Skip to main content
Threat IntelligenceEmerging Threats

Iran-linked CyberAv3ngers targets US water systems

Municipal water treatment plant exterior with industrial infrastructure.

"Cyberattacks against critical infrastructure require a coordinated, whole-of-government response," said John Israel, MNIT assistant commissioner and Minnesota CISO.

What unfolded in Minnesota on July 26–27

On July 26 and 27, more than 30 community water systems across Minnesota were disrupted by what state officials called "a coordinated cyberattack" that targeted operational technology (OT). Minnesota IT Services (MNIT) reported the Department of Health is working with affected water facilities to ensure public health is maintained. MNIT added that, as of its latest update, no cities had asked citizens to modify the amount of drinking water they consume.

Local impacts varied: Braham warned its water reserves were limited and asked residents not to water lawns or use water for recreational purposes, though those problems were resolved the same day. Maple Plain declared a state of emergency to gain flexibility in coordinating resources. The Twin Cities suburb of Plymouth and South St. Paul both confirmed cyber-related problems on July 27, but neither asked residents to curb water use.

Tenable links the pattern to CyberAv3ngers; officials have not attributed

Security researchers at Tenable suspect the Iran-linked faux hacktivist outfit CyberAv3ngers was behind the Minnesota disruptions, saying the operational pattern is consistent with the group's previous raids and noting the timing relative to recent government warnings. The report stresses that neither state-level nor federal officials have made any claims regarding attribution for the attacks.

Tenable's assessment draws a line between the Minnesota incidents and activity patterns the firm has observed previously, but the public record — as reported by MNIT and other federal advisories — does not include an official attribution statement from government authorities.

CISA advisory and the timing that raised alarms

The Cybersecurity and Infrastructure Security Agency (CISA) updated an advisory on July 22 warning of Iran-linked attackers targeting programmable logic controllers (PLCs) across critical infrastructure. That alert, issued four days before Minnesota disclosed the attacks, said Iran-linked hackers were attempting to disrupt operations using tactics previously associated with CyberAv3ngers and urged government facilities, water and wastewater systems, and energy providers to remain on high alert.

CISA's update explicitly added Schneider Electric and Siemens equipment to the list of potential targets, extending earlier public guidance that had focused on other PLC vendors.

Who CyberAv3ngers is and how it operates

First identified around 2020, CyberAv3ngers is widely believed to be linked to Iran's Islamic Revolutionary Guard Corps (IRGC), specifically its Cyber‑Electronic Command division (IRGC‑CEC). Tenable described the group as beginning as a "propaganda persona" and later carrying out real disruptive campaigns.

Notable episodes the source records include a November 2023 campaign that compromised Unitronics Vision Series PLCs at the Municipal Water Authority of Aliquippa, Pennsylvania, defacing them with anti‑Israel messages. Tenable said the group compromised at least 75 Unitronics Vision Series PLCs across the United States, Israel, the United Kingdom, and Ireland by exploiting default passwords. Between 2024 and 2025 the crew developed the IOCONTROL malware kit for OT and Internet of Things (IoT) attacks; OpenAI stated in 2024 that members used ChatGPT in the development process. In 2026 CyberAv3ngers stepped up activity, targeting Rockwell Automation/Allen‑Bradley PLCs from March onward.

Tenable and other observers highlight operational weaknesses CyberAv3ngers exploits: devices left exposed to the web, use of remote‑access software such as TeamViewer and AnyDesk to manage OT, and poor segmentation between IT and OT environments. Those conditions can allow a single intrusion to spread and bypass enterprise security monitoring, Tenable warned.

How technologists, policymakers, and residents are responding

  • Technologists and security teams: Tenable's findings point them toward checking for internet‑exposed PLCs, insecure remote‑access tools (TeamViewer, AnyDesk), default passwords, and weak IT/OT segmentation — the specific failure points Tenable says CyberAv3ngers has repeatedly exploited.
  • Policymakers and government IT: MNIT said it is "working side by side with our partners to share intelligence, support affected communities, and help utilities restore operations safely," and the Department of Health is coordinating with affected facilities — actions consistent with the "whole‑of‑government" response the Minnesota CISO described.
  • Residents and local communities: Responses so far have focused on operational continuity rather than large‑scale public directives — Braham issued a temporary water‑use advisory that was resolved the same day, while other affected cities declared emergencies or reported problems without asking residents to change drinking water consumption.

The incident in Minnesota arrived days after federal warnings, and researchers immediately noted parallels with a group that has repeatedly targeted small water and municipal facilities. Investigations are ongoing; MNIT and public‑health officials remain engaged, and Tenable's public assessment frames this episode as another test of the defenses of smaller water systems that — by the firm's account — have long presented attractive, low‑barrier targets.

Source: The Register — Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems