Iran Linked to Cyberattacks on Dozens of Minnesota Water Utilities

A memo circulated within the water industry ties Iran to a wave of cyberattacks that struck dozens of municipal water and wastewater systems across Minnesota in July 2026, marking what experts describe as the most disruptive strike by Iranian hackers against the United States since the two countries entered a state of war in late February.

The communication, obtained by WIRED, was issued by the Water Information Sharing and Analysis Center (WaterISAC) and references an alert from the Minnesota Fusion Center citing “ongoing malicious cyber activity impacting public drinking water systems across Minnesota.” The fusion center found the attacks to be “aligned” with a hacking campaign that the US Cybersecurity and Infrastructure Security Agency (CISA) attributed in April to “Iran-affiliated” hackers. Both reports were marked unclassified but “for official use only.”

More than 30 municipal systems were targeted, with attacks in some cases disabling telecommunications between industrial control systems and water utility equipment. In Braham, a city of approximately 1,700 people, the intrusion reportedly caused a brief outage of the city’s water plant. A new CISA advisory released Thursday states the attacks have also resulted in boil-water notices and “sustained manual operations,” though no water shortages or confirmed safety threats to Minnesota’s water supply have been reported.

Cybersecurity firm Tenable has suggested CyberAv3ngers — an Iranian hacker group linked to the Iranian Revolutionary Guard Corps — may be responsible, noting the “operational pattern is consistent with” the group or associated actors. The New York Times separately reported that US and state officials concluded the attacks were “likely” carried out by Iranian state-sponsored hackers.

Joe Slowik, a former Los Alamos National Labs cybersecurity researcher working for the Department of Energy, called the attacks significant. “Now we have documented disruption and even modification of safety and protection parameters in critical infrastructure,” Slowik said, adding that there is “no reason to believe that the attacks would stop” with Minnesota, given that “plenty of other sites have the same targeted technology.”

CISA’s new advisory urges water utilities of all sizes to disconnect programmable logic controllers (PLCs) from the internet, enforce strong password protection, and restrict device access to trusted connections only.

Source: WIRED

This article was generated by AI and cites original sources.
Scroll to Top