Key Takeaways
- Investigators are examining whether Iranian‑linked hackers are responsible for a recent cyber intrusion targeting water systems in seven U.S. states, including Minnesota.
- Over the past decade, Iranian state‑affiliated or IRGC‑connected actors have repeatedly conducted cyber operations against American banks, critical infrastructure, government agencies, defense contractors, hospitals, and political entities, often seeking disruption, publicity, or intelligence.
- Notable incidents include distributed denial‑of‑service attacks on U.S. banks (2011‑2013), intrusion into the Bowman Avenue Dam control system (2013), the destructive Las Vegas Sands hack (2014), prolonged espionage against federal agencies and defense contractors (2016‑2021), ransomware‑extortion campaigns (2017‑2024), election‑related influence operations (2020), attacks on Boston Children’s Hospital (2021), the CyberAv3ngers’ targeting of water‑system PLCs (2023‑2024), a presidential‑campaign hack‑and‑leak effort (2024), and recent breaches of medical‑technology and FBI officials’ email accounts (2026).
- While Iran consistently denies involvement, U.S. officials have attributed many of these campaigns to Iranian state‑linked groups, citing technical evidence, indictments, and intelligence assessments.
- The current water‑system probes echo earlier PLC‑focused attacks, highlighting a persistent Iranian interest in exploiting weakly secured industrial control devices to cause disruption and send political messages.
Recent Probe into Water‑System Intrusions
Investigators are actively probing whether Iranian hackers are behind a series of malicious cyber incidents this week that targeted water and wastewater systems in seven U.S. states, among them Minnesota. The activity follows a pattern seen in earlier Iranian‑linked operations that exploited programmable logic controllers (PLCs) to manipulate industrial equipment. If confirmed, this would add another episode to a decade‑long chronicle of Iranian cyber aggression against American infrastructure. Authorities caution that definitive attribution may take weeks or months as forensic analysts collect and correlate technical artifacts such as malware signatures, IP addresses, and command‑and‑control infrastructure.
Historical Pattern of Iranian‑Linked Cyber Activity
For more than ten years, Iranian‑linked operators—often tied to companies affiliated with the Islamic Revolutionary Guard Corps (IRGC)—have repeatedly scanned for and exploited accessible American targets. Their objectives typically include creating disruption, intimidating adversaries, gaining publicity, and eroding public trust in U.S. institutions. While Iran publicly denies any role in cyberattacks, a substantial body of evidence from court indictments, intelligence reports, and private‑sector analyses points to a consistent pattern of state‑sponsored or state‑tolerated hacking campaigns.
Early Financial‑Sector Attacks (2011‑2013)
Between 2011 and 2013, seven Iranians employed by firms connected to the Iranian government and the IRGC were charged with conducting distributed denial‑of‑service (DDOS) attacks against 46 U.S. financial institutions. The assaults disabled bank websites, preventing customers from accessing online accounts and collectively costing victims tens of millions of dollars in remediation expenses. The Justice Department highlighted the operation as an early example of Iranian actors using cyber tools to inflict economic harm.
Critical Infrastructure Test: Bowman Avenue Dam (2013)
In the same indictment that covered the bank DDOS campaign, one defendant was accused of accessing the control system for the Bowman Avenue Dam in Rye, New York. Although the intruder could view operational data, the dam’s sluice gate was disconnected for routine maintenance at the time, preventing any physical impact. The case demonstrated Iranian interest in gaining footholds within supervisory control and data acquisition (SCADA) environments, even when immediate damage was averted.
Destructive Attack on Las Vegas Sands (2014)
In 2014, the Las Vegas Sands casino corporation suffered a severe cyber breach: its hard drives were wiped, its corporate network degraded, and its hotel websites defaced with messages condemning CEO Sheldon Adelson’s remarks about using nuclear weapons on Iran. The hackers also exfiltrated personal data—including Social Security and driver’s‑license numbers—of tens of thousands of customers. Then‑Director of National Intelligence James Clapper publicly blamed Iran, calling it the first known destructive cyberattack on U.S. soil carried out by a nation‑state.
Espionage Against Federal Agencies and Defense Contractors (2016‑2021)
A 2024 Justice Department indictment alleged that a group of Iranian hackers targeted the U.S. State Department, Treasury Department, and multiple defense contractors possessing classified information, beginning around 2016 and persisting through at least 2021. The campaign also hit an accounting firm and a hospitality company. Defendants worked for a firm that marketed itself as a cybersecurity provider, with one individual reportedly serving in the IRGC’s electronic warfare division. The operation underscored Iran’s long‑term interest in harvesting sensitive governmental and defense‑related data.
