In this article
- The short version
- What Stuxnet was
- How it got into a plant with no internet
- What it did to the centrifuges
- Who was behind it?
- A reported inside helper (unconfirmed)
- What this means for you
- Sources
The short version
- Stuxnet was found in June 2010. It targeted industrial control software and was aimed at centrifuges at Iran's Natanz plant.
- It was designed to spread on USB drives, which let it reach computers that were not connected to the internet.
- Neither the United States nor Israel has officially admitted building it. Media reports say both were involved, and that is reported, not officially confirmed.
- The lesson for ordinary people is simple: a USB drive can carry malware into places the internet cannot reach.
What Stuxnet was
Stuxnet was a computer worm aimed at Siemens industrial control software and the controllers it programs. Researchers at the security company Symantec reported that it only acted on specific equipment running at specific speeds, which suggests it was built for one particular target rather than for general damage. Symantec also reported that about 60% of the infected computers it found were in Iran.
It used several previously unknown Windows flaws, including one that could run code just by showing a shortcut icon in a folder. That is a large part of why it is still studied today.
How it got into a plant with no internet
Sensitive industrial sites are often “air-gapped”, meaning their control computers are kept off the internet on purpose. Stuxnet was built around that. Symantec's analysis found that industrial systems are often programmed from standalone Windows computers, and that staff move files between systems on removable drives. Stuxnet copied itself onto any USB drive that was plugged in.
Symantec also reported that Stuxnet was first aimed at five Iranian organisations, hit between June 2009 and May 2010, before it reached the plant. Those organisations were not named. Its report suggests they were chosen because their business ties to the plant gave the worm a route in. Symantec traced about 12,000 infections back to those five organisations.
What it did to the centrifuges
Stuxnet is reported to have targeted specific motor-speed controllers connected to the centrifuges, and to have damaged them. The commonly quoted damage figures are reported estimates, not verified facts:
- The Institute for Science and International Security estimated in December 2010 that up to about 1,000 centrifuges, around 10%, were destroyed between November 2009 and late January 2010.
- Iran's president at the time, Mahmoud Ahmadinejad, said on November 29, 2010 that a computer virus had caused problems for “a limited number” of centrifuges.
- Later analysis concluded the damage was not total, and Iran replaced the damaged equipment.
Who was behind it?
Nobody has officially taken responsibility. What is on the record:
- The New York Times reported on June 1, 2012 that Stuxnet was part of a joint US and Israeli operation. That is a media report. Neither government has confirmed it.
- Kaspersky, another security company, concluded that an attack this advanced needed the backing of a nation state.
- The United Kingdom has denied any involvement.
- Iranian officials have said the United States and Israel were responsible. That claim has not been independently verified.
We have left out unproven theories from this page.
A reported inside helper (unconfirmed)
In September 2019 Yahoo News, as reported by Dark Reading on September 3, 2019, said an Iranian engineer recruited by Dutch intelligence helped get Stuxnet into the Natanz plant, either by carrying it in on a USB drive or by infecting another engineer's computer. The report relies on unnamed sources. No government has confirmed it, so treat it as an unverified claim.
What this means for you
You are not running a nuclear plant, but the same trick works on ordinary people. A USB drive can carry malware onto your laptop, your office computer or your family PC without any internet connection at all. The habits below are cheap and effective.
- Never plug in a USB drive you found, or one handed to you by a stranger. A “lost” drive left where you will find it is a classic trap.
- Turn off AutoPlay. In Windows, open Settings, search for “AutoPlay” and set it to take no action. That stops a drive from launching anything by itself.
- Keep your computer and apps updated. Stuxnet-style tricks rely on flaws that updates close.
- Use your own charger and cable in public. If you must use a public charging point, a small USB “data blocker” lets power through but blocks data.
- Share files another way. Cloud links and email attachments you trust are safer than passing a drive around.
- At work, hand found drives to IT. Do not “just check what is on it”.
Sources
- Wikipedia: Stuxnet (summarises Symantec, Kaspersky, ISIS and New York Times reporting)page checked October 9, 2026
- NBC News: Stuxnet malware hit five sites before target (Symantec findings)publication date not shown on the page
- Dark Reading: Report says an Iranian ‘mole’ carried Stuxnet to the nuclear facilitySeptember 3, 2019
Published October 9, 2026. We only include facts we could confirm in the sources above, and we say clearly where something is reported but not confirmed.
Frequently asked questions
What was Stuxnet?
A computer worm discovered in June 2010 that was built to damage industrial equipment, reportedly centrifuges at Iran's Natanz uranium enrichment plant. It is the best-known example of malware used as a weapon.
Did Stuxnet really spread by USB?
Yes. Symantec's analysis found it copied itself onto removable drives, which is how it could reach computers that were not connected to the internet.
Who built Stuxnet?
It has not been officially confirmed. The New York Times reported in 2012 that the United States and Israel were behind it. Neither government has confirmed that.
Can a USB drive still infect my computer today?
Yes. Modern systems are better protected, but a malicious USB drive can still cause harm, especially if your computer is out of date. Do not plug in drives you do not trust.