More than 30 community water systems in Minnesota were hit by a coordinated cyberattack that caused limited operational disruptions but did not make drinking water unsafe, according to reporting cited in Srsly Risky Biz. The incidents came less than a week after US federal agencies refreshed a warning that Iranian state-affiliated actors may target US critical infrastructure, noting compromises and operational disruption across multiple sectors since March. While the Minnesota activity was not formally attributed, Tenable said the operational pattern was consistent with CyberAv3ngers, a threat actor linked to Iran’s Islamic Revolutionary Guard Corps.
The attacks fit a broader pattern of low-level but disruptive operations against operational technology and embedded devices, where adversaries exploit weak remote access, exposed management services, compromised credentials, and insecure update mechanisms to interrupt physical processes. Research on destructive OT incidents has shown that even relatively simple techniques can disable or brick field devices, routers, modems, and monitoring equipment, increasing pressure on operators of water, energy, and other essential services to harden remote management, validate firmware and logic updates, and prepare recovery plans for device-level disruption.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Predatory Sparrow carried out another attack against Iranian fuel systems, marking a renewed disruptive operation after its 2021 fuel-station incident.
Attackers targeted the ViaSat KA-SAT satellite network, gained access through a VPN gateway to the management plane, and deployed AcidRain over SSH using compromised credentials. The malware wiped tens of thousands of SurfBeam2 modems and disrupted remote monitoring and control of 5,800 Enercon wind turbines in Germany.
Predatory Sparrow claimed responsibility for a cyberattack that disrupted more than 4,000 fuel stations across Iran. The attack prevented use of subsidized fuel smart cards, caused long lines for days, and reportedly soft-bricked POS devices that displayed the hotline number 64411.
Russian state-sponsored hackers targeted dozens of substations across three Ukrainian distribution system operators, leaving more than 230,000 people without power for three to six hours. Attackers manually opened circuit breakers, wiped SCADA servers with KillDisk, launched denial-of-service attacks on call centers, and allegedly bricked at least 16 serial-to-Ethernet converters.
A leaked NSA ANT catalog described implants for routers, firewalls, BIOSes, satellite phones, and hard drives, illustrating offensive capabilities against embedded and hardware-adjacent systems.
Although the Minnesota incidents were not formally attributed, Tenable assessed that the operational pattern was consistent with CyberAv3ngers, a threat actor associated with Iran’s Islamic Revolutionary Guard Corps.
More than 30 Minnesota community water systems were targeted in a coordinated cyberattack that caused limited operational disruptions but did not make the water unsafe to drink. Braham saw the worst reported impact, and residents were asked to limit water consumption for a few hours while the city relied on a single water tower.
US federal agencies said that since March, Iranian state-affiliated actors had compromised multiple victims across several critical infrastructure sectors. Some victims experienced operational disruption and financial loss.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
news.risky.biz
Open sourcemidnightblue.nl
Open sourceboozallen.com
Open sourceeff.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.