Cyber attacker targets refrigeration plant
5th August 2026
ISRAEL: Iran has been blamed for a cyber attack on the refrigeration system of an Israeli food processor which reprogrammed the controllers and destroyed the compressors.
According to a cyber security firm Profero, an Iranian state-directed persona, Cyber Isnaad Front, deployed remote access software, disguised as a Microsoft update, on the unnamed company’s networks.
Refrigeration engineers were called to the food production plant in May when the temperatures were seen to be rising in the cold rooms and freezers.
Expecting a mechanical failure, the engineers found that the controllers that run the plant’s industrial refrigeration plant had been reprogrammed. Both the setpoints and safety limits were wrong, and the motorised valves had been switched to manual and pinned open. The log-in credentials on the central controller had also been changed, locking them out.
The plant ran two industrial refrigeration systems, an older array and a newer one, both using CO2 refrigerant. On the older system, the attacker only changed parameters – setpoints, protection thresholds, alarm and alert limits. The fix was straightforward and the engineers restored the old system the same night.
On the newer system, the attacker went much deeper. Beyond setpoints, they wiped and reset the controller’s entire configuration – the digital and analog inputs mapped to temperature sensors and pressure transmitters, the digital outputs that start compressors, the analogue outputs that drive motorised valves and fans and the fault inputs.
Recovery was not a simple reset and took days to rectify. The controller had to be re-engineered from scratch, tracing every wire in the electrical panel against the electrical schematic, identifying it in the programme, and redefining it in the controller.
Then the attacker did the thing that turned a configuration change into physical destruction. The motorised valves that hold gas pressure in the gas cooler and receiver were switched to manual mode and pinned permanently open. As a result, the system’s relief valves opened and vented the CO2 to the atmosphere and three compressors were destroyed.
No malware ran on the controllers. All the attacker needed was setpoints, valve modes, and an understanding of thermodynamics. The destruction was said to have been carried out in the native language of the equipment, and the lockout, changing the central controller’s credentials, was designed to make sure the only people who could undo it could not get in while it happened.
Further information on the attack can be found here.






