A Decade of Iranian Cyberattacks on America: What We Know
From wiping casino hard drives to targeting children's hospitals, a pattern of disruptive attacks tied to Iran stretches back more than a decade. Now investigators are asking whether the same playbook was used against water systems in seven US states.

Key points
- Investigators are examining whether Iranian hackers attacked water systems in seven US states, including Minnesota, in an incident reported this week.
- Iranian-linked groups have been formally charged by the US Justice Department with cyberattacks on at least 46 US financial institutions between 2011 and 2013.
- In 2023, a group calling itself CyberAv3ngers, affiliated with Iran's Revolutionary Guard, successfully shut down water pumping equipment in Aliquippa, Pennsylvania.
- A 2014 attack on Las Vegas Sands Corp wiped hard drives and exposed the personal data of tens of thousands of customers, including Social Security numbers.
- Iran has consistently denied involvement in cyberattacks, and official attribution can take weeks or months to confirm.
Something hit water utilities across seven US states this week. Investigators are now looking at whether Iran was behind it, and whether whoever did this may have deliberately made the attack look Iranian to stir up tensions during the current US-Iran standoff. That second possibility matters. Attribution, meaning the process of proving who actually carried out a cyberattack, is hard and slow.
But if it does point back to Iran, it would be the latest chapter in a long-running story.
What has Iran actually done before?
Quite a lot, and the record is documented in federal indictments, not just intelligence assessments.
Between 2011 and 2013, seven Iranians working for companies tied to the Iranian government and the Islamic Revolutionary Guard Corps, a branch of Iran's military, were charged with carrying out distributed denial-of-service attacks, meaning coordinated floods of fake internet traffic designed to knock websites offline, against 46 US banks. Customers could not access their accounts. Remediation costs ran into the tens of millions of dollars across the affected institutions.
The same indictment charged one defendant with accessing the control system for a dam in Rye, New York. The attacker could see operational data, though the gate controlling water flow happened to be offline for maintenance at the time.
In 2014, Las Vegas Sands Corp had its hard drives wiped, its corporate network damaged, and its hotel websites defaced. Then-Director of National Intelligence James Clapper told Congress it was the first "destructive cyberattack carried out on US soil by nation-state entities." Tens of thousands of customer records, including Social Security and driver's licence numbers, were stolen.
What about attacks closer to everyday life?
Plenty of them touched ordinary Americans directly.
From 2017 to 2024, a group of Iranian government-linked hackers known by names including Pioneer Kitten broke into schools, local governments, hospitals and financial institutions. In some cases, they sold that access to ransomware groups, meaning criminal gangs who lock a victim's computer files and demand payment to restore them. The FBI and CISA, which stands for the Cybersecurity and Infrastructure Security Agency and is the US government's main civilian cyber defence body, both issued warnings about this campaign.
Before the 2020 election, Iranian operatives downloaded the personal data of more than 100,000 voters from a misconfigured state website, meaning a system that had been set up with settings that accidentally left it open to outsiders. They then sent threatening emails to tens of thousands of registered Democrats, posing as the far-right Proud Boys group. The FBI also linked Iran to a website called "Enemies of the People" that published death threats against US election officials.
In 2021, the FBI helped stop an attack on Boston Children's Hospital. Former FBI Director Christopher Wray called it "one of the most despicable cyberattacks I've seen."
How does this week's water incident fit the pattern?
It fits closely. From 2023 onwards, a group calling itself CyberAv3ngers, affiliated with the Revolutionary Guard, targeted programmable logic controllers (PLCs) at water and wastewater facilities. A PLC is a small industrial computer used to remotely control physical equipment like pumps and valves. In Aliquippa, Pennsylvania in 2023, the group successfully shut down water pumping equipment.
| Year | Target | What happened |
|---|---|---|
| 2011-2013 | 46 US banks | Websites knocked offline; tens of millions in costs |
| 2013 | Bowman Avenue Dam, New York | Control system accessed; gate was offline |
| 2014 | Las Vegas Sands Corp | Hard drives wiped; customer data stolen |
| 2020 | US voter databases | 100,000+ voter records stolen; threatening emails sent |
| 2021 | Boston Children's Hospital | Attack thwarted by FBI intervention |
| 2023 | Aliquippa, Pennsylvania water system | Pumping equipment shut down |
Many of the targeted PLCs had no password set, or were still running the factory default password. That is the failure mode here: industrial equipment connected to the internet with the digital equivalent of a door left unlocked.
If you live near any of the affected Minnesota utilities and your water service was disrupted, watch for any official notices from your water provider. No evidence has emerged publicly that tap water was made unsafe, but follow guidance from your local utility directly.
One thing the post-mortem will say, as it always does: the device should never have been reachable from the open internet in the first place.



