Thu 06 Aug 2026 / 10:29 ET
Kernel
Internet 3 min read

Minnesota water cyberattack Iran link appears in industry memo

A WaterISAC memo says Minnesota water utility hacks align with Iran-linked activity, while officials say drinking water remains safe.

Riley Okafor

By Riley Okafor / Senior AI Reporter

Minnesota water cyberattack Iran link appears in industry memo
img: WIRED

A Minnesota water cyberattack Iran link is now spelled out in a water-sector memo obtained by WIRED: WaterISAC told members that the Minnesota Fusion Center found the intrusions against public drinking water systems were aligned with an earlier campaign attributed by CISA to Iran-affiliated hackers.

The Water Information Sharing and Analysis Center, an industry group that shares security alerts with water utilities, circulated the note after more than 30 Minnesota municipal water and wastewater systems were targeted, according to state officials cited by StateScoop. The WaterISAC and Minnesota Fusion Center documents were marked unclassified but for official use only, according to WIRED.

The attribution still has caveats. No Iranian hacker group has publicly claimed the Minnesota incidents, and U.S. officials have not publicly named a specific group as responsible. The New York Times reported Thursday that U.S. and state officials and others familiar with the attacks believe Iranian state-sponsored hackers were likely behind them.

Was Iran behind the Minnesota water cyberattack?

The WaterISAC memo says the Minnesota Fusion Center connected the attacks to malicious activity that CISA first described in April as the work of Iran-affiliated hackers. Cybersecurity firm Tenable said Monday that the pattern resembled activity by CyberAv3ngers, a group tied to Iran’s Islamic Revolutionary Guard Corps, though Tenable framed that as an assessment rather than proof.

Claroty researcher Yhonatan Harari told WIRED that his company had seen signs that another Iran-linked group, Handala, may have carried out the attacks. Handala previously claimed responsibility for attacks including the March disruption at medical supplies company Stryker and the breach of FBI director Kash Patel’s personal email, according to WIRED. Harari said Claroty could not yet say whether CyberAv3ngers or Handala was responsible, but assessed a high likelihood that Iranian actors were involved.

The technical target was familiar and depressingly avoidable: remotely reachable programmable logic controllers, or PLCs. A PLC is a rugged computer that runs industrial equipment, such as pumps, valves and other machinery inside water plants. Put it on the open internet with weak access controls, and congratulations, you have given a foreign intelligence-linked crew a control panel.

According to the WaterISAC memo, the attackers compromised exposed PLCs with the likely intended effect of reducing system pressure and creating possible contamination risk. The memo said affected facilities contained further compromise, while the full impact was still being assessed.

CISA issued a related advisory Thursday warning that the actors are targeting water entities of all sizes. The agency urged utilities to remove PLCs from direct internet exposure, use strong passwords, and allow only trusted devices to connect.

Minnesota officials have said drinking water remains safe. South St. Paul said in a public statement that the incident affected some automated controls, but contingency procedures let public works staff keep water and wastewater operations running normally.

The disruptions were not purely theoretical. In Braham, a city of about 1,700 people, the attack reportedly caused a brief outage at the water plant, though there has been no reported evidence of water shortages or unsafe drinking water. CISA’s advisory said the broader activity has resulted in boil-water notices and prolonged manual operations.

CISA’s earlier advisory, updated last week, said Iran-linked actors had been exfiltrating and manipulating project files used by automated industrial systems. The alert, issued with agencies including the FBI, NSA, Cyber Command, EPA and Department of Energy, said similar activity had caused operational disruption and financial loss in a few cases.

CyberAv3ngers first drew broad notice in late 2023 by targeting Unitronics industrial control devices used in water and wastewater facilities. Dragos and Claroty previously told WIRED that those incidents went beyond screen vandalism because the attackers rewrote device code, disrupting water-related services in Israel, Ireland and a facility in Pittsburgh.

This story draws on original reporting from WIRED.

More Internet/

view all ↗