Iran-linked hackers disrupt Minnesota water utilities in 30+ breaches
A leaked memo obtained by WIRED on July 30, 2026, ties a series of cyberattacks on Minnesota water and wastewater utilities to Iran. The Water Information Sharing and Analysis Center (WaterISAC) document, the first official paper to make that link, says the Minnesota Fusion Center found the attacks aligned with a hacking campaign that the Cybersecurity and Infrastructure Security Agency (CISA) has described as carried out by Iran-affiliated hackers.
More than 30 municipal water and wastewater systems in Minnesota were targeted. Hackers compromised remotely accessible programmable logic controllers (PLCs), with the likely goal of causing a loss of system pressure and potential water contamination, the memo stated. In the city of Braham, the attack caused a brief outage of the water plant. Facilities were able to mitigate further compromise, officials said, and drinking water remained safe.
Joe Slowik, a former cybersecurity researcher at Los Alamos National Labs, called the attacks a rare case of state-sponsored targeting of civilian infrastructure outside Russia’s war in Ukraine. He warned that the documented disruption and modification of safety parameters across multiple sites should cause significant concern, and that other facilities using the same technology remain vulnerable.
Cybersecurity firm Tenable published a report on July 28 suggesting the Iranian group CyberAv3ngers, tied to the Islamic Revolutionary Guard Corps, may be responsible. The New York Times reported on July 30 that officials concluded the attacks were likely carried out by Iranian state-sponsored hackers.
CyberAv3ngers first emerged in late 2023, targeting Unitronics devices used in water facilities, and has since escalated to breaching a U.S. oil and gas company and deploying malware called IOControl.
While the specific group behind the Minnesota attacks remains uncertain—Claroty researcher Yhonatan Harari noted evidence pointing to another Iranian group, Handala—all signs indicate Iranian involvement. A separate CISA advisory, updated on July 22, had warned that Iran-linked actors were targeting PLCs to cause operational disruption, but it did not mention the Minnesota incidents.
On July 30, CISA issued a new advisory stating the attacks led to boil-water notices and sustained manual operations. It urged water utilities to disconnect PLCs from the internet, use strong passwords, and allow-list trusted devices, warning that the threat actors are targeting water entities of all sizes.
Sources
- WiredSecondary
Related
Okta buys Permiso for about $200M to secure AI identities
US probes Iran-linked cyberattack on 30 Minnesota water systems
CareCloud breach affects 345,000 as hackers steal medical records
Chrome pushes twice-weekly security fixes after AI finds 1,072 bugs
OpenAI agent hacked Hugging Face in 17,600 actions over 4.5 days
HAWK post-quantum algorithm withdrawn after Mythos attack halves key
Hackers steal 740,000 records from DfE and police database
Cyera acquires Oasis Security for $1B in third deal this year
Trending now
- US bans import of advanced mobile robots, including humanoids
- Amazon winds down most flagship AI models in strategy overhaul
- Radio telescopes detect space junk in daylight for first time
- Capcom sales hit record highs as Resident Evil Requiem tops 8 million sold
- China starts production of home-grown immersion DUV chipmaking tools
- NASA Swift rescue mission hits attitude control trouble
- Ariane 6 rocket completes first vertical liftoff
- Xbox reveals Gamescom 2026 lineup with Fable, Gears of War: E-Day
Comments
No comments yet. Be the first.