A leaked internal memo ties a wave of cyberattacks on more than 30 Minnesota water utilities to Iranian state-sponsored hackers, according to a document obtained by WIRED and sent to members of the Water Information Sharing and Analysis Center. The attacks, which hit municipal drinking water and wastewater systems across the state, represent one of the most disruptive strikes Iran has launched against U.S. infrastructure since the war between the two countries began in late February. The memo explicitly links the Minnesota incidents to a hacking campaign that the U.S. Cybersecurity and Infrastructure Security Agency first attributed to "Iran-affiliated" hackers in April.

The WaterISAC communication states that Minnesota's Fusion Center, a state intelligence-sharing organization, issued an alert about "ongoing malicious cyber activity impacting public drinking water systems across Minnesota" and determined the attacks were "aligned" with the Iran-linked campaign CISA had previously described. According to the memo, the hackers compromised remotely accessible programmable logic controllers with the "likely desired impact to cause loss of system pressure and potential contamination of the water supply." The targeted facilities managed to prevent further damage, but the full scope of the impact is still under review, the memo notes. In at least one municipality—the 1,700-resident city of Braham—the hacking led to a temporary shutdown of the water plant, though there's no evidence yet of water shortages or threats to Minnesota's water safety. A CISA advisory released Thursday warns that the attacks have "resulted in boil-water notices" and "sustained manual operations."

Former Los Alamos National Labs cybersecurity researcher Joe Slowik, now working under contract for the Department of Energy, called the confirmation of Iran's responsibility a rare instance of state-sponsored targeting of civilian infrastructure outside Russia's war against Ukraine. "Now we have documented disruption and even modification of safety and protection parameters in critical infrastructure," Slowik told WIRED. The CISA advisory updated last week—originally issued in April but revised on July 22—warned that Iran-linked actors were targeting programmable logic controllers used for automation in critical infrastructure to cause "operational disruption and financial loss." The advisory specifically noted that CyberAv3ngers, a hacker group tied to Iran's Revolutionary Guard Corps, had carried out similar PLC targeting, though it doesn't explicitly mention the Minnesota attacks. Cybersecurity firm Claroty researcher Yhonatan Harari told WIRED that while it remains unclear whether CyberAv3ngers or another Iranian group called Handala is responsible, "in a very high likelihood we can say it's Iranian actors."

Slowik warned that there's no reason to expect the attacks will stop with Minnesota. "There are plenty of other sites that have the same targeted technology," he said. "There's plenty of areas for this to still be executed by an adversary that has shown a willingness to do so." CyberAv3ngers first emerged in late 2023 after Hamas' October 7 attacks, initially targeting devices sold by industrial control systems firm Unitronics and setting them to display "Gaza" along with the group's logo. While those attacks appeared to be vandalism, cybersecurity firms tracking the incidents found the hackers had actually rewritten device code, causing disruption to water services from Israel to Ireland to a facility in Pittsburgh. The group's attacks continued to escalate even after the State Department offered a $10 million bounty for information and the Treasury sanctioned six IRGC officials allegedly linked to it. The Thursday CISA advisory urges utilities to disconnect PLCs from the internet, use strong passwords, and allow only trusted devices to connect—underscoring the urgency of defending water infrastructure that hackers have shown they're willing and able to sabotage.