Leaked Memo Links Cyberattacks on Minnesota Water Utilities to Iran
A leaked memo confirms that Iranian hackers are responsible for cyberattacks on multiple water utilities in Minnesota, causing operational disruptions and boil-water advisories.

According to a leaked document obtained by WIRED, Iranian hackers are responsible for a series of cyberattacks that hit more than 30 municipal water and wastewater systems in Minnesota. The memo was circulated by the Water Information Sharing and Analysis Center (WaterISAC), citing an alert from the Minnesota Fusion Center.
The attacks used tactics previously described by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) as conducted by “Iran-affiliated” hackers. The hackers gained access to programmable logic controllers (PLCs), which could lead to loss of pressure and potential water contamination. In at least one town, Braham (population 1,700), the attack caused a brief water outage, though officials assert that drinking water remains safe.
Security experts note that such targeting of civilian infrastructure has rarely been seen outside of Russia’s war against Ukraine. Now Iran is demonstrating similar capabilities. While no group has officially claimed responsibility, investigators point to the Iranian Revolutionary Guard–linked group CyberAv3ngers or the group Handala.
In response, CISA issued new guidance urging water utilities to disconnect PLCs from the internet, use strong passwords, and allow only trusted devices. The attacks come amid the broader conflict that began when the US launched its war against Iran in late February; previous Iranian hacks targeted medical supply company Stryker and FBI Director Kash Patel’s personal email.
/nginx/o/2026/07/30/17816963t1h4f72.jpg)