Ransomware and Extortion Campaigns (2017‑2024)
From 2017 to 2024, the FBI and CISA warned of an Iranian government‑associated threat cluster known as “Pioneer Kitten” that compromised schools, municipal governments, healthcare organizations, and financial institutions. In many cases, the actors retained access to breached networks and later handed them off to ransomware affiliates, which then extorted victims. Although officials judged the ransomware itself likely unsanctioned by Tehran, the attackers also struck U.S. defense‑sector networks and other entities aligned with Iranian strategic interests.
Influence Operations Targeting John Bolton (2019‑2021)
Between 2019 and 2021, an actor believed to be linked to Iran gained access to the personal email account of John Bolton, former National Security Advisor under President Trump. Federal prosecutors later referenced the breach in an indictment accusing Bolton of mishandling classified records. The intruder reportedly sent Bolton a menacing message warning that the FBI should not learn of the leaked content, illustrating a blend of espionage and intimidation.
Election‑Related Interference (2020)
In the lead‑up to the 2020 presidential election, voters in Florida and several other states received emails purporting to be from the far‑right Proud Boys, urging recipients to “vote for Trump or else!” U.S. intelligence later concluded that Iran was likely behind the messages. A subsequent indictment detailed how two Iranian hackers and co‑conspirators exploited a misconfigured system to download confidential data on over 100,000 voters in an unspecified state, then used that information to send threatening emails to tens of thousands of registered Democrats while also targeting Republican officials with fabricated videos. The U.S. intelligence community assessed that Iran sought to damage the Trump campaign and undermine public confidence, though it did not attempt to manipulate election infrastructure directly. The FBI also blamed Iranian actors for creating a website titled “Enemies of the People” that posted death threats against election officials in late 2020.
Threat to Healthcare: Boston Children’s Hospital (2021)
In 2021, Iranian‑linked actors attempted to infiltrate Boston Children’s Hospital. Former FBI Director Christopher Wray later described the thwarted attack as “one of the most despicable cyberattacks I’ve seen.” CISA reported that Iranian‑sponsored actors had targeted an unnamed U.S.-based pediatric hospital and a municipal government, highlighting the regime’s willingness to menace critical health services.
CyberAv3ngers and PLC‑Focused Water System Attacks (2023‑2024)
Calling itself the CyberAv3ngers, a group affiliated with the IRGC exploited programmable logic controllers (PLCs)—devices widely used to remotely monitor and control industrial machinery—in 2023 and 2024. The same PLCs were implicated in the recent water‑system intrusions affecting Minnesota and other states. The attackers often targeted Unitronics‑made PLCs that either lacked passwords or used default credentials. Once compromised, the devices displayed the message “You have been hacked, down with Israel.” In 2023, the group succeeded in shutting down water‑pumping equipment in Aliquippa, Pennsylvania, demonstrating the capacity to disrupt essential services through inadequately secured industrial control systems.
Presidential‑Campaign Hack‑and‑Leak Operation (2024)
In 2024, the Justice Department charged three Iranian nationals and IRGC employees with hacking into the accounts of current and former U.S. officials, journalists, and political campaigns. Prosecutors asserted that the aim was to sow discord, erode confidence in the electoral process, and gather intelligence that could aid IRGC efforts to avenge the 2020 killing of commander Qasem Soleimani. Although the indictment did not name the targeted campaign, media reports identified it as the Trump campaign. The Trump campaign publicly acknowledged a breach by suspected Iranian actors who stole and disseminated sensitive internal documents; the FBI also examined possible Iranian targeting of the Biden‑Harris campaign’s email infrastructure.
Medical‑Technology and Official Email Breaches (2026)
More recently, in 2026, the Justice Department seized four websites alleged to have been used by Iranian state‑linked groups to publish hacked data and claim responsibility for attacks. One of those groups, Handala, took credit for a March intrusion into medical‑technology firm Stryker. Later that year, Handala also claimed responsibility for compromising the personal email account of FBI Director Kash Patel, a breach reported by CBS News. These incidents illustrate a continuing trend of Iranian actors targeting both corporate intellectual property and high‑profile U.S. officials to gather intelligence and exert pressure.
Conclusion
The ongoing investigation into the recent water‑system intrusions fits squarely within a broader, well‑documented history of Iranian cyber activity against the United States. Over the past decade, Iranian‑linked actors have moved from disruptive DDOS attacks on banks to destructive intrusions at casinos, espionage against federal agencies, ransomware‑enabled extortion, influence operations aimed at elections, and direct threats to critical infrastructure such as water treatment plants and hospitals. Their tactics frequently exploit weakly secured devices with readily exploitable weaknesses—default passwords, unpatched software, or misconfigured systems—to gain access, then leverage that foothold for disruption, data theft, or psychological intimidation. While Iran denies responsibility, the accumulation of technical evidence, indictments, and intelligence assessments makes a compelling case that the Iranian state, or entities closely tied to it, remains a persistent and adaptive cyber threat to U.S. national security, economic stability, and public safety. Continued vigilance, improved hardening of industrial control systems, and robust information‑sharing between government and private sectors are essential to mitigating future incursions.

