Predatory Sparrow: The OT Hack That Melted Steel on Camera

📋 Key Takeaways
  • What happened
  • State-signalling OT attack anatomy
  • Impact and numbers
  • Timeline
  • Why it still matters in 2026
10 min read · 1,817 words
Educational & Ethical Use Only — This article is provided for educational and ethical cybersecurity research purposes only. The techniques described should only be used on systems you own or have explicit permission to test. Always follow responsible disclosure and the laws applicable to you. Mitigations are included so engineers can harden real systems.

June 27, 2022 (published into July’s slot): Predatory Sparrow (Gonjeshke Darande), a hacker group widely understood to operate as an Israeli state-aligned operation, claims and demonstrates a cyberattack on Iran’s Khuzestan Steel Company — one of the country’s three largest steel producers — forcing furnaces offline and halting production at a moment of already-fraught internal instability. The attack’s signature was its theatrical precision: the group announced in advance via tweet, claimed to have deliberately chosen timing and scope to avoid casualties (asserting it let measures be taken so workers could move away from danger), released CCTV-style footage showing molten steel spilling across a factory floor as machinery failed, and framed the operation in explicitly political terms tied to labour conditions and the Iranian state. By early July, Iranian officials confirmed disruption and partially attributed the outage to technical failure spin while semi-official acknowledgment accumulated, and industry reporting placed Khouzestan Steel’s blast-furnace stoppage among the most consequential publicly-observed OT (operational technology) attacks on record. For the industrial-security community, the event joined the past decade’s short list of physical-damage cyber operations — Stuxnet’s centrifuges in 2010, the 2015/2016 Ukraine grid attacks, Triton/Trisis against safety systems in 2017 — and marked a new norm: states attacking civilian industrial infrastructure with high visibility and plausible-deniability-free messaging, turning OT attacks into broadcast diplomacy as much as sabotage.

Quick Answer
The Predatory Sparrow attack on Khuzestan Steel (June 27, 2022, disclosed via their Twitter presence) is a milestone in state-linked offensive cyber operations against industrial control systems (ICS/OT). Who: Predatory Sparrow (“Gonjeshke Darande,” Persian for the group name) — a group whose targeting pattern, messaging style and operation tempo align with Israeli state-aligned strategic signalling; it had previously hit Iranian fuel-station payment systems (October 2021) and railways (2021–2022), always with taunting, politically pointed claims. What: the operation disabled heavy machinery at Khuzestan Steel (one of Iran’s top-3 steel firms, ~4M tonnes/year class),forcing furnaces offline; the group published footage showing cascading molten-steel spillage consistent with a furnace-line failure during the intrusion, and claimed casualty-avoidance intent (saying it acted to let workers be clear of danger, timing and scope chosen accordingly). Iran’s response mix: official downplaying (technical-failure framing early) alongside confirmations of a stoppage; no full forensic disclosure. Why it matters (2026 lens): it normalised three things at once — (1) physical-outcome cyberattacks on civilian industry moved from rare (Stuxnet 2010; Ukraine grid 2015/2016; Triton 2017) to repeatable instruments of coercive signalling; (2) public-message-first attack choreography (pre-announcements, drip-fed footage, political framing) which converts sabotage into broadcast messaging aimed at publics and leaders; and (3) casualty-aware attack design as claimed norm — the group’s stated intent to avoid harm doubles as both escalation management and brand differentiation. For OT defenders, the durable takeaway: assume the attacker’s goals are physical and reputational, not data exfiltration; segment heavy-industry networks for integrity-and-safety first (unidirectional gateways where feasible, controller-level hardening, physical interlocks validated against full-control compromise); and rehearse the “furnace-line-down” response as a joint IT/OT/PR crisis, because the next iteration of this class will be livestreamed too.

What happened

On June 27, 2022, the Predatory Sparrow Twitter account tweeted its claim against Khuzestan Steel Company (KSC) — known in Persian as Khouzestan — with the group’s characteristic mix ofo bravado and messaging discipline: advance notice framing, sympathetic-to-workers rhetoric, and a threat-to-infrastructure payload. Furnace operations stopped; factory-floor footage (widely circulated and consistent with a serious metallurgical-line failure, showing molten steel pouring from a stopped line) became the operation’s visual signature. KSC declared force majeure in the aftermath, and Iranian outlets confirmed an incident while the official line wobbled between cyberattack acknowledgment and “technical failure” spin.

