2 Remove Virus

Cyberattack Disrupts More Than 30 Minnesota Water Systems as Officials Investigate Suspected Iranian Link

A coordinated cyberattack targeting more than 30 public water systems across Minnesota has prompted a large-scale response from state and federal authorities, with investigators examining whether the operation is connected to the Iran-linked hacking group CyberAv3ngers. Officials described the incident as one of the most significant cyber campaigns ever directed at the state’s local water infrastructure.

 

 

The attacks began on 26 July and affected multiple municipalities, including Plymouth, South St. Paul, Maple Plain and Braham. While officials said drinking water remained safe throughout the incident, several utilities experienced operational disruptions after attackers gained unauthorised access to industrial control systems.

In Braham, local officials said a municipal well and part of the city’s water treatment operations were temporarily taken offline after the control system was manipulated remotely. The outage forced residents to briefly limit water consumption while utility workers restored service. According to local officials, electrical power remained available, but the automated controls responsible for managing water distribution stopped functioning until the system was brought back online.

Other affected communities reported losing portions of their automated control and communication capabilities. As a result, plant operators switched to manual procedures to keep water treatment and distribution running while cybersecurity teams assessed the damage and worked to restore normal operations.

Minnesota IT Services (MNIT), which coordinates cybersecurity for state agencies, said it activated its incident response teams immediately after the attacks were detected. The agency is working alongside the Minnesota Department of Public Safety, the FBI and other federal and state partners to investigate the intrusions, help utilities recover and share threat intelligence with potentially affected organisations.

Although officials have not formally attributed the attacks, MNIT said the methods used, the timing of the incidents and the type of infrastructure targeted resemble previous campaigns against US critical infrastructure involving programmable logic controllers (PLCs). CyberAv3ngers, a hacking group widely linked by US authorities to Iran’s Islamic Revolutionary Guard Corps, has previously claimed responsibility for attacks on water and wastewater facilities in the United States and Israel.

The incident comes only days after the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI expanded an earlier advisory warning that Iranian-affiliated actors continue targeting internet-connected operational technology used in critical infrastructure. The updated guidance broadened the list of potentially targeted PLC manufacturers beyond Rockwell Automation to include Schneider Electric, Siemens and additional vendors.

According to CISA, the attackers are not primarily exploiting newly disclosed software vulnerabilities. Instead, they are gaining access through internet-exposed PLCs, weak security configurations and inadequate network segmentation before attempting to manipulate industrial processes and supervisory control systems. Federal agencies have urged organisations operating critical infrastructure to disconnect PLCs from the public internet wherever possible, strengthen authentication controls and closely monitor industrial networks for signs of unauthorised activity as the investigation into the Minnesota attacks continues.