matters -- that keeps the country running. Since the corporations and agencies that run things assume and advertise constant stability, these essential systems have zero padding.
To make things worse, if those covert systems are activated, they could also affect the internet, TV, and all kinds of communications technologies so the government cannot talk to the public, and the public has no way of knowing what is happening except word of mouth.
The U.S. is a “just-in-time” society. Food, fuel, and medical supplies are delivered exactly when needed. If the digital logistics networks that control those shipments are corrupted or wiped by Iranian hackers, the physical supply chain snaps instantly.
Because almost no one has emergency gear, there will be nationwide panic and localized breakdown of civil order within 72 hours. The public is not used to this kind of stress.
The US is a glass house. If it throws the first rock at Iran, Teheran will respond.
If you shoot an arrow — don’t miss.
Do you think federal bureaucracy can cope? When have they ever? When has any President made a difference in a disaster? George Bush reading My Pet Goat on 9/11?Obama relaxing in Martha’s Vineyard during the Louisiana floods?
What US sectors are most dangerously vulnerable?
Water and Wastewater Systems (Critical Vulnerability+overconfidence)
Water and Wastewater Systems are fragile because they are highly digitized for remote operations but completely decentralized and financially starved. And —t here are over 15,000 unique municipal water systems in the U.S.
Unlike the military, these local utioverconfidencelities are run by city governments with tiny budgets, often relying on a single IT worker or external contractors.Groups like the IRGC-affiliated Cyber Av3ngers target the Programmable Logic Controllers (PLCs) that control water pumps, chemical levels, and valves, to exploit internet control systems that still use factory-default passwords.
A coordinated strike could instantly force hundreds of towns into manual operation, causing pressure loss, localized flooding, or boil-water panics.
Healthcare and emergency services
Iranian hackers, including proxy groups, may target hospitals and medical manufacturers because they are vital in any kind of disaster and cannot afford downtime. Hospitals rely on a massive web of interconnected Internet-of-Things (IoT) devices, from MRI machines to automated insulin pumps, most of which have no built-in security features.. That sounds pretty nasty but the US and Israel have already hit Iranian healthcare facilities, killing many people. What goes round, comes round.
Activations of malware can freeze internal scheduling and patient databases. When a hospital’s digital network is locked, ambulances must be diverted, surgeries, canceled, and critical medical supply chains halt.
Energy and the Electrical Grid (High Vulnerability)
While the high-voltage transmission lines of the main U.S. power grid are well protected, the local distribution grids that deliver electricity to homes and businesses are not. These grids rely heavily on legacy operational technology (OT) built decades ago.. To reduce smart-grid costs, companies have hooked up these ancient mechanical systems directly to the internet.
Intelligence sources warn that foreign hackers, including Iranian groups are already inside local electrical cooperative networks mapping the digital terrain so they can remotely flip circuit breakers to plunge specific regions into darkness selectively or all at once during a conflict.
Transportation and Logistics (Medium-High Vulnerability)
The U.S. supply chain relies on “just-in-time” delivery_-- grocery stores and distribution hubs hold almost no inventory and expect trucks and trains to delivery what they need around the clock. Shipping companies, commercial ports, and freight rail operators rely on automated tracking software and digital signaling systems to move goods.
A coordinated cyber strike targeting the terminal operating systems at a major maritime port (like Los Angeles or New York) or the automated routing systems of freight rail corridors would cause an immediate physical backup. Within 48 hours, trucks would idle, ships would be unable to offload, and the domestic supply chain would freeze, triggering panic. Where are my burritos? No coffee?
Physical Vulnerability Matrix.
Healthcare
Interconnected, unpatched medical IoT devices.
Ransomware and data wiping of patient systems.
Diverted ambulances and halted medical manufacturing.
Local Power
Legacy machinery connected to the public web.
Pre-positioning inside regional circuit breakers.
Localized blackouts targeting specific cities.
Logistics
Complete dependency on automated tracking software.
Disrupting freight rail and port automated networks.
Sudden, systemic freeze of food and fuel deliveries.
Psychological
The American public is passive. It has an unspoken “don’t ask, don’t tell “ agreement with government that everything is OK if its basic physical needs are met. Yes, burritos.
But for that to work it needs, the media and communications technologies to provide distractions and tell it that its burritos are OK.
An attack on communications not only blinds the authorities, the public finds itself in a total information vacuum.Things are definitely not OK and it doesn’t know if it’s going to get worse, or why, or if help will come.
Cellular Networks and Telecom Infrastructure (The Highest Civic Impact)
The U.S. cellular grid relies on a highly consolidated network of physical towers and digital routing hubs managed by a handful of massive carriers.
Cell towers require continuous power and are connected to regional routing centers via fiber-optic cables or microwave links. The software that manages mobile data traffic, handles roaming, and routes calls is centralized and increasingly cloud-based, making it vulnerable to network-based attacks. Targeting the core routing networks of major carriers would instantly drop cellular data and voice services across entire states.
If cell service vanishes simultaneously with power or water outages, the public is instantly isolated—unable to contact emergency services, check on family members, or access web-based emergency updates.
Commercial Broadcasters and Cable TV Systems
Local and national television networks are the primary medium the government uses to visually reassure the public and project order during a crisis. But modern TV networks, from newsrooms to local affiliate broadcast stations, run entirely on internet-connected production software, digital master control systems, and automated satellite uplinks.
