LAS VEGAS — Cyberattacks on operational technology have shifted in recent years from extortion and espionage to destruction, a trend that should alarm those tasked with defending outdated industrial equipment, experts said on Thursday. The panel discussion at the Black Hat USA cybersecurity conference here highlighted the plethora of risks facing U.S. critical infrastructure operators — many of them poorly staffed and funded — at a time of heightened geopolitical conflict. “OT attacks are increasingly moving from targeting not just data but physical operations,” said Cheri Benedict, a cybersecurity and supply chain adviser at the White House’s Office of the Federal Chief Information Officer. “There is a real desire and willingness to cause this impact at scale,” said Matthew Rogers, the operational technology cybersecurity lead at the Cybersecurity and Infrastructure Security Agency (CISA). Security experts have watched with growing concern over the past few weeks as states have reported Iran-linked intrusions into their water systems. But those attacks failed to compromise the safety and quality of Americans’ drinking water. Meanwhile, Iran has also mounted a campaign to disable safety monitoring systems in water and other sectors. Those attacks are “what should actually scare you,” Rogers said. Rogers pointed to an advisory about the Iranian activity that CISA updated on July 22. In it, the agency said that at one organization, Iran-linked threat actors planted malware on a programmable logic controller (PLC) that “overrode specific instruction sets responsible for maintaining safe operating parameters in the victim’s environment.” One of the first known examples of malware disabling safety systems occurred in 2017, when a tool known as Triton switched off safety equipment at a Saudi Arabian power plant. Since then, hackers have developed new ways to stealthily cripple safety monitoring technology. Because infrastructure operators rarely examine PLCs unless they noticeably malfunction, safety-compromising