The group’s claimed casualty-conscious conduct — asserting that it had deliberately chosen to warn and to avoid harming workers — matched its 2021 fuel-station operation, where it had similarly claimed calibrated, message-first sabotage. This is attack design as public communication: each element (the choice of target, the timing of announcement, the release of footage, the political framing tied to labour grievances and the Islamic Republic’s leadership) serves the signalling objective as much as the physical disruption. Whatever the precise tradecraft inside the plant (never publicly dissected at the depth of a Stuxnet post-mortem), the outcome demonstrated what a determined adversary with OT access to heavy industry can produce: production stoppage, mechanical damage risk, and a global news cycle choreographed from a phone.

The strategic context amplified the signal. June 2022 — the Iran–Israel shadow war grinding through assassinations, maritime attacks and nuclear-programme sabotage; talks stalled; Iranian domestic unrest simmering. An attack that halts a flagship state-adjacent steel plant and narrates it as pro-worker pressure reads as controlled escalation: painful enough to matter, restrained enough (no reported deaths) to keep below open-conflict thresholds. For the global OT-security community, the event also completed a pattern visible since 2019’s ransomware-driven OT-stop incidents (Norsk Hydro, etc.): industrial compromise now spans the full intent spectrum — criminal monetisation to state signalling — and defenders must build for both.

State-signalling OT attack anatomy

Predatory Sparrow / Khuzestan Steel (2022-06-27):

  TARGET: Khuzestan Steel Co.
    (top-3 Iranian steel producer,
     ~4M tonnes/year class)
    heavy machinery: furnace lines

  ATTACKER: Predatory Sparrow
    (Gonjeshke Darande)
    prior ops: fuel-station payments
      (2021-10), railways (2021-22)
    alignment: widely assessed
      Israeli state-linked (never
      officially confirmed)

  CHOREOGRAPHY (the tell of the class):
    pre/post announcement via Twitter
    pro-worker / anti-regime framing
    casualty-avoidance claims
    footage release (floor cameras:
      molten spill during failure)
    -> sabotage as broadcast messaging

  EFFECT: furnaces offline; production
    halt; force majeure declared;
    no reported worker deaths

  LINEAGE of physical-outcome cyber:
    2010  Stuxnet (centrifuge damage)
    2015/16 Ukraine grid (blackouts)
    2017  Triton/Trisis (safety
          systems targeted)
    2021  Oldsmar water-plant
          intrusion (attempted)
    2022  Khuzestan Steel (this)

  DEFENDER POSTURE FOR THE CLASS:
    integrity-first OT segmentation
    unidirectional gateways where
      feasible
    controller hardening + physical
      interlocks under assumed
      full-control compromise
    joint IT/OT/PR crisis rehearsal
      (the next one is broadcast too)
data-hmmnm-seam="2">

Impact and numbers

Metric Value
Date June 27, 2022 (announced via Twitter)
Target Khuzestan Steel Company — top-3 Iranian steel producer
Attacker Predatory Sparrow (Gonjeshke Darande) — widely assessed Israeli state-aligned
Effect Furnace lines halted; production stoppage; force majeure declared
Casualties None reported (group claimed deliberate avoidance)
Evidence released Factory-floor footage of molten-steel spillage during failure
Prior ops (same actor) Iranian fuel stations (Oct 2021), railway systems (2021–22)
Class lineage Stuxnet 2010 → Ukraine grid 2015/16 → Triton 2017 → Khuzestan 2022
data-hmmnm-seam="3">

Timeline

Date Event
2021-10 Predatory Sparrow disrupts Iranian fuel-station payment systems with similar choreography
2021–2022 Railway-system intrusions and announcements continue the group’s campaign
2022-06-27 Khuzestan Steel furnace lines halted; footage and claims published; force majeure follows
2022-07 Iranian acknowledgment accumulates alongside technical-failure spin; global OT-security analysis
2022+ State-linked OT signalling attacks continue across regional conflicts (public visibility varies)
data-hmmnm-seam="4">

Why it still matters in 2026

Because the merged doctrines it showcased — cyber-enabled physical sabotage plus front-foot messaging — became the template for state cyber operations in the conflicts that followed. The Russia–Ukraine war’s OT-adjacent operations (grid attacks, industrial-control wipe operations, hacktivist-branded front groups on both sides), the Iran–Israel exchange’s continued escalation through 2024–2025 (strikes on infrastructure paired with cyber operations and immediate public framing), and the widening cast of regional actors running “patriotic” brands over state-capable tooling all run the same choreography Predatory Sparrow perfected: strike, tweet, frame, calibrate. For industrial defenders, the 2026 posture follows directly: OT security is no longer a niche compliance exercise but national-resilience infrastructure, and the design assumptions shifted from “prevent intrusion” to “maintain safe physical state under assumed compromise” — safety-instrumented systems isolated or analogically redundant, furnace-line-class processes validated against full adversary control of the office network, and crisis playbooks that include a broadcast dimension, because the attacker’s real target audience is the public narrative. The group’s casualty-awareness claims, whatever their sincerity, also seeded an uncomfortable norms-of-engagement thread now standard in state-cyber discourse: attacking civilian industry is tolerated signalling only while deaths are avoided and messaging frames restraint — a norm under visible strain as operations escalate. Khuzestan Steel remains the cleanest single case study of this entire package: heavy industry, physical outcome, messaging-first execution, and escalation calibrated below the war threshold.

