HackMyIP
← Back to News
2026-07-30 Dark Reading

Iran-Backed Hackers Target 30+ Minnesota Water Systems in Cyberattack

APTThreat IntelIncident Response

A suspected Iran-linked advanced persistent threat (APT) group has launched cyberattacks against more than 30 community water utilities across Minnesota, exposing deep vulnerabilities in the US critical infrastructure sector. The campaign, which targeted small municipal water treatment facilities, underscores how under-resourced public utilities remain prime targets for state-sponsored threat actors seeking to disrupt essential services and gather intelligence on operational technology (OT) environments.

Security researchers at the Minnesota IT Services division identified the intrusions, linking the activity to a known Iranian threat cluster that has previously targeted Israeli and US water systems. The attackers reportedly exploited unpatched vulnerabilities in internet-exposed programmable logic controllers (PLCs) and human-machine interfaces (HMIs), gaining initial access through weak or default credentials on remote management interfaces. Once inside, the actors conducted network reconnaissance, attempted lateral movement into supervisory control and data acquisition (SCADA) networks, and in some cases altered water treatment settings. Security teams can use a port scanner to identify exposed ICS endpoints and an SSL/TLS checker to verify that management interfaces are properly encrypted.

The incidents highlight a broader pattern of Iranian, Chinese, and Russian APT groups increasingly focusing on US water and wastewater systems, which often lack dedicated cybersecurity staff and rely on legacy equipment. Federal agencies, including CISA and the FBI, have issued multiple advisories warning that nation-state actors are pre-positioning on critical infrastructure networks for potential disruptive operations. Organizations can leverage the privacy checkup to audit their external attack surface and identify exposed services that could serve as entry points for these campaigns.

In response, Minnesota authorities have urged all water utilities statewide to conduct immediate security assessments, enforce multi-factor authentication on remote access points, segment OT networks from corporate IT infrastructure, and apply the latest firmware updates to industrial control systems. The episode serves as a stark reminder that critical infrastructure cybersecurity is no longer optional, and that even small municipalities must adopt a threat-informed defense strategy to counter persistent, well-funded adversaries.

Source: Dark Reading →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →