Iranian-Linked Hackers Disrupt Minnesota Water Utilities in Escalating Cyber Campaign
A wave of cyberattacks targeting dozens of Minnesota water and wastewater utilities has been linked to Iranian-affiliated hackers, marking a significant escalation in cyber warfare against U.S. critical infrastructure. This follows a pattern of retaliatory intrusions since late February, with experts expressing deep concern over the expansion of such disruptive tradecraft.
Since late February, the U.S. has seen an increase in retaliatory cyber intrusions attributed to Iranian-backed actors. These attacks have varied in scope, from paralyzing medical supplies company **Stryker** to breaching the personal email of **FBI Director Kash Patel**. Now, an unprecedented wave of disruptive cyberattacks has hit water utilities across Minnesota, with a memo circulated within the water industry directly linking these incidents to Iran.
### Official Confirmation and Escalation
A communication obtained by WIRED and sent to members of the **Water Information Sharing and Analysis Center (WaterISAC)**, an industry group for water utilities, explicitly ties a series of cyberattacks on Minnesota water and wastewater utilities to Iran. The **WaterISAC** note references an alert from the **Minnesota Fusion Center**, a state-level intelligence-sharing entity, confirming ongoing malicious cyber activity impacting public drinking water systems. The **Minnesota Fusion Center** found these attacks to be βalignedβ with a hacking campaign first described in April by the **U.S. Cybersecurity and Infrastructure Security Agency (CISA)** as being carried out by βIran-affiliatedβ hackers.
### A New Front in Cyber Warfare
**Joe Slowik**, a former Los Alamos National Labs cybersecurity researcher, highlights the gravity of this development. He notes that state-sponsored targeting of civilian infrastructure at this scale has rarely been seen outside of Russiaβs war against Ukraine. βNow we have documented disruption and even modification of safety and protection parameters in critical infrastructure,β Slowik stated. βSeeing this sort of tradecraft expand to Iran, and seeing it across multiple sites, it should really be making people concerned right now.β Slowik also warned that these attacks are unlikely to be isolated to Minnesota, as many other sites share the same targeted technology.
### CISA Advisory and Impact
A new **CISA** advisory, released Thursday, warns that βthese threat actors are targeting water entities of all sizes.β It urges utilities to disconnect **PLCs** from the internet, implement strong password protection, and allow-list only trusted devices for connection. Earlier this week, Minnesota state officials revealed that over 30 municipal water and wastewater systems had been targeted, with some incidents disabling telecommunications between industrial control systems and water utility equipment. In **Braham**, a city of 1,700, the hacking reportedly led to a brief outage of the cityβs water plant. While no immediate water shortages or safety threats have been confirmed, the latest **CISA** advisory indicates that attacks have βresulted in boil-water noticesβ and βsustained manual operations,β suggesting fears of contamination.
### Suspects and Modus Operandi
While official confirmation from Iran or a specific Iranian hacker group is pending, **Tenable**, a cybersecurity firm, published a report on Monday suggesting that **CyberAv3ngers**, an Iranian hacker group tied to the **Iranian Revolutionary Guard Corps (IRGC)**, may be responsible. **Tenable** noted that βthe operational pattern is consistent withβ **CyberAv3ngers** or associated groups. Separately, The New York Times reported that U.S. and state officials familiar with the incidents concluded the Minnesota attacks were βlikelyβ carried out by Iranian state-sponsored hackers, though without naming a specific group.
**Tenable**βs report referenced an updated **CISA** advisory from April, warning that Iran-linked actors were targeting **programmable logic controllers (PLCs)** used in critical infrastructure to cause βoperational disruption and financial loss.β This advisory specifically pointed to an βIranian-affiliatedβ hacker group and noted that **CyberAv3ngers** had previously targeted **PLCs** in similar fashion.
### The Threat to PLCs
The **WaterISAC** memo, citing the **Minnesota Fusion Center**, stated that the hackers compromised remotely accessible **PLCs**, with the likely goal of causing βloss of system pressure and potential contamination of the water supply.β Although facilities were able to mitigate further compromise, the full impact is still being assessed. Minnesota officials have affirmed that all drinking water remains safe, and targeted municipalities have emphasized that failsafes protected their systems.
The **CISA** advisory, updated last week and co-issued by the **FBI**, **National Security Agency**, **Cyber Command**, **Environmental Protection Agency**, and the **Department of Energy**, noted that attackers were exfiltrating and manipulating project files governing automated industrial systems. This tampering with **PLCs** can alter information on industrial control system displays, potentially leading to system disruption, damage, or dangerous conditions.
### CyberAv3ngersβ History of Attacks
**CyberAv3ngers** first emerged in late 2023, following the October 7th Hamas attacks and the subsequent war in Gaza. Their initial campaign targeted devices sold by **Unitronics**, an industrial control systems firm commonly used in water and wastewater facilities. These attacks involved rewriting device code, leading to disruptions in water-related services in locations ranging from Israel to Ireland and a U.S. facility in Pittsburgh, Pennsylvania. Despite a $10 million bounty from the U.S. State Department and sanctions against six **IRGC** officials linked to the group, **CyberAv3ngers**β attacks have escalated. According to **Dragos**, the group breached a U.S. oil and gas company in 2024 and launched a widespread campaign infecting industrial control and IoT devices with **IOControl** malware.
While evidence strongly points to Iranian involvement, whether **CyberAv3ngers** is directly behind the Minnesota attacks remains to be definitively confirmed. However, the consistent targeting of **PLCs** and critical infrastructure underscores a growing and severe threat landscape.