Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-28 ยท updated: 2026-08-28 ยท tags: [cyber, incident] ยท confidence: high ยท severity: high ยท affected_sectors: [energy] ยท au_impact: true

White House Bans Foreign-Made Bulk-Power Equipment Over Cyber Backdoor Fears

Summary

On 27-28 August 2026 the White House issued an executive order declaring a national emergency to secure the US bulk-power system and banning the acquisition or installation of foreign-made technology used to manage power. The order is grounded in the assessment that certain foreign actors are "increasingly creating and exploiting vulnerabilities" in such equipment, potentially via digital backdoors enabling them to remotely access, control or disrupt power generation.

What the order covers

The sweeping order covers equipment for transmission lines rated at 69,000 volts or higher, substations, control rooms, power generating stations and nuclear reactors, together with the associated software and firmware. The Department of Defence, Commerce and Energy are required to review transactions, and agencies have 120 days to publish rules identifying countries warranting added scrutiny. A list of pre-qualified equipment and approved vendors will be published to give industry a path forward.

Context

The order lands two days after the FBI dismantled the QScan/QTRouter Chinese proxy network (26 August) and amid a wave of attacks attributed to Iran against US water systems and UK power plants. The administration appears to be moving from incident response to hardware-source controls, reframing supply-chain risk in the energy sector from a purely technical issue into an executive-level national-security posture.

AU/NZ relevance

The New Zealand order matters for Australia and NZ because the electricity sectors there run largely on the same imported transmission and substation equipment flagged as at risk of foreign backdoor access. Operators aligned with the NZISM and the Australian framework of critical-infrastructure protection, and defenders using the National Cyber Security Centre's critical-infrastructure frameworks, should read the US action as confirmation of a threat vector that Australia and NZ infrastructure shares. The move is a strong signal for Australian and New Zealand electricity utilities to re-examine firmware provenance and remote-access capabilities on bulk-power equipment.