Thirty water companies across Minnesota faced cyber assaults this week, believed to be the work of the Iranian hacker group CyberAv3ngers. Security researchers at Tenable linked the attacks with the group's previous operations, while Minnesota's state IT agency described the disruption as the result of a coordinated effort.

Tenable highlighted the timing of the intrusions as key, especially in light of a July 22 warning from the US Cybersecurity and Infrastructure Security Agency (CISA) about Iranian actors actively probing internet-connected devices like programmable logic controllers within US critical sectors such as water and energy. This aligns with broader concerns about escalating Iranian cyber activities paralleling kinetic hostilities against US infrastructure.

CyberAv3ngers: More Than Just Hacks

The hacker collective has a notable track record: Sophos reports CyberAv3ngers claimed responsibility for a 2020 cyberattack targeting 150 Israeli railway servers and 28 stations. Later attempts to sell the stolen data for four bitcoin demonstrated their approach to monetizing breaches. In 2025, leaked documents exposed ties between CyberAv3ngers and another Iranian group, Moses Staff, painting a picture of a state-coordinated cyber operation rather than fractured individual actors.

US authorities have yet to officially attribute the Minnesota incident, but the group's growing footprint signals risks for critical infrastructure. The ongoing tensions between the US and Iran suggest that such cyber confrontations could become more frequent and sophisticated.

This content is informational and does not constitute financial advice.