The U.S. is investigating a cyberattack on water supply systems and suspects Iran
U.S. intelligence agencies are investigating a large-scale cyberattack on water supply systems in the state of Minnesota. There is no definitive evidence of Iran’s involvement yet, but investigators are considering this possibility, and experts note an increase in activity by hacker groups linked to Tehran.
U.S. intelligence agencies are examining Iran’s possible involvement in a large-scale cyberattack on water systems in the state of Minnesota. More than 30 municipal critical infrastructure facilities were targeted. The Federal Bureau of Investigation is already conducting an investigation. At the same time, U.S. intelligence emphasizes that there is currently no conclusive evidence that hackers linked to Iran were behind the attack.
According to the publication, federal cybersecurity agencies have been warning for several months about increased activity by Iranian cyber groups. They are attempting to gain access to systems that control water and energy facilities in the U.S. In some cases, such attacks have already led to disruptions in infrastructure operations.
Joe Slovik, director of threat research at Dataminr, said that a wave of hacking attempts began to be recorded almost immediately after the U.S.-Israeli strikes on Iran on February 28. “It’s no secret that such incidents have been occurring since the spring. There have been disruptions in many critical infrastructure sectors. This is a serious matter,” he said.
According to Minnesota authorities, the attacks took place on July 26–27. At one facility, the water supply system was temporarily shut down due to the cyberattack, while at another, remote sensors were compromised. However, officials assured the public that the quality of drinking water was not affected and there is no need to change consumption habits. The state’s Department of Information Technology is currently working with municipalities and federal agencies to address the aftermath of the attack and is sharing information about potential threats.
Experts note that the attackers targeted small utility companies that used internet-connected controllers with default passwords. “It’s very easy prey,” explained Kurt Godett, head of the intelligence division at Dragos. He recalled that a similar scenario had already been used in late 2023 during an attack on a water pumping station in Pennsylvania. At that time, the CyberAv3ngers group claimed responsibility; U.S. authorities link this group to the Islamic Revolutionary Guard Corps.
Alex Orleans, head of threat analysis at Sublime Security, believes that the main goal of such operations is psychological impact. “First, it’s the American people: the goal is to make us panic and turn public opinion against the war. Second, it’s the Iranian regime itself. They want to show their leadership that they’re contributing to the military effort,” he noted.
U.S. security agencies had previously reported a sharp increase in activity by hacker groups linked to the Islamic Revolutionary Guard Corps. According to CISA, the FBI, the NSA, and the U.S. Department of Energy, these groups are increasingly targeting critical infrastructure—including water supply systems, the energy sector, and government agencies—by exploiting vulnerabilities in industrial control systems. In a number of cases, this has already led to operational disruptions and financial losses, according to The Washington Post.
The United States and Israel are holding consultations on possibly increasing pressure on Iran, specifically by blocking its land borders. This scenario is being considered as part of broader measures to limit Tehran’s capabilities.