
A series of cyberattacks targeting water systems in Minnesota is under investigation, with cybersecurity researchers and U.S. authorities examining whether the activity may be linked to CyberAv3ngers, a hacking group that U.S. officials have previously associated with Iran.
Approximately 30 water systems were reportedly targeted over two days, temporarily disrupting operations at one municipal water utility. While investigators are exploring possible links to Iran-backed cyber actors, U.S. authorities have not publicly attributed the attacks to the Iranian government.
What Happened?
According to U.S. media reports, multiple municipal water systems in Minnesota experienced cyber incidents on July 26 and July 27.
The attacks reportedly affected approximately 30 water systems, although the extent of the impact varied.
The city of Braham experienced a temporary disruption to its water operations, with officials restoring normal service after roughly two hours.
Authorities have not reported widespread interruptions to drinking water service or evidence that water quality was compromised.
Who Is Suspected?
Investigators are examining whether the attacks are connected to CyberAv3ngers, a hacking group that has previously targeted industrial control systems and critical infrastructure.
Cybersecurity company Tenable said technical characteristics observed during the incident resembled methods previously associated with CyberAv3ngers.
However, similarities in tactics alone do not constitute definitive attribution, and the investigation remains ongoing.
Has Iran Been Officially Blamed?
Not at this stage.
While U.S. officials have previously linked CyberAv3ngers to Iran’s Islamic Revolutionary Guard Corps (IRGC), no U.S. agency has publicly attributed the Minnesota incidents to the Iranian government.
The FBI has not publicly announced an official conclusion regarding responsibility for these attacks.
Iran has consistently denied directing cyberattacks against foreign targets.
Why Are Water Systems Being Targeted?
Water treatment facilities increasingly rely on internet-connected industrial control systems to monitor and operate equipment.
Cybersecurity experts have warned that these systems can become attractive targets because they provide essential public services and, in some cases, may operate with limited cybersecurity resources.
Recent years have seen multiple cyber incidents involving water utilities in several countries, prompting governments to strengthen protections for critical infrastructure.
Recent Government Warnings
The reported attacks occurred shortly after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that Iran-aligned cyber actors could target internet-connected operational technology used by critical infrastructure operators.
The advisory encouraged organizations to:
- Secure internet-facing control systems.
- Apply software updates promptly.
- Strengthen authentication measures.
- Monitor networks for unusual activity.
The advisory was precautionary and was not issued in response to the Minnesota incidents specifically.
Previous Activity Attributed to CyberAv3ngers
U.S. authorities have previously accused CyberAv3ngers of conducting cyber operations against industrial control systems, including water infrastructure.
According to prior U.S. government statements, the group has focused on internet-connected devices used to operate critical infrastructure.
Public attribution in cyber incidents is often based on a combination of technical evidence, intelligence assessments, and investigative findings rather than a single indicator.
Broader Cybersecurity Concerns
The Minnesota investigation follows a broader pattern of heightened concern about cyber threats targeting critical infrastructure.
Government agencies and private cybersecurity firms have warned that state-linked and criminal hacking groups increasingly view essential services—including water, energy, healthcare, and transportation—as attractive targets.
Because attribution can take weeks or months, investigators typically avoid assigning responsibility until technical and intelligence evidence has been thoroughly evaluated.
Why This Matters
Water systems form part of a country’s critical infrastructure and are increasingly dependent on digital control systems.
Even limited disruptions can prompt broader concerns about cybersecurity preparedness and the resilience of essential public services.
The investigation also illustrates the challenges of attributing cyberattacks, where technical similarities, intelligence assessments, and public evidence must be carefully weighed before governments formally identify those responsible.
The Bottom Line
Authorities are investigating cyberattacks that reportedly targeted about 30 Minnesota water systems, with researchers examining possible links to CyberAv3ngers, a hacking group previously associated by U.S. officials with Iran. While technical similarities have prompted scrutiny, no U.S. agency has publicly attributed the attacks to Iran, and the investigation remains ongoing.
TL;DR
- Around 30 Minnesota water systems were reportedly targeted in cyberattacks.
- A water utility in Braham experienced a temporary service disruption lasting about two hours.
- Investigators are examining whether the activity is connected to CyberAv3ngers.
- U.S. officials have previously linked CyberAv3ngers to Iran’s Islamic Revolutionary Guard Corps (IRGC), an allegation Tehran denies.
- No official public attribution has yet been announced by the FBI or other U.S. authorities.



