Iranian hackers attempted cyberattacks against critical US infrastructure: report
Note: AI technology was used to generate this article’s audio.
Iranian hackers have recently attempted cyberattacks against a broad range of US critical infrastructure, including water systems, telecommunications, energy facilities and other targets, according to NBC News citing four people with access to government and industry cyberthreat information.
The attempts, reported in recent weeks, have so far been unsuccessful.
An Iranian hacking group issued a warning that “unexpected and critical events” would soon target American infrastructure.
The activity builds on earlier Iranian-linked operations.
US agencies, including CISA, the FBI, NSA and others, have repeatedly warned since April 2026 that Iranian-affiliated actors are exploiting internet-connected programmable logic controllers (PLCs) in water and wastewater systems, energy facilities and government services.
These efforts involved malicious project files and manipulation of HMI and SCADA displays, causing limited operational disruption and financial losses in some cases.
Officials assess the campaign aims to produce disruptive effects inside the United States, likely in response to ongoing ‘Israeli’-US war on Iran.
In late July 2026, coordinated attacks hit water systems in Minnesota (more than 30 communities) and at least six other states, with some reports expanding the scope to around a dozen states and over 100 facilities.
In certain instances the activity degraded water operations, such as temporarily affecting pump stations and prompting boil-water advisories, though no widespread contamination or prolonged outages of drinking water quality were reported.
US intelligence assessments have linked much of this activity to Iranian actors, including groups associated with the Islamic Revolutionary Guard Corps such as CyberAv3ngers, though public official attribution has remained cautious.
One source familiar with the latest information described the broader targeting of telecommunications, energy and other sectors beyond water as a continued escalation.
Federal advisories have urged operators to disconnect internet-exposed industrial control systems, change default credentials and monitor for anomalies.
Experts note that many US water utilities and aging industrial systems remain vulnerable due to their decentralized nature and reliance on outdated, internet-facing devices.
The pattern fits a longer history of Iranian cyber operations against US critical infrastructure, including prior targeting of water systems with Unitronics and other PLCs, energy providers, and related sectors.
Groups such as Handala have also claimed or been linked to disruptive incidents, including attacks on medical technology firms and data leaks.
Treasury and Justice Department actions have sanctioned and charged individuals tied to related Iranian cyber networks.



