Iran-linked hackers targeted more than 30 Minnesota public water systems in a coordinated cyberattack, according to state officials. The incidents disrupted automated operations at several utilities and forced some staff to switch to manual controls.
Minnesota IT Services said the two-day campaign began on July 26. Officials have not formally attributed the attacks, but the activity reportedly shares characteristics with earlier operations linked to the Iran-aligned CyberAv3ngers group.
Water systems forced into manual operation
The attacks affected water utilities across the state, including Plymouth, South St. Paul, Maple Plain and Braham. In at least one municipality, a well and water-treatment plant were temporarily taken offline.
Other affected communities experienced communication problems and disruption to automated control systems. Utility staff used manual workarounds while technicians restored normal operations.
Officials said drinking water remained safe in the targeted municipalities. No city asked residents to alter their water use because of the cyberattack.
Minnesota IT Services activated its incident-response capabilities after detecting the activity. The agency is working with the Minnesota Department of Public Safety, the FBI and other state and federal partners to investigate and support affected communities.
Attackers targeted industrial control systems
The campaign appears to have focused on programmable logic controllers, or PLCs. These devices automate critical processes in water treatment and distribution systems.
A Minnesota IT Services spokesperson said the timing, access methods and targeted infrastructure resembled previous coordinated attacks against US critical infrastructure.
Investigators described the incidents as attacks because they identified unauthorised access with malicious intent. However, authorities have not publicly confirmed the group responsible.
CyberAv3ngers, also known as Shahid Kaveh, is widely associated with Iran’s Islamic Revolutionary Guard Corps. The group has previously targeted US water and wastewater facilities.
CyberAv3ngers has attacked water infrastructure before
In November 2023, CyberAv3ngers targeted Unitronics PLC-controlled equipment at a Pennsylvania municipal water authority. Attackers exploited an internet-exposed device that still used default credentials.
The group claimed it chose the equipment because the software used to operate it was made in Israel. The incident prompted warnings for water and wastewater operators to change default PLC passwords, enable multifactor authentication and remove exposed devices from the public internet.
CyberAv3ngers also claimed attacks against water-treatment sites in Israel that year.
The latest incidents in Minnesota would represent one of the largest known coordinated attacks on local US water infrastructure linked to the group.
CISA expands warning on Iranian PLC threats
The attacks came shortly after the Cybersecurity and Infrastructure Security Agency and the FBI expanded an advisory on Iranian activity targeting internet-connected operational technology.
Water and wastewater systems, government services and energy facilities are among the sectors considered at risk. The warning says Iran-linked actors have broadened their focus beyond Rockwell Automation equipment to include PLCs from Schneider Electric, Siemens and other manufacturers.
Affected Rockwell devices include CompactLogix and Micro850 models. CISA has not yet named the specific Schneider Electric and Siemens products at risk.
The advisory says attackers are not necessarily relying on known CVE vulnerabilities. Instead, they are exploiting exposed PLCs, weak configurations and poor network segmentation.
Utilities urged to remove PLCs from the internet
Iran-linked attackers have been observed attempting to download malicious project files and manipulate data on human-machine interface and SCADA displays. Such activity could disrupt industrial processes and weaken safety functions.
CISA urges critical-infrastructure operators to disconnect PLCs from the public internet immediately. Organisations should also review remote access, change default credentials, enable multifactor authentication and monitor for suspicious activity.
The Iran hackers Minnesota water systems campaign highlights the growing risk to smaller municipal utilities. Even when water quality remains unaffected, an intrusion into operational technology can disrupt essential services and force local teams to manage systems manually.


0 responses to “Iran Hackers Target 30 Minnesota Water Systems in Cyberattack”