The Breach: An Internal Memo Draws a Direct Line to Tehran

A confidential memo from the Water Information Sharing and Analysis Center (WaterISAC), obtained by WIRED on Thursday, has for the first time explicitly linked the cyberattacks that hit more than 30 Minnesota water and wastewater utilities to Iran. The memo draws on an alert from the Minnesota Fusion Center, which found the activity was “aligned” with a hacking campaign the Cybersecurity and Infrastructure Security Agency (CISA) had already attributed to “Iran-affiliated” hackers in April.

The attacks disrupted telecommunications between industrial control system components and water plant equipment, in some cases disabling automated operations entirely. In the 1,700-person city of Braham, the breach caused a brief water plant outage. While no water shortages or safety failures were reported, a separate CISA advisory issued the same day noted that the incidents had “resulted in boil-water notices,” a sign that hackers may have tampered with parameters that control water pressure and contamination safeguards.

Joe Slowik, a former Department of Energy contractor and cybersecurity researcher at Los Alamos National Labs, described the attacks as a rare case of state-sponsored targeting of civilian infrastructure outside of Russia’s war against Ukraine. “Now we have documented disruption and even modification of safety and protection parameters in critical infrastructure,” Slowik said. “Seeing this sort of tradecraft expand to Iran, and seeing it across multiple sites, should really be making people concerned.”

From CyberVandalism to Active Sabotage: The Escalating Threat to U.S. Water Infrastructure

The Iran Fingerprint: CyberAv3ngers or Handala—or Both?

While the WaterISAC memo draws a firm line to Iran, the precise group behind the Minnesota hits remains uncertain. Security firm Tenable had earlier floated CyberAv3ngers, an actor tied to the Iranian Revolutionary Guard Corps that has specialized in targeting programmable logic controllers (PLCs) in water systems since late 2023. That group’s previous campaigns—from defacing Unitronics devices with “Gaza” to infecting IoT devices with IOControl malware—demonstrated a consistent willingness to rewrite industrial code and cause physical disruption. However, Claroty researcher Yhonatan Harari told WIRED that his firm found evidence pointing instead to Handala, a distinct Iranian group that claimed credit for breaching Stryker and former Trump official Kash Patel’s email. The common denominator, Harari stressed, is “a very high likelihood” that Iranian actors are responsible. The operational similarity—compromising remotely accessible PLCs with the “likely desired impact to cause loss of system pressure and potential contamination”—aligns so closely with CyberAv3ngers’ established playbook that many experts see the group as the prime suspect.

What Makes This Wave Different: Intentional Safety-Parameter Manipulation

Earlier attacks by CyberAv3ngers were often dismissed as vandalism, albeit disruptive. The Minnesota breaches, however, crossed a threshold: they triggered actual boil-water notices, meaning the intrusion altered settings to the point where officials feared contamination. The WaterISAC memo states that the hackers’ goal appeared to be causing “loss of system pressure and potential contamination.” That shifts the threat from mere operational nuisance to a deliberate attempt to endanger water safety. As Dragos researcher Kyle O’Meara noted of the group last year, “They definitely have the capability; they have the intent. They have the interest in learning how to shut things off and potentially cause harm.” The CISA advisory confirmed that hackers exfiltrated and manipulated project files governing automated industrial processes, meaning they not only intruded but understood enough about the control logic to weaponize it.

Targets Across the Board: Why Small Municipalities Are the Soft Underbelly

More than 30 Minnesota water and wastewater systems were hit, from tiny towns to South St. Paul. CISA warns that threat actors are “targeting water entities of all sizes,” signaling a broad, opportunistic campaign. Small municipal utilities often lack the dedicated cybersecurity staff, segmentation, and monitoring that larger operators possess, yet they rely on the same vulnerable internet-exposed PLCs. The attack on Braham illustrates the potential: a brief plant shutdown in a community of 1,700 may seem minor, but if hackers can flip a switch there, they can repeat the process at hundreds of similar sites that use the same hardware, as Slowik cautioned. The risk is not limited to Minnesota: the same Unitronics devices and other industrial controllers are deployed in water facilities nationwide.

What Water Utility Operators, Regulators, and the ICS Security Industry Should Do Next

For water utility operators:

  • Immediately disconnect PLCs from the public internet unless an air-gapped network with strong allow-listing is in place, as CISA explicitly recommended in its Thursday advisory. This is not a future project—the advisory was issued because actively exploited vulnerabilities exist.
  • Audit project files and controller configurations for unauthorized modifications. The documented tactic of exfiltrating and manipulating these files means a clean compromise today can be weaponized later even if the hackers lose access.
  • Review remote-access protocols across all ICS components, not just PLCs. The Minnesota breaches relied on compromising remotely accessible devices; multi-factor authentication and VPNs with verified configurations are the minimum baseline.
  • Test manual override procedures under simulated outage conditions, as several targeted municipalities relied on “contingency procedures” to maintain operations. The ability to run plants manually without automated controls must be rehearsed and documented.

For regulators and industry groups (WaterISAC, EPA, state fusion centers):

  • Expedite the rollout of mandatory incident reporting for water utilities, including initial compromise indicators. Voluntary sharing is not keeping pace with a threat that pivots within hours. The WaterISAC memo’s “official use only” distribution, while necessary for operational security, also delayed broader defensive action.

For the industrial control system security industry:

  • Firms like Dragos, Claroty, and Tenable should urgently release detection signatures for both CyberAv3ngers’ and Handala’s specific PLC manipulation techniques, not just generic Iranian-state TTPs. The distinction matters when over 30 utilities are scrambling to determine if they were breached by the same actor.

Risk & Opportunity Assessment

Commercial RiskHighWater utilities face immediate operational outages, boil-water orders, and potential liability; municipalities like Braham experienced a plant shutdown, and insurers will reassess cyber premiums for exposed ICS assets.
Competitive RiskLowCompetition among water utilities is negligible, but utilities that demonstrate robust cybersecurity posture may gain preferential access to federal grants and lower insurance costs.
Regulatory RiskHighCISA, EPA, and state fusion centers are intensifying scrutiny; mandatory security standards for internet-exposed industrial controllers are likely, and failure to comply could bring enforcement actions under existing environmental and security regulations.
Reputation RiskCriticalFor Iran, attribution of attacks that trigger boil-water notices carries immediate reputational damage at the UN and with allies; for the targeted utilities, any lasting water-quality incident—even if prevented this time—would erode public trust permanently.
Technology DisruptionTransformationalThe shift from nuisance defacement to deliberate safety-parameter manipulation rewrites the threat model for OT security. The same tradecraft can be applied to any internet-connected PLC in energy, manufacturing, and transportation.
Commercial OpportunityHighFirms offering OT-specific network segmentation, PLC integrity monitoring, and incident response for industrial environments will see a surge in demand from water and other critical infrastructure sectors seeking to harden their systems.