A series of cyberattacks targeting water systems in seven U.S. states in recent months have been linked to an Iran-affiliated hacking group, cybersecurity experts report. The group, which calls itself the “Cyberav3ngers,” is believed to have launched the assaults shortly after the outbreak of conflict involving Iran earlier this year.

According to cybersecurity firm Tenable, the Cyberav3ngers began posting on dark web forums in the weeks following the escalation, indicating their intent to target U.S. water infrastructure. Chris Day, Tenable’s public sector chief technology officer, said the company started monitoring these activities in April, coinciding with the start of hostilities with Iran. The group has claimed a close association with Iran’s Islamic Revolutionary Guard Corps, a connection echoed in warnings issued by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) on July 22. CISA cautioned that the attacks were likely state-backed and directed at critical infrastructure.

The cyber incidents involved unauthorized access that disabled internet-connected water control systems, affecting over 30 sites in Michigan alone and extending to other states. Hackers removed system administrators’ access and temporarily halted operations such as pumping water into towers. Despite these unauthorized intrusions, officials reported no significant disruptions to public water services, and normal operations were restored quickly. As of now, no group has officially claimed responsibility for the attacks.

Experts remain concerned that the intrusion attempts may continue, given the unclaimed nature of the operations and the ongoing regional tensions. The Cyberav3ngers' continued online presence and prior declarations suggest the possibility of further targeting of U.S. critical infrastructure. U.S. authorities and private sector analysts are monitoring the situation closely to respond to any emerging threats.