Cyber and Critical Infrastructure 28 September 2026

Cyber & Critical Infrastructure: A Homeland-Security Watch Item

Cyber activity this week highlights three distinct but important exposure areas: military personnel data, state government systems, and operational technology. A vulnerability in a Defense Manpower Data Center file-sharing system allowed unauthorized users to access files containing unencrypted personal information, including Social Security numbers and military personnel data, with access reportedly occurring between October 2025 and July 2026. The potential scope remains unclear, and there is currently no public evidence identifying a foreign intelligence service as the perpetrator.

Arizona’s court system separately disclosed a cyberattack in which criminal hackers or automated systems may have copied personally identifiable information belonging to many residents; the Federal Bureau of Investigation (FBI) is investigating and the full scope remains uncertain. At the same time, federal agencies continue to warn that Iranian-affiliated actors are targeting internet-connected programmable logic controllers (PLCs) within U.S. critical infrastructure, with previous incidents affecting water and wastewater operations.

These incidents do not establish a single coordinated campaign. They demonstrate, however, how cyber risk can affect sensitive personnel information, government systems, and physical infrastructure through different pathways. For organizations, key indicators include exposed operational technology, third-party access, credential abuse, unauthorized access to sensitive databases, and movement from information systems toward systems that control physical operations.

SOURCES

Navy Times — Sept. 24, 2026
Military personnel data exposed in breach, agency warns

Arizona Supreme Court — Sept. 25, 2026
Arizona Courts Experience Cyber Attack

KJZZ — Sept. 26, 2026
Cyberattack targets Arizona courts

FBI — July 22, 2026
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers

FBI/EPA — July 30, 2026
Malicious Cyber Actors Targeting Water and Wastewater Sector PLCs

Previous
Previous

The Operating Space: Gray Zone and Low Intensity Conflict

Next
Next

Nefarious North Korean Cyber Activity