Iran hackers hit 30 Minnesota public water systems in coordinated cyberattack
The suspected hackers have breached US water infrastucture before – and CISA has just warned their targets are expanding.

Image by Cybernews.
- More than 30 Minnesota community water systems were targeted in a coordinated cyberattack, but officials say drinking water remains safe.
- Security researchers suspect Iran-linked CyberAv3ngers, while authorities continue investigating the attacks.
- CISA last week expanded its PLC advisory to include Siemens and Schneider Electric as Iranian hackers widen their targeting.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
More than 30 Minnesota water systems were targeted in a coordinated cyberattack now blamed on the Iran-linked CyberAv3ngers hacker group – just days after CISA expanded its warning on targeted industrial control systems.
Minnesota officials described the two-day attack – which began on July 26th – as one of the largest attacks on local water infrastructure in the state's history.
Minnesota IT Services (MNIT) – the state's central technology organization – said in a statement posted on its website Tuesday that it immediately activated the state's cybersecurity incident response capabilities.
“As MNIT cybersecurity teams assess the cyber impacts, they are sharing threat intelligence, providing guidance on response efforts and best practices, and helping affected utilities contain, investigate, and remediate damages from the attack,“it said.
Officials also say the drinking water in those targeted municipalities remains safe and no cities have asked residents to change their water usage.
The agency said it now is “working closely” with the Minnesota Department of Public Safety, the FBI, and other state and federal authorities to “support affected communities and strengthen the security of the state’s critical infrastructure.”
CyberAv3ngers has targeted US water systems before
MNIT spokesperson Emily Zimmer told Reuters that “the timing, methods of access, and targeted infrastructure share characteristics with previous coordinated attacks against US critical infrastructure,” also involving PLCs, or Programmable Logic Controllers.
PLC devices are a critical component used to automate industrial control systems (ICS).
Zimmer said the agency used the term "attack" to describe the situation "because investigators identified unauthorized access with malicious intent directed at these systems," Reuters reported.
And although MNIT has not formally attributed the attacks to the CyberAvengers – a well-known hacktivist collective with ties to the Islamic Revolutionary Guard Corps (IRGC) – the group has successfully breached other US water and wastewater facilities in the past, just never on this scale.
In fact, the US Department of State’s Rewards for Justice program put up a $10 million bounty in 2024, asking for any information leading to the arrest of Iranian military officials linked to the group's operations.
In November 2023, the CyberAv3ngers targeted Unitronics PLC-controlled equipment at a Pennsylvania municipal water authority after exploiting an internet-exposed device with default credentials.
Also known as Shahid Kaveh, the group claimed to have exploited the Unitronics PLC model V570 series specifically because the software used to run the device was made in Israel – defacing the system to state their agenda.
“You’ve been Hacked. Down with Israel. Every Equipment "Made In Israel " Is CyberAv3ngers Legal Target!”the gang's message read.
The nation-state APT claimed attacks on at least ten water treatment stations in Israel that same year.
In response to the attack, all WWS facilities were urged to change the Unitronics PLC default password, incorporate multi-factor authentication, and either disconnect the PLC from the open internet or stop using the default TCP port.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
CISA recently expanded Iranian PLC warning
The attacks come less than a week after the US Cybersecurity and Infrastructure Security Agency (CISA) and the FBI expanded an April advisory warning that Iran-affiliated hackers continue targeting “internet-connected operational technology (OT) devices” across US critical infrastructure.
Sectors at high risk include government and energy services and facilities, as well as water and wastewater systems.
The advisory warns that attackers are attempting to manipulate industrial processes and degrade safety functions, increasing the potential for real-world operational impacts and financial loss if internet-connected control systems remain exposed.
The report further warns that attackers have expanded the list of targeted PLC manufacturers beyond Rockwell Automation to include the following:
- Rockwell Automation / Allen-Bradley
- Schneider Electric
- Siemens
- Other manufacturers (unnamed)
Rockwell models at risk include CompactLogix and Micro850, while the specific PLC models for Schneider Electric and Siemens were listed as “To Be Determined.”
What’s more, the PLCs are not being exploited via “CVE-bound vulnerabilities,” according to a summary by Enigma Global.
Instead, the attackers are relying on unsecured PLCs, taking advantage of software misconfigurations, and “insufficient network segmentation and hardening controls.”
CISA states, “The Iranian-affiliated activity has been observed “attempting to download malicious project files and manipulate data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays.”
Critical defenders are being warned to immediately “disconnect PLCs from the internet and watch for suspicious activity.”
Check if your data has been leaked