A critical investigation into recent cyber intrusions affecting municipal public drinking water and wastewater systems across Minnesota has directly implicated Iranian state-sponsored hackers. According to a confidential internal note circulated by the Water Information Sharing and Analysis Center (WaterISAC), an industry organization dedicated to cybersecurity threat sharing among water utilities, intelligence collected by the Minnesota Fusion Center confirms that a wave of malicious activity targeting local water facilities aligns with a broader hacking campaign originally flagged by the US Cybersecurity and Infrastructure Security Agency (CISA) as being orchestrated by actors affiliated with Iran. Although marked for official use only, the unclassified intelligence assessments underscore an alarming escalation in foreign state threats directed at essential civilian infrastructure within the United States.
Dangerous Expansion into Civilian Infrastructure Sabotage
The confirmed involvement of Iranian threat actors in targeting water infrastructure marks a severe shift in state-sponsored cyber warfare, drawing parallels to tactics previously observed during Russia's conflict in Ukraine. Cybersecurity expert Joe Slowik, a former researcher at Los Alamos National Labs currently contracting for the Department of Energy, highlighted that the documented tampering with safety parameters and operational control systems represents an intolerable escalation. According to Slowik, observing this level of aggressive tradecraft expand to Iranian cyber units across multiple geographic locations should provoke deep concern among global critical infrastructure operators.
Furthermore, analysts warn that the vulnerabilities exploited in Minnesota are far from isolated. Slowik emphasized that thousands of industrial sites across North America and beyond utilize identical control technologies. Because the adversary has already demonstrated both the technical capability and the explicit willingness to disrupt critical municipal operations, additional public utility targets remain vulnerable to similar hostile incursions unless rigorous defensive measures are implemented immediately.
Operational Disruptions Across Minnesota Municipalities
State officials in Minnesota revealed earlier this week that more than 30 municipal water and wastewater facilities were targeted during the cyber campaign. In several instances, the intrusions succeeded in disabling telecommunications channels connecting industrial control system technologies with physical plant equipment. In the city of Braham, a community of approximately 1,700 residents, the breach resulted in a temporary shutdown of the municipal water treatment plant. While state health authorities emphasize that the safety of Minnesota's public drinking water supply remains intact due to automated contingency procedures, CISA advisories confirm that the attacks triggered boil-water notices in certain jurisdictions and forced plant technicians to transition to sustained manual operations.
Municipal leaders in affected communities, including South St. Paul, issued statements clarifying that backup safety mechanisms successfully mitigated severe system compromise. Public works officials in South St. Paul noted that despite automated control disruptions, established emergency protocols allowed personnel to maintain normal water and wastewater operations without compromising consumer safety.
CISA Directives and Technical Security Mandates
In response to the breaches, CISA issued an updated emergency advisory warning that hostile threat actors are actively targeting water entities regardless of their operational size. Federal authorities instructed water utility operators to immediately isolate Programmable Logic Controllers (PLCs) from direct internet exposure, enforce multi-factor authentication with robust password policies, and implement strict allow-listing protocols to ensure only verified devices can establish connections with control hardware.
The joint warning, published in coordination with the FBI, the National Security Agency (NSA), US Cyber Command, the Environmental Protection Agency (EPA), and the Department of Energy, highlighted that attackers were actively exfiltrating and manipulating project files governing automated industrial processes. Altering display parameters or internal control logic within PLCs can induce dangerous physical operating conditions, lead to equipment destruction, and result in severe financial and operational losses.
Attributing the Attacks to Iranian Hacker Collectives
Although the Iranian government has not issued official statements regarding the incidents, intelligence analysis points heavily toward Tehran. A technical assessment released by cybersecurity firm Tenable indicates that the operational tactics match the signature methodology of CyberAv3ngers, a prolific hacker collective linked directly to the Islamic Revolutionary Guard Corps (IRGC). Updated advisory notices from CISA reinforce that Iranian-affiliated operators have specifically targeted PLCs used in critical automation to induce operational chaos.
However, investigators are also evaluating potential involvement from other specialized Iranian units. Yhonatan Harari, a lead researcher at cybersecurity firm Claroty, noted that evidence suggests the involvement of Handala, another notorious Iranian hacker faction previously responsible for high-profile breaches including the Stryker cyberattack and the compromise of Kash Patel's email account in March. Despite slight uncertainties regarding specific group attribution, cybersecurity analysts maintain high confidence that the overarching campaign was directed by Iranian state operatives.
CyberAv3ngers History and Global Escalation
CyberAv3ngers initially gained international notoriety in late 2023 following the October 7 Hamas attacks and the subsequent conflict in Gaza. During that initial campaign, the group targeted industrial control devices manufactured by Unitronics, a firm whose hardware is widely deployed across water utilities. The hackers defaced equipment displays with political messages and graphics. Subsequent investigations by Dragos and Claroty revealed that the actors had rewritten internal firmware code, causing physical service disruptions across utilities in Israel, Ireland, and a municipal facility in Pittsburgh, Pennsylvania.
Despite the US Department of State offering a $10 million reward for information leading to the group's neutralization and the US Department of the Treasury sanctioning six senior IRGC officials, CyberAv3ngers escalated its operations throughout 2024. According to research from Dragos, the group successfully breached a US oil and gas facility and deployed a sophisticated malware strain known as IOControl across industrial control systems and Internet of Things (IoT) devices. Cybersecurity researchers stress that the group possesses both the intent and refined technical tradecraft required to sabotage critical public infrastructure.



















