World
the digital front •
This is how the Pasdaran use cyber soldiers to terrorise the West
US intelligence suspects that Iran is behind the cyberattack on Minnesota’s water systems and other similar incidents reported in other states. The Washington Post article

One of the water treatment plants affected in Minnesota (photo: LaPresse)
US intelligence agencies believe it is highly likely that Iran is behind the coordinated cyberattack that hit more than thirty municipal water systems in Minnesota this week, according to several US officials. The FBI is investigating the attack, which comes as the military conflict between the United States and Iran, which began five months ago, risks escalating.
Although intelligence agencies have not yet reached a definitive conclusion regarding Tehran’s responsibility, the attack follows months of warnings from federal cybersecurity authorities that Iran had targeted devices controlling the operation of water supply, wastewater treatment and energy infrastructure in the United States, causing operational disruptions in some cases. According to Joe Slowik, director of threat research at the intelligence platform Dataminr, intrusions have been detected at several water and energy facilities across the country since the days following the outbreak of the war on 28 February. “It’s no secret that these activities have been ongoing since the spring,” he said. “There have been disruptions in several sectors of critical infrastructure. It’s a very serious matter.”
The New York Times had already reported that federal and state investigators believe Iran is likely to have been involved in the attacks in Minnesota. At least one facility was temporarily out of service and another suffered a disruption to its remote sensors. However, the state’s IT agency states that, at present, Minnesotans have not been asked to alter their drinking water consumption. The attacks took place between Sunday and Monday, according to a statement issued by Minnesota IT Services, the state agency responsible for IT systems. The agency, together with the affected local authorities, is working with state and federal authorities to share information on the threats and restore the compromised systems.
Nate George, mayor of Braham, stated in an online press release that the town’s Public Works department had discovered the attack in the early hours of Monday morning. After learning that at least four other communities in Minnesota had been affected, technicians determined that their system had also been compromised. “Public works staff isolated the compromised system, restored a backup and got the system up and running again in around ninety minutes,” explained George, adding that during the outage, residents were supplied with water via the town’s water tower. In the town of Plymouth, too, several devices controlling the operation of the water and sewerage systems were compromised, but were subsequently restored, reported Michael Thompson, director of public works. The water supply was not interrupted. Those primarily affected were the so-called PLCs (Programmable Logic Controllers), industrial devices that automatically control water levels, pressure, pump operation and system alarms.
Since the start of the war on 28 February, Iran has stepped up its cyberattacks against the United States, although most of them have not received much media attention. Kurt Gaudette, head of intelligence at the cybersecurity firm Dragos, which specialises in protecting critical infrastructure, argues that there is a recurring pattern between the March attacks and those in Minnesota: small utility operators using internet-connected control units that are still protected by default passwords are being targeted. “They are extremely easy targets,” he says. Gaudette recalls a similar incident in late 2023, when a PLC at a water pumping station in Aliquippa, Pennsylvania, was hacked. The attack, which caused no significant consequences, was claimed by the CyberAv3ngers group, affiliated with Iran’s Revolutionary Guards. The plant used PLCs manufactured by the Israeli company Unitronics, which was targeted by the same campaign of attacks in the United States, the United Kingdom, Israel and Ireland. The attacks came shortly after the start of the Israeli offensive in Gaza following the Hamas attack that claimed around 1,200 lives.
According to Alex Orleans, head of threat intelligence at Sublime Security, Iran’s objective does not appear to be so much to destroy infrastructure as to send a message to two audiences: the Americans and the Iranian regime itself. “The first target is the American public: to make us panic and fuel anti-war sentiment by making it seem as though the cost of the conflict is too high, when in reality our systems are quite resilient,” he explains. “The second is the Iranian regime itself. They want to prove to their superiors that they are contributing to the war effort.” According to Slowik, who monitors cyber threats originating from abroad, the incidents in Minnesota and other states, including some on the east coast, are the work of the Revolutionary Guards’ Cyber Electronic Command. “Iran’s actions reflect a desire, or a need, to be able to say: ‘We can strike you too, even if it’s not New York or Los Angeles’,” he explains.
In April and July, the Cybersecurity and Infrastructure Security Agency (CISA) of the Department of Homeland Security had already issued alerts warning that the Pasdaran were exploiting vulnerabilities in PLCs. On Thursday, the agency issued a new alert, reporting “a significant increase” in hostile actors targeting devices that control the operation of water and wastewater treatment plants. CISA has recommended disconnecting these devices from the internet as soon as possible and changing passwords immediately. In March, the IT systems of medical device manufacturer Stryker were also compromised for two or three weeks following an attack claimed by the Handala group, which the US Department of Justice believes was created on behalf of the Iranian Ministry of Intelligence and Security. Earlier this year, Handala had also claimed to have successfully hacked into the personal email account of the director of the FBI, Kash Patel.
Ellen Nakashima and Pranshu Verma
Copyright Washington Post