data-hmmnm-seam="5">

Detection and hardening takeaways

  • Design for integrity under assumed compromise. The Khuzestan outcome — furnaces forced offline with physical-damage risk — is the failure mode to engineer against: physical interlocks and safety-instrumented systems that fail safe even with adversarial control of supervisory layers; controller-level hardening (no engineering-workstation reachability from IT); unidirectional gateways for outbound telemetry where the process allows.
  • Treat announcement-choreography as an IOC class. Pre-announcing accounts, pro-worker framing, drip-fed footage — this messaging pattern is now a leading Indicator of state-signalling OT operations. Threat-intel programmes should monitor the actor brands (“hacktivist” fronts with suspicious capability), because the tweet often precedes or accompanies the physical event, buying defenders nothing unless they’re listening on those channels too.
  • Rehearse the joint IT/OT/PR crisis. The next Khuzestan-class event is broadcast in real time; response must be too. Pre-drafted holding statements, coordinated engineering-plus-communications command structure, and rehearsed pre-agreed facts-vs-speculation discipline prevent the “technical failure” spin trap that reads as evasion when footage is already circulating.
  • Segment for the physical process, not the org chart. Heavy-industry networks compartmentalised by process-cell (each furnace line its own zone) cap any single intrusion’s physical reach — the difference between “one line down, contained” and “plant-wide stoppage with cascade spillage.” Zone-and-conduit design per IEC 62443 exists precisely for this class.
  • Watch the warm-up acts. Predatory Sparrow’s fuel-station and railway operations telegraphed capability and intent before the steel attack. Regional-actor campaigns against payment systems, ticketing, and logistics in your geography are rehearsals; treat repeated low-impact political sabotage against national infrastructure as the leading indicator it is, and raise industrial-defence posture accordingly.

FAQ

Who is Predatory Sparrow, really?

A hacker brand with a consistent Persian-language identity, a pro-worker/anti-regime messaging line, and an operation tempo aligned with Israeli strategic signalling — the widespread assessment (which Israel has never officially confirmed, consistent with its deliberate-ambiguity doctrine) treats it as a state-aligned or state-directed operation. The name is Persian; the targets are Iranian critical infrastructure; the messages read like psyops. That ambiguity itself is part of the design.

Did the attack actually cause physical damage?

Production stoppage and furnace-line halt are confirmed by the plant’s own force-majeure declaration and Iranian reporting; the released footage showed molten steel spilling during the failure, consistent with mechanical risk during uncontrolled stops. Whether durable equipment destruction occurred (versus emergency stops with spillage but repairable harm) wasn’t publicly forensically established — Iran never released a full post-mortem, and the group’s claims did the detail work instead.

How does this differ from ransomware OT incidents like Norsk Hydro?

Intent and message. Criminal ransomware on industrial networks (Norsk Hydro 2019, Colonial Pipeline 2021’s IT-side shutdown) monetises or disrupts as a side effect, with no political script and no calibrated restraint. Predatory Sparrow’s operations are signalling first: the target’s propaganda value, the framing, and the casualty-aware claims are the point — physical damage is the medium, not the revenue.

Is “casualty-aware sabotage” actually a norm now?

It’s an asserted norm by practitioners and a strained one by evidence. The claim of worker-safety consciousness serves escalation management (keeping operations below retaliation thresholds) and reputational positioning. As state-cyber operations have escalated through subsequent conflicts, adherence has become selective at best — which is precisely why OT defenders plan for physical-outcome compromise regardless of any attacker’s stated manners.

data-hmmnm-seam="end">

Prabhu Kalyan Samal

Application Security Consultant at TCS. Certifications: CompTIA SecurityX, Burp Suite Certified Practitioner, Azure Security Engineer, Azure AI Engineer, Certified Red Team Operator, eWPTX v3, LPT, CompTIA PenTest+, Professional Cloud Security Engineer, SC-900, SC-200, PSPO I, CEH, Oracle Java SE 8, ISP, Six Sigma Green Belt, DELF, AutoCAD. Writing about ethical hacking, security tutorials, and tech education at Hmmnm.