Iran takes credit for AT&T outage
AT&T denies breach as thousands of Texans left offline.

Illustration by Cybernews
- APT Iran claimed it disrupted AT&T internet services across four Texas cities.
- AT&T says attempted cable theft caused the outage, not a confirmed cyberattack.
- DownDetector logged nearly 1,700 reports, and over 7,000 Dallas households were affected.
- Cybernews researchers say the hackers may have claimed credit for an existing outage.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Iranians say they knocked out AT&T internet services across Texas. However, the telecom giant says there is no evidence that the outage was caused by a cyberattack.
APT Iran, a threat actor linked to the Islamic Revolutionary Guard Corps (IRGC) and the CyberAv3ngers hacking group, made the statement on Telegram Tuesday, saying it had targeted telecommunications and other critical infrastructure across Texas.
The group took responsibility for disruptions to AT&T internet services in Houston, Dallas, Austin, and San Antonio. It also says to have penetrated an unnamed Texas water utility and disrupted its services.
The attackers’ claims appeared after thousands of Texans had already reported problems with AT&T's services, suggesting that hackers may have just pointed to the outage to show off.
AT&T says the outage was caused by attempted cable theft.
“Our assessment indicates that attempted cable theft led to the outage,” the spokesman said to the Houston Chronicle.
“Internet service across Dallas and surrounding areas is operating normally, and we continue to monitor our network and review relevant information.”
Thousands of Texans hit by outage
The Iranian hacker claims come after a massive outage that affected the state of Texas. DownDetector, which tracks user-reported problems with online services, recorded a surge of nearly 1,700 reports shortly after noon on Monday.
The largest concentration came from Houston, followed by areas including Spring, Dallas, Fort Worth, Cypress, and Austin. Over 7000 households in Dallas were affected.
More than 40% of the reports were related to 5G home internet, while broadband and WiFi problems accounted for another large share.
@ATTHelp @Google Can one of you please explain the problems in the Houston area with very slow internet/no service related to Google applications over AT&T fiber?
undefined Judge Lincoln Goodwin (@JudgeGoodwin) September 6, 2026
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Iranians claim responsibility
The outage came in handy for threat actors, who may have used the spotlight to spread fear. On Tuesday evening, after outage reports had begun to subside, APT Iran said it had disrupted AT&T services as part of a broader campaign against US critical infrastructure.
"We have attacked telecommunications and other critical infrastructure in Texas," the group asserts, adding that it had disrupted AT&T internet services in 4 cities.
The hackers also state to have breached a Texas water utility and disrupted its water services. There have been no public reports confirming a recent cyberattack against a Texas water system matching the group's claim.
🚨 CTI ALERT 🇺🇸🇮🇷 | IRANIAN APT CLAIMS RESPONSIBILITY FOR ALLEGED CAMPAIGN AGAINST TEXAS CRITICAL INFRASTRUCTURE — AT&T, TELECOMMUNICATIONS, AND POTENTIAL WATER SUPPLY SYSTEMS
undefined VECERT Analyzer (@VECERTRadar) September 9, 2026
[STATUS: UNCONFIRMED / TYPE: CRITICAL INFRASTRUCTURE TARGETING · TELECOM DISRUPTION CLAIM · POSSIBLE… pic.twitter.com/ytEwiHNa0w
Attackers posted a short video alongside the statement, showing the words "HACKED_BY_APT_IRAN" and "HACKED_BY_CyberAv3ngers" inserted into a system's program file.
The system name was obscured, though the visible portion appeared to end with "PLC1," a term commonly associated with industrial control environments.
Cybernews researchers remain skeptical of the hacker’s words.
“It looks like a typical Iranian hackers’ hoax where they monitor public outage feeds and claim credit for whatever breaks, to harvest the media cycle,” one of our researchers said.
Iran intensifies threats to US infrastructure
APT IRAN has been increasingly vocal about targeting US critical infrastructure, particularly telecommunications, energy, and water systems.
At the end of August, the group warned that the US would soon see "unexpected and critical events" affecting energy, water, and telecommunications. It has also taken responsibility for attacks against water systems in several US states.
Iranian hacking groups have targeted US infrastructure targets since the US war on Iran began. At the end of March, APT Iran and Handala, which is also affiliated with the IRGC, issued a unified infrastructure threat in conjunction with CyberAv3ngers.
“Previous experience has shown that this warning is testable and incidents have occurred in the past for the water infrastructure of the United States,” APT Iran said in a post on its Telegram channel on March 27th.
In July this year, Iran-linked hackers knocked a UK power plant offline for 4 days. Tehran has since vowed to expand retaliatory cyberattacks against countries allied with the US.
Rob Demain, CEO of e2e-assure, told Cybernews that while the affected plant itself was low-impact, the same vulnerability could exist across hundreds of similar energy assets, and a successful attack on a larger facility could leave schools, hospitals, and government buildings without power for days.
In the same month, Iranian hackers hit 30 Minnesota public water systems in a coordinated cyberattack. At least one municipal well and treatment plant was knocked offline, while other communities shifted to manual workarounds.
Minnesota officials described the 2-day attack as one of the largest attacks on local water infrastructure in the state's history.
In April, the US Cybersecurity and Infrastructure Security Agency (CISA) and the FBI issued an advisory stating that multiple Iran-linked attacks have already led to disruptions in industrial control systems across several US critical infrastructure sectors – causing "operational disruption and financial loss" in some instances.
🚨 Iranian-affiliated cyber actors are targeting internet-connected OT devices, including Rockwell Automation/Allen-Bradley PLCs, across #CriticalInfrastructure sectors. Review our joint #Cybersecurity Advisory for IOCs & mitigations. 👉 https://t.co/DO9mqoXpLF pic.twitter.com/r9NJDSfaRr
undefined CISA Cyber (@CISACyber) April 7, 2026