Jul 30, 2026
ManyPress

Advertisement

Technology

A memo circulated to water utilities links a recent wave of cyberattacks on Minnesota water systems to Iran-affiliated hackers.

ManyPress

ManyPress

ManyPress Editorial

3 min readSource:Wired
Memo Ties Cyberattacks on Minnesota Water Utilities to Iran

Key facts

  • The Minnesota Fusion Center determined the attacks were aligned with a campaign previously linked to Iran-affiliated hackers.
  • More than 30 municipal water and wastewater systems in Minnesota were targeted in the breaches.
  • The city of Braham experienced a brief water plant outage due to the hacking activity.
  • CISA has advised utilities to disconnect PLCs from the internet and use strong passwords to prevent further compromises.
  • Cybersecurity researchers are investigating whether the attacks were carried out by the groups CyberAv3ngers or Handala.

A communication obtained by WIRED and sent to members of the Water Information Sharing and Analysis Center (WaterISAC) identifies Iran as the source of recent cyberattacks on dozens of Minnesota water and wastewater utilities. The memo cites findings from the Minnesota Fusion Center, which determined the attacks align with a hacking campaign previously attributed to Iran-affiliated actors by the US Cybersecurity and Infrastructure Security Agency (CISA).

By the numbers

30
municipal water and wastewater systems targeted in Minnesota
1,700
population of the city of Braham

Scope of the Attacks

Minnesota state officials reported that more than 30 municipal water and wastewater systems were targeted in the breaches. The hackers compromised remotely accessible programmable logic controllers (PLCs), which are used to automate and coordinate industrial infrastructure. In the city of Braham, the intrusion caused a brief water plant outage, though officials have stated that Minnesota's drinking water remains safe.

Attribution and Methodology

While the WaterISAC memo is the first official document to explicitly link the Minnesota attacks to Iran, experts and cybersecurity firms are investigating which specific groups may be responsible. Some reports point to the Iranian hacker group CyberAv3ngers, while others suggest the group Handala could be involved. Both are considered to be Iranian-affiliated actors with a history of targeting industrial control systems.

Federal Guidance and Mitigation

CISA issued an advisory on Thursday warning water entities of all sizes to secure their systems by disconnecting PLCs from the internet, implementing strong passwords, and restricting device access. The agency noted that these attacks have resulted in sustained manual operations and, in some cases, boil-water notices. Facilities affected by the recent wave of incidents have implemented contingency procedures to maintain operations.

Timeline

  1. April
    CISA first described a hacking campaign carried out by Iran-affiliated hackers targeting PLCs.
  2. July 22
    CISA updated its advisory regarding Iranian-linked actors targeting industrial control systems.
  3. Thursday
    A WaterISAC memo and a new CISA advisory were released regarding the Minnesota water utility attacks.

Advertisement

This article was independently rewritten by ManyPress editorial AI from reporting originally published by Wired.

Technology