A Decade of Iranian Cyberattacks on America: What We Know
From wiping casino hard drives to targeting children's hospitals, a pattern of disruptive attacks tied to Iran stretches back more than a decade. Now investigators are asking whether the same playbook was used against water systems in seven US states.

Key points
- Investigators are examining whether Iranian hackers attacked water systems in seven US states, including Minnesota, in an incident reported this week.
- Iranian-linked groups have been formally charged by the US Justice Department with cyberattacks on at least 46 US financial institutions between 2011 and 2013.
- In 2023, a group calling itself CyberAv3ngers, affiliated with Iran's paramilitary Guard Corps, shut down water pumping equipment in Aliquippa, Pennsylvania.
- A 2014 attack on Las Vegas Sands Corp wiped hard drives and exposed customer data, including Social Security numbers and driver's licence numbers.
- Iran has consistently denied involvement in cyberattacks, and official attribution can take weeks or months to confirm.
Something hit water utilities across seven US states this week. Investigators are now looking at whether Iran was behind it, and whether whoever did this may have deliberately made the attack look Iranian to stir up tensions during the current US-Iran standoff. That second possibility matters. Attribution, the process of proving who actually carried out a cyberattack, is hard to do quickly.
But if it does point back to Iran, it would be the latest chapter in a long-running story. We first covered the CyberAv3ngers group on 29 July 2026, in "More Than 30 Minnesota Water Utilities Hit in Coordinated Cyberattack".
What has Iran actually done before?
Quite a lot, and the record is documented in federal indictments, not just intelligence assessments.
Between 2011 and 2013, seven Iranians working for companies tied to the Iranian government and the Guard Corps (IRGC), Iran's paramilitary force, were charged with carrying out distributed denial-of-service attacks, meaning coordinated floods of fake internet traffic designed to knock websites offline, against 46 US banks. Customers could not access their accounts. Remediation costs ran into the tens of millions of dollars across the affected institutions.
The same indictment named one defendant for accessing the control system for a dam in Rye, New York. He could view operational data, though the gate controlling water flow happened to be offline for maintenance at the time.
In 2014, Las Vegas Sands Corp had its hard drives wiped and its corporate network damaged. Its hotel websites were defaced with condemnations of CEO Sheldon Adelson. Then-Director of National Intelligence James Clapper told Congress it marked the first time "destructive cyberattacks [were] carried out on U.S. Soil by nation-state entities." Tens of thousands of customer records were stolen, Social Security numbers among them.
What about attacks closer to everyday life?
Plenty of them touched ordinary Americans directly.
From 2017 to 2024, a group of Iranian government-linked hackers known as Pioneer Kitten broke into schools, municipal governments and healthcare organisations. In some cases they sold that access to ransomware groups, meaning criminal gangs who lock a victim's files and demand payment to restore them. The FBI and the Cybersecurity and Infrastructure Security Agency (CISA), the US government's main civilian cyber defence body, both issued warnings about this campaign.
A separate indictment, filed in 2024, alleged that Iranian hackers targeted the US State Department, the Treasury Department and several defence contractors starting as early as 2016 through at least 2021.
Before the 2020 election, Iranian operatives downloaded data on more than 100,000 voters from a misconfigured state website, one set up with settings that accidentally left it open to outsiders. They then sent threatening emails to tens of thousands of registered Democrats, posing as the Proud Boys. The FBI also linked Iran to a website called "Enemies of the People" that posted death threats against US election officials.
In 2021, the FBI helped stop an attack on Boston Children's Hospital. Former FBI Director Christopher Wray called it "one of the most despicable cyberattacks I've seen."
How does this week's water incident fit the pattern?
It fits closely. From 2023 onwards, CyberAv3ngers targeted programmable logic controllers (PLCs) at water and wastewater facilities. A PLC is a small industrial computer used to remotely control physical equipment like pumps and valves. In Aliquippa, Pennsylvania that year, the group shut down water pumping equipment. Our 23 July 2026 story "US Agencies Warn That Iranian Hackers Are Targeting Industrial Control Systems Made by Siemens, Schneider Electric, and Rockwell Automation" detailed the specific techniques used against these devices.
| Year | Target | What happened |
|---|---|---|
| 2011-2013 | 46 US banks | Websites knocked offline; tens of millions in costs |
| 2013 | Bowman Avenue Dam, New York | Control system accessed; gate was offline |
| 2014 | Las Vegas Sands Corp | Hard drives wiped; customer data stolen |
| 2016-2021 | Federal agencies, defence contractors | Network intrusions; classified data at risk |
| 2020 | US voter databases | 100,000-plus voter records stolen; threatening emails sent |
| 2021 | Boston Children's Hospital | Attack thwarted by FBI intervention |
| 2023 | Aliquippa, Pennsylvania water system | Pumping equipment shut down |
Many of the targeted PLCs had no password set, or were still running the factory default. That is the failure mode: industrial equipment connected to the internet with the digital equivalent of a door left unlocked.
If you live near any of the affected Minnesota utilities and your water service was disrupted, watch for official notices from your water provider. No evidence has emerged publicly that tap water was made unsafe, but follow guidance from your local utility directly.
The post-mortem will say, as it always does: the device should never have been reachable from the open internet in the first place.



