CyberAv3ngers suspected in Minnesota water system attacks
Tenable says the Iran-linked group may be behind disruptions at more than 30 Minnesota water facilities, though officials have not attributed the attacks.
By Renata Fuchs · Policy Reporter
· 3 min read
Tenable researchers suspect CyberAv3ngers was behind the Minnesota water system cyberattacks that disrupted more than 30 community facilities on July 26 and 27. The assessment is not an official attribution: Minnesota and federal agencies have not named a responsible actor, and the state has released limited technical detail about the incidents.
The case matters beyond Minnesota because it fits a pattern security teams have been warning about: attacks against operational technology at small public utilities, where exposed control systems and limited security staffing can turn basic access mistakes into service disruptions. Tenable said the timing also stands out. CISA updated an advisory on July 22 about Iran-linked actors targeting programmable logic controllers, or PLCs, across critical infrastructure, four days before Minnesota reported the attacks.
Minnesota IT Services, known as MNIT, described the incidents as a coordinated cyberattack against operational technology. The agency said the Minnesota Department of Health is working with affected water facilities to maintain public health, and that no cities had asked residents to change drinking water consumption as of its latest update.
What happened to Minnesota water systems?
The disruptions hit more than 30 community water systems over two days. MNIT has not provided a facility-by-facility account of what failed, how attackers got in, or whether any specific vendor equipment was involved.
Braham was among the first cities to disclose a problem. It initially warned that water reserves were limited and asked residents to avoid lawn watering and recreational water use. The city said the issue was fixed the same day. Maple Plain declared a state of emergency to gain more flexibility in coordinating resources, but did not tell residents to reduce water use. Plymouth and South St. Paul also confirmed cyber-related issues on July 27 without asking for consumption cuts.
John Israel, MNIT assistant commissioner and Minnesota chief information security officer, said the response involved agencies at multiple levels of government sharing intelligence, supporting affected communities and helping utilities restore operations safely. He said the incident showed the value of Minnesota’s cybersecurity investments and partnerships.
What is CyberAv3ngers?
CyberAv3ngers is a hacker persona first identified around 2020 and widely believed by researchers to be tied to Iran’s Islamic Revolutionary Guard Corps, specifically its Cyber-Electronic Command division. Tenable said the group initially operated as a propaganda front, claiming attacks on Israeli infrastructure that were later found to be fabricated.
The group’s first sustained campaign, according to Tenable, came in November 2023, when it compromised Unitronics Vision Series PLCs at the Municipal Water Authority of Aliquippa in Pennsylvania and displayed anti-Israel messages. Tenable said the broader campaign affected at least 75 Unitronics PLCs in the United States, Israel, the United Kingdom and Ireland, with default passwords used as the access path.
Between 2024 and 2025, CyberAv3ngers developed an OT and IoT malware kit called IOCONTROL, according to Tenable. OpenAI said in 2024 that members of the group used ChatGPT during that development process. Tenable said the group increased activity in 2026, targeting U.S. critical infrastructure through Rockwell Automation and Allen-Bradley PLCs from March onward.
CISA’s July 22 advisory update expanded the list of potential targets to include Schneider Electric and Siemens equipment. Federal officials said some attacks across critical infrastructure sectors caused operational disruption, but did not describe those disruptions in detail.
The operational lesson is familiar to utility security teams. Tenable said some small and rural operators use remote-access tools such as TeamViewer and AnyDesk to manage OT environments, or leave PLCs reachable from the internet. Those choices can place control systems outside conventional enterprise monitoring. Weak separation between IT and OT networks can also let one breach affect a wider part of the environment.
This story draws on original reporting from The Register.