Leaked Memo Links Iran to Minnesota Water Utility Cyberattacks. Dozens of Systems Were Targeted in Escalating Campaign.
A leaked cybersecurity memo circulating within the U.S. water industry has tied a wave of cyberattacks targeting dozens of Minnesota water utilities to Iran, marking one of the most significant attacks on American civilian infrastructure since the United States launched military operations against Iran earlier this year.
According to a report by WIRED, the communication, distributed to members of the Water Information Sharing and Analysis Center (WaterISAC), references an alert from the Minnesota Fusion Center concluding that the ongoing attacks are aligned with a cyber campaign previously attributed by U.S. authorities to Iran-affiliated hackers.
The attacks come amid a broader escalation in cyber activity linked to Tehran following the outbreak of direct hostilities with the United States in late February. Since then, suspected Iranian hackers have been connected to a series of retaliatory operations, including attacks on medical supply company Stryker and the reported compromise of FBI Director Kash Patel’s personal email account.
The WaterISAC memo states that the Minnesota Fusion Center found the recent intrusions were consistent with an earlier campaign described by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) in April.
That advisory warned of Iran-linked hackers targeting programmable logic controllers, or PLCs, industrial computers widely used to automate critical infrastructure, including drinking water and wastewater facilities.
The leaked document represents the first official communication explicitly linking the Minnesota incidents to Iran, although federal authorities have not publicly announced a formal attribution.
Cybersecurity experts say the alleged campaign represents an alarming evolution in Iran’s cyber capabilities. Joe Slowik, a former Los Alamos National Laboratory cybersecurity researcher now working with the U.S. Department of Energy, told WIRED that the attacks demonstrate an unprecedented willingness to interfere directly with civilian infrastructure.
“Now we have documented disruption and even modification of safety and protection parameters in critical infrastructure,” Slowik said. “Seeing this sort of tradecraft expand to Iran, and seeing it across multiple sites, it should really be making people concerned right now.” He also warned there is little reason to believe the campaign will remain confined to Minnesota, noting that similar industrial systems are deployed across the country.
Earlier this week, Minnesota officials confirmed that more than 30 municipal drinking water and wastewater systems had experienced cyber intrusions. In several cases, the hackers disrupted communications between industrial control systems and operational equipment.
The city of Braham, home to roughly 1,700 residents, reportedly experienced a temporary shutdown of its water treatment plant. Officials said there was no evidence of contaminated drinking water or widespread service interruptions.
Minnesota authorities have repeatedly emphasized that the state’s drinking water remains safe, crediting built-in safety mechanisms and emergency procedures for preventing more serious consequences.
South St. Paul officials said contingency plans allowed employees to continue operating water and wastewater services manually after automated controls were affected. An updated CISA advisory issued Thursday warned that the threat actors are targeting water utilities “of all sizes” and urged operators to disconnect internet-accessible PLCs, strengthen password protections, and restrict access to trusted devices.
The advisory also noted that similar attacks have already resulted in boil-water notices and forced utilities to rely on sustained manual operations. Private cybersecurity firms are still debating which Iranian hacking group may be responsible.
Security company Tenable concluded earlier this week that the attacks closely resemble the tactics of CyberAv3ngers, a hacking group linked to Iran’s Islamic Revolutionary Guard Corps. The group has previously targeted industrial control systems used in water infrastructure and has been publicly identified by CISA in earlier advisories involving PLC attacks.
CyberAv3ngers first gained international attention in late 2023 after compromising industrial control devices manufactured by Unitronics, replacing control panel displays with pro-Gaza messages while also altering device code in ways that disrupted water-related operations in Israel, Ireland and the United States.
Since then, U.S. authorities have offered a $10 million reward for information leading to the group’s members, while the Treasury Department sanctioned six Iranian officials allegedly connected to the operation. Despite those measures, cybersecurity researchers say the group’s attacks have continued to expand into energy infrastructure and internet-connected industrial devices.
However, researchers at cybersecurity firm Claroty told WIRED that another Iranian-linked group, Handala, remains a possible suspect. Handala has claimed responsibility for several high-profile cyberattacks this year, including the Stryker breach and the compromise of Kash Patel’s personal email.
Although investigators have not reached a definitive conclusion regarding which group carried out the Minnesota attacks, experts interviewed by WIRED said the available evidence strongly points toward Iranian state-sponsored actors.