Back threatbeat.com Iran Hackers Minnesota Warning Ignored Critical Events To Hit 3 U S Infrastructure Sectors
Iranian hackers who claimed responsibility for attacks on a swath of municipal water systems across the United States at the end of July warned Sunday that “critical events” will hit three critical infrastructure sectors.
APT IRAN, which is closely linked to the Islamic Revolutionary Guard Corps-affiliated CyberAv3ngers and has previously focused on operational technology targets, claimed in a mid-August statement that the hacks on dozens of communities were conducted “only to warn” of their broader capabilities to strike U.S. critical infrastructure.
In a new statement posted on their Telegram channel Sunday, the group declared, “Soon, the United States will witness unexpected and critical events in the energy, water, and telecommunications industries.”
“We had previously warned that anyone who encroaches on this soil and threatens our beloved Iran will pay for this mistake with their lives,” APT IRAN continued. “You ignored our warnings, and we in Minnesota warned you again. You ignored them again; but this time we will sew the lips and mouths of the American people together.”
In their earlier claim of responsibility, APT IRAN stated that “our intention in attacking Minnesota was only to warn.”
“The infrastructure of electricity, telecommunications, water, and anywhere in America that you think is under our control, and whenever America acts arrogantly, we will press the button,” the group had added.
That statement did not mention any other of the dozen states reporting recent cyberattacks on water systems around the time of the July 26-27 Minnesota attacks.
In an Aug. 23 statement , APT IRAN said that those attacks targeted Minnesota, Michigan, Georgia, New Jersey, South Dakota and Arkansas.
The broader context for the claim was an Aug. 22 Telegraph report that blamed Iran for forcing a small power plant in the UK to shut down for four days last month. A UK government spokesperson told CNBC that the report “refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system.” The facility was not named, nor did the government assess blame for the reported outage.
“No attack has been carried out by us against Britain,” APT IRAN claimed in their statement, adding that “if any action is taken by us, we will certainly accept responsibility for it.”
“We emphasize that we have only attacked the United States, and contrary to the figures and numbers that have been published, only six states were affected by our attack — no more, no less,” the group added.
On July 30, the FBI and EPA said in a joint announcement to critical infrastructure owners and operators that waters systems “in at least seven states” had reported incidents to the FBI since July 27, and “some of that activity degraded water operations.” On Aug. 4, ABC News reported that “possible cyber intrusions targeting water and wastewater utilities have now been reported in at least a dozen states,” with Iran as the “prime suspect” in the attacks.
At the end of March, APT IRAN and Handala, which is also affiliated with the IRGC, issued a unified infrastructure threat in conjunction with CyberAv3ngers.
“ experience has shown that this warning is testable and incidents have occurred in the past for the water infrastructure of the United States,” APT IRAN said in a March 27 post on the group’s Telegram channel. “Therefore, it is emphasized to refrain from threatening the water infrastructure of Iran.”
“If this warning is not heeded, irreparable damages will be inflicted on the other side,” it concluded.
After an April cessation in kinetic hostilities was announced in the United States’ conflict with Iran, Handala similarly dialed back its mounting public threats against critical infrastructure and declared that it had “currently postponed overt confrontation” with the United States per “highest leadership” orders. But as the ceasefire collapsed and strikes resumed, Handala circled back to ominous critical infrastructure threats. On July 16, the group posted on its Telegram channel an image of various critical infrastructure sectors — pumps at a gas station , an aisle at a supermarket, an electricity substation and a water treatment facility — accompanied by the text “YOU WILL REALIZE.”
In a statement posted today, the group claimed that “all Handala members are alive and well, and when the time is right, details of our extensive recent operations will be made public.”
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
