Leaked Memo Links Iran to Massive Cyberattacks on Minnesota Water FacilitiesSecurity
31 Jul 2026, 11:46 am (4 days ago)· 0

Leaked Memo Links Iran to Massive Cyberattacks on Minnesota Water Facilities

Confidential intelligence documents confirm that Iranian state-backed hackers targeted over 30 municipal water and wastewater utilities in Minnesota, compromising control systems and raising infrastructure security alarms.

A critical investigation into recent cyber intrusions affecting municipal public drinking water and wastewater systems across Minnesota has directly implicated Iranian state-sponsored hackers. According to a confidential internal note circulated by the Water Information Sharing and Analysis Center (WaterISAC), an industry organization dedicated to cybersecurity threat sharing among water utilities, intelligence collected by the Minnesota Fusion Center confirms that a wave of malicious activity targeting local water facilities aligns with a broader hacking campaign originally flagged by the US Cybersecurity and Infrastructure Security Agency (CISA) as being orchestrated by actors affiliated with Iran. Although marked for official use only, the unclassified intelligence assessments underscore an alarming escalation in foreign state threats directed at essential civilian infrastructure within the United States.

Dangerous Expansion into Civilian Infrastructure Sabotage

The confirmed involvement of Iranian threat actors in targeting water infrastructure marks a severe shift in state-sponsored cyber warfare, drawing parallels to tactics previously observed during Russia's conflict in Ukraine. Cybersecurity expert Joe Slowik, a former researcher at Los Alamos National Labs currently contracting for the Department of Energy, highlighted that the documented tampering with safety parameters and operational control systems represents an intolerable escalation. According to Slowik, observing this level of aggressive tradecraft expand to Iranian cyber units across multiple geographic locations should provoke deep concern among global critical infrastructure operators.

Also read

Furthermore, analysts warn that the vulnerabilities exploited in Minnesota are far from isolated. Slowik emphasized that thousands of industrial sites across North America and beyond utilize identical control technologies. Because the adversary has already demonstrated both the technical capability and the explicit willingness to disrupt critical municipal operations, additional public utility targets remain vulnerable to similar hostile incursions unless rigorous defensive measures are implemented immediately.

Operational Disruptions Across Minnesota Municipalities

State officials in Minnesota revealed earlier this week that more than 30 municipal water and wastewater facilities were targeted during the cyber campaign. In several instances, the intrusions succeeded in disabling telecommunications channels connecting industrial control system technologies with physical plant equipment. In the city of Braham, a community of approximately 1,700 residents, the breach resulted in a temporary shutdown of the municipal water treatment plant. While state health authorities emphasize that the safety of Minnesota's public drinking water supply remains intact due to automated contingency procedures, CISA advisories confirm that the attacks triggered boil-water notices in certain jurisdictions and forced plant technicians to transition to sustained manual operations.

Municipal leaders in affected communities, including South St. Paul, issued statements clarifying that backup safety mechanisms successfully mitigated severe system compromise. Public works officials in South St. Paul noted that despite automated control disruptions, established emergency protocols allowed personnel to maintain normal water and wastewater operations without compromising consumer safety.

CISA Directives and Technical Security Mandates

In response to the breaches, CISA issued an updated emergency advisory warning that hostile threat actors are actively targeting water entities regardless of their operational size. Federal authorities instructed water utility operators to immediately isolate Programmable Logic Controllers (PLCs) from direct internet exposure, enforce multi-factor authentication with robust password policies, and implement strict allow-listing protocols to ensure only verified devices can establish connections with control hardware.

The joint warning, published in coordination with the FBI, the National Security Agency (NSA), US Cyber Command, the Environmental Protection Agency (EPA), and the Department of Energy, highlighted that attackers were actively exfiltrating and manipulating project files governing automated industrial processes. Altering display parameters or internal control logic within PLCs can induce dangerous physical operating conditions, lead to equipment destruction, and result in severe financial and operational losses.

Attributing the Attacks to Iranian Hacker Collectives

Although the Iranian government has not issued official statements regarding the incidents, intelligence analysis points heavily toward Tehran. A technical assessment released by cybersecurity firm Tenable indicates that the operational tactics match the signature methodology of CyberAv3ngers, a prolific hacker collective linked directly to the Islamic Revolutionary Guard Corps (IRGC). Updated advisory notices from CISA reinforce that Iranian-affiliated operators have specifically targeted PLCs used in critical automation to induce operational chaos.

However, investigators are also evaluating potential involvement from other specialized Iranian units. Yhonatan Harari, a lead researcher at cybersecurity firm Claroty, noted that evidence suggests the involvement of Handala, another notorious Iranian hacker faction previously responsible for high-profile breaches including the Stryker cyberattack and the compromise of Kash Patel's email account in March. Despite slight uncertainties regarding specific group attribution, cybersecurity analysts maintain high confidence that the overarching campaign was directed by Iranian state operatives.

CyberAv3ngers History and Global Escalation

CyberAv3ngers initially gained international notoriety in late 2023 following the October 7 Hamas attacks and the subsequent conflict in Gaza. During that initial campaign, the group targeted industrial control devices manufactured by Unitronics, a firm whose hardware is widely deployed across water utilities. The hackers defaced equipment displays with political messages and graphics. Subsequent investigations by Dragos and Claroty revealed that the actors had rewritten internal firmware code, causing physical service disruptions across utilities in Israel, Ireland, and a municipal facility in Pittsburgh, Pennsylvania.

Despite the US Department of State offering a $10 million reward for information leading to the group's neutralization and the US Department of the Treasury sanctioning six senior IRGC officials, CyberAv3ngers escalated its operations throughout 2024. According to research from Dragos, the group successfully breached a US oil and gas facility and deployed a sophisticated malware strain known as IOControl across industrial control systems and Internet of Things (IoT) devices. Cybersecurity researchers stress that the group possesses both the intent and refined technical tradecraft required to sabotage critical public infrastructure.

Questions & Answers

Who has been implicated in the cyberattacks on Minnesota's water systems?
Official memos and intelligence reports link the attacks to Iranian state-sponsored hacker groups, primarily CyberAv3ngers and Handala.
Is the drinking water in Minnesota currently safe?
State officials confirmed that drinking water remains safe due to contingency failsafes, though some areas issued temporary boil-water advisories.
What specific equipment did the hackers target?
The hackers compromised remotely accessible Programmable Logic Controllers (PLCs) that manage automation and hardware coordination in water plants.
What defensive measures did CISA recommend for water facilities?
CISA advised operators to disconnect PLCs from the internet, secure access with strong passwords, and allow-list only trusted network devices.

Comments 0

No comments yet — be the first.

Citizen journalism

Become a TrendKia journalist

Voice of the people

Share news, photos and videos from your area with TrendKia and let your voice reach the nation. Every citizen a journalist.

Join now
CH 01 LIVE
TrendKia TV ON AIR