Since the US launched its war against Iran in late February, Iranian hackers have retaliated with intrusions ranging from paralyzing medical supplies company Stryker to breaching the personal email of FBI Director Kash Patel. Now, a leaked memo ties the widest and most disruptive strike yet—a series of cyberattacks on Minnesota water utilities—to Iran, according to a report by WIRED.
The Leaked Memo and Attribution
A communication obtained by WIRED on Thursday, sent to members of the Water Information Sharing and Analysis Center (WaterISAC), an industry group for water utilities, links to Iran the cyberattacks that hit dozens of Minnesota water and wastewater utilities. The memo states that the Minnesota Fusion Center, a state-level intelligence-sharing entity, issued an alert regarding ongoing malicious cyber activity impacting public drinking water systems across Minnesota. The fusion center found those attacks were "aligned" with a hacking campaign first described in April by the US Cybersecurity and Infrastructure Security Agency (CISA) as having been carried out by "Iran-affiliated" hackers. Both reports were marked as unclassified but "for official use only."
Impact on Minnesota Water Utilities
Earlier this week, Minnesota state officials revealed that more than 30 municipal water and wastewater systems had been targeted. In some cases, hackers disabled telecommunications between industrial control systems and water utility equipment. In the city of Braham, population 1,700, the hacking reportedly led to a brief outage of the city's water plant. The latest CISA advisory, released Thursday, notes the attacks have resulted in "boil-water notices"—indicating fears of water contamination—and "sustained manual operations." There is not yet evidence of resulting water shortages or a threat to the safety of Minnesota's water supply.
Expert Analysis and Wider Concerns
Joe Slowik, a former Los Alamos National Labs cybersecurity researcher working on contract for the Department of Energy, described the confirmation of Iran's responsibility as representing a kind of state-sponsored targeting of civilian infrastructure rarely seen outside of Russia's war against Ukraine. "Now we have documented disruption and even modification of safety and protection parameters in critical infrastructure," Slowik said. "Seeing this sort of tradecraft expand to Iran, and seeing it across multiple sites, it should really be making people concerned right now." He added that there is no reason to believe the attacks will stop with Minnesota, noting that plenty of other sites have the same targeted technology and an adversary willing to execute further strikes.
CISA Advisory and Mitigation Steps
A new CISA advisory released Thursday warns that "these threat actors are targeting water entities of all sizes." It recommends utilities disconnect programmable logic controllers (PLCs) from the internet, password-protect access with strong passwords, and allow-list only trusted devices to connect to them.
Suspected Hacker Group
Separately, cybersecurity firm Tenable reported Monday that signs suggest CyberAv3ngers, an Iranian hacker group tied to the Iranian Revolutionary Guard Corps, may be responsible. Tenable noted that the operational pattern is consistent with that group or associated groups. The New York Times also reported Thursday on the attacks.
Implications for Critical Infrastructure Security
For technology executives overseeing critical infrastructure, this incident underscores the urgent need to isolate industrial control systems from direct internet exposure, enforce multi-factor authentication, and participate in threat-sharing groups like WaterISAC. The attacks demonstrate that state-sponsored hacking groups are actively targeting civilian infrastructure with disruptive intent, a trend that will likely continue as geopolitical tensions escalate.