HackMyIP
← Back to News
2026-08-27 SecurityWeek

Trump Executive Order Blocks Foreign Backdoors in US Power Grid Equipment

Supply ChainRegulationAPT

President Trump issued Executive Order 14420 on Wednesday, declaring a national emergency to address vulnerabilities in the United States' bulk power system stemming from foreign-supplied electrical equipment. The order attributes its elevated threat posture to rapid growth in data centers, AI workloads, advanced manufacturing, and defense production, noting that grid reliability magnifies the consequences of supply chain disruptions or targeted attacks that exploit embedded backdoors for remote access. The directive applies to critical infrastructure operating bulk-power transmission lines rated at 69 kilovolts or higher, explicitly excluding local electricity distribution facilities.

The order targets transformers, inverters, energy storage systems, and industrial control systems (ICS) including remote terminal units (RTUs), programmable logic controllers (PLCs), and safety instrumented systems, along with associated firmware, software, and remote access capabilities. Any acquisition, import, transfer, or installation of foreign-produced bulk-power equipment initiated after August 26, 2026, is prohibited when the transaction involves designated entities whose hardware or software is deemed to pose risks of sabotage, unauthorized access, malicious remote operation, or supply disruption. While the order does not name any country, its structure closely mirrors a 2020 Trump-era bulk-power order that triggered a DOE prohibition explicitly targeting entities linked to China—a measure later revoked under the Biden administration.

For equipment already deployed, the Energy Department can mandate security controls following consultation with defense and intelligence leaders, requiring grid operators to identify, isolate, monitor, secure, disconnect, or replace components to neutralize operational threats while preserving service continuity. Authorities may also negotiate mitigation agreements or publish a list of pre-qualified equipment and vendors exempt from baseline prohibitions. Security teams auditing grid-adjacent infrastructure for hidden remote access paths can use a port scanner to surface exposed management interfaces, while vendor due diligence on connected component suppliers can be sharpened with a WHOIS lookup to verify corporate provenance of firmware distributors.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →