A notorious Iran-linked hacker group was likely behind the recent attacks on dozens of water systems across the US — and the shadowy cyber-soldiers may not be done with their assault, experts warned.
The self-proclaimed “Cyberav3ngers” group appeared to carry out the attacks which hit seven states in recent months, according to cybersecurity company Tenable, which told The Post the devious group began posting on the dark web about plans to hit the US within weeks of war breaking out with Iran.
“We listened or observed them kind of declaring that they were going to start targeting US Water infrastructure in in North America,” Tenable Public Sector Chief Technology Officer Chris Day said. “We started tracking activity back in April, right around the beginning of the Iran War.”
And the group has long-proclaimed itself to be closely tied to Iran’s brutal Islamic Revolutionary Guard Corps (IRGC), with the US Cybersecurity and Infrastructure Security Agency (CISA) also warning on July 22 that the Cyberav3ngers — and by proxy Iran — were likely targeting US systems.
Those attacks resulted in dozens of internet-connected water control systems — over 30 in Michigan alone — being taken over by hackers, who booted administrators and prevented water from being pumped into systems like water towers.
No significant disruptions or harm came from the attacks and order was quickly restored at all sites, but so far nobody has claimed credit for the attacks — which prompted experts to caution the assault may still be underway, especially since the Cyberav3ngers appeared to be the culprits.
“Usually they’re pretty vocal,” Day said. “But in the past we’ve seen them when they started making claims it’s usually after the operation, so that makes me wonder, this operation may not be over.”
“Or they’re still wanting to try to extract maximum gain and notoriety out of it before they say anything,” he added.
And the attacks had the potential to be worse — with law enforcement sources telling The Post hackers could have gained access to systems which control and monitor the dosage of possibly dangerous chemicals in local water supplies.
There remains no concrete proof that the Cyberav3ngers were actually behind the attacks or are even IRGC proxies, but Day said the attacks bore all the fingerprints of both the group’s and Iran’s known tactics in cyberwarfare.
“They’ve always been kind of opportunistic, looking for exposed systems where they can leverage a known vulnerability,” Day said, calling the Cyberav3ngers a “mid-tier” threat-level.
“And they’re always acting as a proxy for the [Iranian] regime in some way,” he added.
The group has been around since at least 2020, and typically targets infrastructure systems within Iran’s enemies in the Middle East.
But the Cyberav3ngers hackers have previously targeted the US, with water systems being hit in Pennsylvania during a spate of attacks from Oct. 2023 to Jan. 2024, according to Tenable.
And while the US was able to easily mop up the effects of the latest attacks, Day cautioned that actions from the likes of the Cyberav3ngers expose cybersecurity vulnerabilities in US infrastructure — which at its worst could result in widespread blackouts and water stoppage.
“We’ve seen no indication that it’s going to get worse, we don’t expect to see a major escalation,” Day said. “But you have to be vigilant.”
Despite CISA and Tenable fingering the Cyberav3ngers as the likely culprit, the situation was cast into confusion Friday after President Trump denied any Iranian involvement — and instead blamed Minnesota’s “corrupt” Gov. Tim Walz.
“They blame it on Iran. I don’t think so,” Trump said. “I think I blame it on Minnesota, because they’re grossly incompetent.”
Walz then accused the president of deflecting.
“Trump knows exactly who is responsible for this attack, and knows that other states were hit too,” Walz wrote on X. “This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran.”
Read the full article here