Iranian hackers have historically favored highly visible, symbolic defacements.
In a total-war scenario, rather than just knocking TV networks offline, they may be able to hijack the automated broadcast feeds of major cable channels, replacing standard programming with fake emergency alerts, forged casualty reports, or psychological warfare messages. They can trigger immediate, widespread civil panic before the feeds can be manually severed.
Satellite and Internet Routing Protocols (BGP Hijacking)
The internet does not exist in a vacuum; it relies on a delicate, trust-based directory system called the Border Gateway Protocol (BGP) to route data between global networks.
BGP was designed decades ago based on mutual trust between networks. It is fragile and vulnerable to routing manipulation, claims that certain servers are the fastest path for specific internet traffic.
Iranian cyber units is said to have have successfully executed BGP hijacking incidents in the past to reroute Western internet traffic through servers in Tehran. In a major conflict, a massive BGP routing attack could misdirect or swallow U.S. domestic internet traffic, causing widespread cloud outages, taking down major news websites, and freezing emergency web communications.
The “Amplification” Effect on Other Vulnerable Sectors
A successful strike on media and communications acts as a force multiplier that makes every other infrastructure failure exponentially more dangerous:
Water / Power Outage] + [Communications Blackout
No Way for Authorities to Explain the Situation
Rumors and Worst-Case Scenarios Take Over
Unstoppable Widespread Civil Panic Within 24-48 Hours
Television Media Threats
Internet-connected automated broadcast feeds.
Hijacking feeds to air deep fakes or false alerts.
Mass psychological shock and loss of faith in news.
Internet Routing Threats
Fragile, legacy protocol architecture (BGP).
Traffic interception and routing black holes.
Sudden widespread website collapses and cloud failure
All this sounds pretty bad. Keep in mind, however, all this comes from US sources.
Tke US national security establishment frequently inflates cyber warfare threats to secure funding, protect institutional turf, and drive commercial defense integration.
While cyber espionage and digital disruption threats are real, how do we know that they would result in a digital apocalypse?
We don’t. The whole concept of CyberWar is ever so 21st Century. But we can guess that anything the US might do to Iranian cyber systems, the Iranians can do to us.
AI increases the ambiguity and complexity.
The increasing ubiquity of automated AI systems digitizing every area of life depends on code. But it depends also on trust in the social contract. A good hacker can use AI too and manipulate not just code but trust destroying it in such a way that “society” is reduced to its basic elements – me, myself and I.
Who cares about the future of the US of A, when one’s own future is in doubt?
We looked at female cats. I am owned by two male cats. And the video is pretty accurate .
Support New Forensics
Chappy and Ichi are boys— and so am I . This is a Boys Club.
Please donate to support Chappy and Ichi and their sidekick, Julian, by clicking on the graphic or the url below.
I would really like to get to 5000 subscribers. If you like my work, share the urls on other blogs and sites and in comments on podcasts.
Show us you care by buying us coffee at https://buymeacoffee.com/julicow















I seriously doubt that Iranian hackers would ever target hospitals and the healthcare sector, based on Islamic law (Sharia). Other critical infrastructure maybe, depending on the type of cyberattack the Outlaw US Empire launches on Iran first, but hospitals definitively no! In order of decreasing probability (from high to low):
1. electricity
2. communication
3. logistics
4. water and wastewater
5. healthcare
"[T]he Pentagon and Wall Street are well protected, of course..."
I really, really would not count on that. Not for a moment. Do you believe that the Pentagon, which cannot even run its own core business of killing people competently, has taken the trouble to instil security into its many, many computers ranging from huge mainframes to smartphones and watches? Of course not. Moreover, the ethos of computer security is directly incompatible with that of military discipline and procedure. Few really good security people would be prepared to work for military officers who have no inkling of their world or the way they have to think.
As for Wall Street... the same in spades. Who is going to get promoted on Wall Street for fixing or improving - or even instituting - computer security? No one who matters. And why would anyone else care?
I used to lecture on computer security, and some of the basic axioms are fundamentally alien to both institutions. Read Cliff Stoll's classic 1989 book "The Cuckoo's Egg", take time out to weep briefly (or laugh uncontrollably, depending on your personality) - then ask yourself how likely it is that things have got better or worse, or stayed the same, in the intervening 37 years. I would guess "much worse" - and that's a very high bar.
Many years ago - decades, actually - I used to cite a story from the 1950s about a top-secret DoD system designed to protect against missile attacks. It was specified with the absolute maximum of everything - processor, memory, peripherals - because performance was hyper-critical. Then, when all that had been specified and actually tested, another department insisted that maximum security be added. Of course performance vanished into a black hole, and there were furious rows. Meanwhile, the staff got kudos for fixing the problem and restoring the expected performance. How? They systematically removed or disabled every single one of the expensive security features.
Today's computers are hopelessly insecure and cannot be made secure. The very processors and RAM chips, the network cards, the wireless systems, the firmware, the underlying libraries - everything is suspect and even if OK today may be subverted tomorrow.
I would bet big money that the Iranians already have a network of fine wires around the Pentagon's testicles - and Wall Street's too - ready to tug at a moment's notice.
It's the perfect deterrent against a nation with thermonuclear deterrent and powerful navy and air force. No need to go there to wreak havoc - just type in a few commands. They might even manage plausible deniability. "How could we have done all that, with our backward technology and complete lack of know-how?"