Investigators are currently probing whether Iranian hackers are responsible for malicious cyber activity this week targeting water systems across seven U.S. states, including Minnesota. If confirmed, this would not be the first instance of Iranian actors being linked to cyberattacks against the United States.

For over a decade, operators connected to Iran have repeatedly targeted American entities. A decade ago, seven Iranians affiliated with companies linked to the Iranian government and the Islamic Revolutionary Guard Corps (IRGC) were charged with distributed denial-of-service (DDoS) attacks against 46 financial institutions between 2011 and 2013.

In 2024, the Justice Department reported that the State Department, Treasury Department, and multiple defense contractors with access to classified information were also targeted.

Between 2019 and 2021, an actor believed to be linked to Iran hacked an email account belonging to former National Security Advisor John Bolton, according to federal prosecutors in an indictment accusing Bolton of mishandling classified records.

Shortly before the 2020 U.S. election, voters in Florida and several other states received threatening emails purportedly from the far-right Proud Boys, warning them to "vote for Trump or else!" Intelligence officials later attributed these emails to Iran. The U.S. intelligence community assessed that Iran sought to damage the Trump campaign and undermine public confidence but did not attempt to manipulate or attack election infrastructure.

In 2023 and 2024, the CyberAv3ngers, a group affiliated with the IRGC, exploited programmable logic controllers (PLCs), devices commonly used to remotely monitor and control machinery, according to the Cybersecurity and Infrastructure Security Agency (CISA). Prosecutors stated these efforts aimed to sow discord, erode confidence in the electoral process, and gather information to advance IRGC efforts to avenge the 2020 killing of their commander, Qasem Soleimani.

These incidents underscore a pattern of destructive cyberattacks carried out on U.S. soil by nation-state entities, with Iran frequently identified as a key actor.

Sources