Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

CyberAv3ngers: The Iranian-Linked Hacktivist Outfit Behind Minnesota's Water System Attacks



Iran-linked CyberAv3ngers has been suspected in the attack on Minnesota's water systems, with experts warning of vulnerabilities in critical infrastructure due to a lack of dedicated cybersecurity resources among small operators. The incident highlights the need for strong partnerships and capabilities in preventing similar incidents.

  • The CyberAv3ngers group, linked to Iran's IRGC, has been suspected in cyberattacks on over 30 Minnesota water facilities.
  • The attack targeted operational technology (OT) and disrupted community water systems, with officials urging residents not to consume drinking water.
  • CyberAv3ngers' operational pattern involves exploiting default passwords and targeting small, vulnerable water and municipal facilities.
  • Poor IT-OT environment segmentation makes these systems vulnerable to attacks, which are often exploited by groups like CyberAv3ngers.
  • The US Department of Health is working with affected water facilities to maintain public health, while officials investigate the incident.



  • Iran-linked CyberAv3ngers, a faux hacktivist outfit widely believed to be linked to Iran's Islamic Revolutionary Guard Corps (IRGC), has been suspected in attacks on more than 30 facilities across the Minnesota water system. The coordinated cyberattack targeted operational technology (OT) and brought disruption to community water systems, with officials urging residents not to consume as much drinking water or use it for recreational purposes.

    According to Security researchers at Tenable, the attack's timing is consistent with previous raids by CyberAv3ngers, which has been linked to Iran's cyberwar efforts. The group, first identified around 2020, initially started as a propaganda persona claiming disruptive attacks on Israeli infrastructure – claims that were later debunked as fabrications.

    CyberAv3ngers' operational pattern is marked by exploiting default passwords and targeting small water and municipal facilities, which experts believe are among the lowest-hanging fruit in US critical infrastructure. Many such operators lack dedicated cybersecurity resources, relying on remote-access software like TeamViewer and AnyDesk to manage OT environments, thereby creating an attack surface that bypasses enterprise security controls entirely.

    Poor segmentation between IT and OT environments also allows a single intrusion to spread across much of the network, making these systems vulnerable to attacks. This vulnerability is exploited by groups like CyberAv3ngers, which has been developing malware kits for attacks on OT and Internet of Things (IoT) devices, including the IOCONTROL malware kit.

    In 2024, researchers noted that the group's members used ChatGPT in the development process, further solidifying its ties to Iranian cyberactors. CyberAv3ngers' stepped up its activity in 2026, targeting US critical infrastructure through Rockwell Automation/Allen-Bradley PLCs from March onward.

    In some cases, these attacks disrupted operations at affected facilities, though federal officials offered no specifics on the nature of those disruptions. Tenable noted that small and rural facilities often lack dedicated cybersecurity resources, making them easier targets for groups like CyberAv3ngers.

    The US Department of Health is working with the affected water facilities to ensure public health is maintained, while state-level and federal officials have yet to name a culprit behind the attacks. The incident highlights the importance of strong cybersecurity capabilities and partnerships in preventing such incidents, as stated by John Israel, MNIT assistant commissioner and Minnesota CISO.

    "Cyberattacks against critical infrastructure require a coordinated, whole-of-government response," he said. "MNIT is working side-by-side with our partners to share intelligence, support affected communities, and help utilities restore operations safely while strengthening defenses against future attacks."



    Related Information:
  • https://www.ethicalhackingnews.com/articles/CyberAv3ngers-The-Iranian-Linked-Hacktivist-Outfit-Behind-Minnesotas-Water-System-Attacks-ehn.shtml

  • https://www.theregister.com/security/2026/07/29/iran-linked-cyberav3ngers-suspected-in-attacks-on-minnesota-water-systems/5280357


  • Published: Wed Jul 29 09:26:09 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us