Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems
A coordinated cyberattack disrupted more than 30 water systems across Minnesota on July 26 and 27, targeting operational technology infrastructure. While some facilities reported temporary constraints—Braham initially faced limited reserves—officials determined public health was maintained and no communities required water restrictions. Several municipalities declared states of emergency to facilitate response coordination, but impacts remained contained.
Security researchers at Tenable have attributed the attacks to CyberAv3ngers, a group suspected of links to Iran's Islamic Revolutionary Guard Corps, though state and federal authorities have not officially confirmed attribution. The attack timing aligns with a CISA advisory issued July 22 warning of Iran-linked actors targeting industrial control systems. Minnesota's government agencies coordinated a multi-level response, with officials highlighting that established cybersecurity partnerships and early warning systems limited escalation.
- Over 30 Minnesota water systems were disrupted by coordinated cyberattack July 26–27 targeting operational technology; disruptions contained without public health risk
- Tenable researchers attribute attacks to Iran-linked CyberAv3ngers, though officials have not officially confirmed; timing aligns with CISA warning four days prior