Iran hackers hit 30 Minnesota public water systems in coordinated cyberattack
The suspected hackers have breached US water infrastucture before – and CISA has just warned their targets are expanding.

Image by Cybernews.
- Iran-linked hackers targeted more than 30 Minnesota public water systems in a coordinated weekend cyberattack.
- At least one municipal well and treatment plant were knocked offline, while other communities shifted to manual workarounds.
- Iran's nation-state hacking group CyberAv3ngers is suspected to be behind the attack.
- The attacks came as CISA expanded its warning about Iranian hackers targeting additional PLC devices used in critical infrastructure.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
More than 30 Minnesota water systems were hit in a coordinated weekend cyberattack now blamed on the Iran-linked CyberAv3ngers hacker group – just days after CISA expanded its warning on targeted industrial control systems.
Minnesota officials described the two-day attack – which began on July 26th – as one of the largest attacks on local water infrastructure in the state's history.
Minnesota IT Services (MNIT) – the state's central technology organization – said in a statement posted on its website Tuesday that it immediately activated the state's cybersecurity incident response capabilities.
“As MNIT cybersecurity teams assess the cyber impacts, they are sharing threat intelligence, providing guidance on response efforts and best practices, and helping affected utilities contain, investigate, and remediate damages from the attack,“it said.
Officials also say the drinking water in those targeted municipalities remains safe and no cities have asked residents to change their water usage.
The agency said it is now “working closely” with the Minnesota Department of Public Safety, the FBI, and other state and federal authorities to “support affected communities and strengthen the security of the state’s critical infrastructure.”
Hackers force water systems into manual mode
Four municipalities have been publicly identified so far, including Plymouth and South St. Paul in the Twin Cities metro area, as well as Maple Plain and Braham.
In at least one city, the attack temporarily knocked a municipal well and water treatment plant offline, according to local media outlet MPRNews.
Other communities reported the attacks disrupted communications and automated operations, forcing staff to switch to manual workarounds while systems were restored, the news outlet said.
One local mayor described the Monday morning attack:
“They were able to hack into the control system of the well and just turn the well off, basically.”
Residents were told to limit water use before systems came back online about an hour and a half later.
“There was power – but there was no controls, you know, telling the water where to go,” the mayor said.
CyberAv3ngers has targeted US water systems before
MNIT spokesperson Emily Zimmer told Reuters that “the timing, methods of access, and targeted infrastructure share characteristics with previous coordinated attacks against US critical infrastructure,” also involving PLCs, or Programmable Logic Controllers.
PLC devices are a critical component used to automate industrial control systems (ICS).
Zimmer said the agency used the term "attack" to describe the situation "because investigators identified unauthorized access with malicious intent directed at these systems," Reuters reported.
And although MNIT has not formally attributed the attacks to the CyberAvengers – a well-known hacktivist collective with ties to the Islamic Revolutionary Guard Corps (IRGC) – the group has successfully breached other US water and wastewater facilities in the past, just never on this scale.
In fact, the US State Department’s Rewards for Justice program put up a $10 million bounty in 2024, asking for any information leading to the arrest of Iranian military officials linked to the group's operations.
In November 2023, the CyberAv3ngers targeted Unitronics PLC-controlled equipment at a Pennsylvania municipal water authority after exploiting an internet-exposed device with default credentials.
Also known as Shahid Kaveh, the group claimed to have exploited the Unitronics PLC model V570 series specifically because the software used to run the device was made in Israel – defacing the system to state their agenda.
“You’ve been Hacked. Down with Israel. Every Equipment "Made In Israel " Is CyberAv3ngers Legal Target!”the gang's message read.
The nation-state APT claimed attacks on at least ten water treatment stations in Israel that same year.
In response to the attack, all WWS facilities were urged to change the Unitronics PLC default password, incorporate multi-factor authentication, and either disconnect the PLC from the open internet or stop using the default TCP port.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
CISA recently expanded Iranian PLC warning
The attacks come less than a week after the US Cybersecurity and Infrastructure Security Agency (CISA) and the FBI expanded an April advisory warning that Iran-affiliated hackers continue targeting “internet-connected operational technology (OT) devices” across US critical infrastructure.
Sectors at high risk include government and energy services and facilities, as well as water and wastewater systems.
The advisory warns that attackers are attempting to manipulate industrial processes and degrade safety functions, increasing the potential for real-world operational impacts and financial loss if internet-connected control systems remain exposed.
The report further warns that attackers have expanded the list of targeted PLC manufacturers beyond Rockwell Automation to include the following:
- Rockwell Automation / Allen-Bradley
- Schneider Electric
- Siemens
- Other manufacturers (unnamed)
Rockwell models at risk include CompactLogix and Micro850, while the specific PLC models for Schneider Electric and Siemens were listed as “To Be Determined.”
What’s more, the PLCs are not being exploited via “CVE-bound vulnerabilities,” according to a summary by Enigma Global.
Instead, the attackers are relying on unsecured PLCs, taking advantage of software misconfigurations, and “insufficient network segmentation and hardening controls.”
CISA states, “The Iranian-affiliated activity has been observed “attempting to download malicious project files and manipulate data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays.”
Critical defenders are being warned to immediately “disconnect PLCs from the internet and watch for suspicious activity.”
Check if your data has been leaked