Iran-backed hackers likely behind attack that shut down Minnesota water plant — and they’re not done yet See more of our coverage in your search results.
Claims checked13
Techniques found3
Topics3
Coverage spectrum
Coverage gap: Low Left coverage
Left0%
Center80%
Right20%
5 sources compared across this story cluster. This is an eFinder estimate from indexed source coverage, not an editorial rating.
What happened
Iran-backed hackers likely behind attack that shut down Minnesota water plant — and they’re not done yet See more of our coverage in your search results.
Why it matters
Add The New York Post on Google A notorious Iran-linked hacker group was likely behind the recent attacks on dozens of water systems across the US — and the shadowy cyber-soldiers may not be done with their assault, experts warned.
Common ground
The self-proclaimed “Cyberav3ngers” group appeared to carry out the attacks which hit seven states in recent months, according to cybersecurity company Tenable, which told The Post the devious group began posting on the dark web about plans to hit the US…
Perspective signals
The tension in the story is sharpened by Loaded Language, Name Calling / Labeling, Appeal to Fear: language that can make the dispute feel more urgent, personal, or adversarial than the underlying facts alone.
Follow-up questions
What terms are actually in the Iran proposal, and which side would have to compromise first?
What evidence would most clearly confirm or weaken the claim that hackers could have gained access to systems which control and monitor the dosage of possibly dangerous chemicals in local water supplies?
How does this story connect Domestic Political Conflict with US-Iran relations over the next few days?
eFinder identified 3 propaganda techniques in this article. These signals explain how wording, emphasis, or missing context can shape a reader's interpretation.
Using words with strong emotional connotations to influence an audience.
Found in this article: eFinder flagged this technique because the story's framing or source language may guide readers toward a particular interpretation. Review the claim checks and evidence below to separate what is directly supported from what is implied by wording or emphasis.
Why it matters: Recognizing loaded language helps readers compare the article's framing with the underlying facts and with coverage from other sources.
Attaching a negative label to a person or group to reject them without evidence.
Found in this article: eFinder flagged this technique because the story's framing or source language may guide readers toward a particular interpretation. Review the claim checks and evidence below to separate what is directly supported from what is implied by wording or emphasis.
Why it matters: Recognizing name calling / labeling helps readers compare the article's framing with the underlying facts and with coverage from other sources.
Building support by instilling anxiety or panic in the audience.
Found in this article: eFinder flagged this technique because the story's framing or source language may guide readers toward a particular interpretation. Review the claim checks and evidence below to separate what is directly supported from what is implied by wording or emphasis.
Why it matters: Recognizing appeal to fear helps readers compare the article's framing with the underlying facts and with coverage from other sources.
fact_checkClaims Checked
eFinder analyzed this article and checked 13 claims against available evidence, cross-references, web search, and Wikipedia. Here is what the fact-checking layer found.
check_circleCorroborated7
schedulePending3
helpInsufficient Evidence1
infoSingle Source1
verifiedVerified1
help
Claim 1: “hackers could have gained access to systems which control and monitor the dosage of possibly dangerous chemicals in local water supplies”
INSUFFICIENT EVIDENCE
No evidence was provided in the search results to confirm or deny if hackers specifically gained access to chemical dosage controls in these specific attacks, although a separate incident in Florida is mentioned.
check_circle
Claim 2: “the US Cybersecurity and Infrastructure Security Agency (CISA) also warning on July 22 that the Cyberav3ngers — and by proxy Iran — were likely targeting US systems”
CORROBORATED
Web search results confirm that on July 22, CISA and other federal agencies issued an advisory warning about Iranian-backed hackers (specifically naming the threat actor) targeting water system controls.
menu_book
wikipedia
NEUTRAL
— The Rewards for Justice Program (RFJ) is the United States' national security interagency program that offers reward for information leading to the location or an arrest of leaders of terrorist groups…
https://en.wikipedia.org/wiki/Rewards_for_Justice_Program
travel_explore
web search
NEUTRAL
— Despite CISA and Tenable fingering the Cyberav3ngers as the likely culprit, the situation was cast into confusion Friday after President Trump denied any Iranian involvement — and instead blamed Minne…
https://dnyuz.com/2026/08/04/iran-backed-hackers-likely-behi…
travel_explore
web search
NEUTRAL
— What is confirmed. Between Sunday, July 26 and Monday, July 27, more than 30 community water and wastewater systems across Minnesota were targeted in what Minnesota IT Services has described as a coor…
https://www.linkedin.com/pulse/community-advisory-coordinate…
+ 1 more evidence source
check_circle
Claim 3: “the group has long-proclaimed itself to be closely tied to Iran’s brutal Islamic Revolutionary Guard Corps (IRGC)”
CORROBORATED
Both MITRE ATT&CK and FortiGuard Labs explicitly state that CyberAv3ngers are affiliated with or an arm of the Iranian Government's Islamic Revolutionary Guard Corps (IRGC).
menu_book
wikipedia
NEUTRAL
— The Rewards for Justice Program (RFJ) is the United States' national security interagency program that offers reward for information leading to the location or an arrest of leaders of terrorist groups…
https://en.wikipedia.org/wiki/Rewards_for_Justice_Program
travel_explore
web search
NEUTRAL
— The CyberAv3ngers are a suspected Iranian Government Islamic Revolutionary Guard Corps (IRGC)-affiliated APT group. The CyberAv3ngers have been known to be active since at least 2020, with disputed an…
https://attack.mitre.org/groups/G1027/
travel_explore
web search
NEUTRAL
— Summary Note: This updated joint Cybersecurity Advisory reflects new investigative and analytic insights for network defenders on malicious cyber activities conducted by advanced persistent threat (AP…
https://www.cisa.gov/news-events/cybersecurity-advisories/aa…
+ 1 more evidence source
check_circle
Claim 4: “The self-proclaimed “Cyberav3ngers” group appeared to carry out the attacks which hit seven states in recent months”
CORROBORATED
Multiple sources report that attacks hit at least seven US states and link the activity to the 'Cyberav3ngers' or Iranian-linked actors.
travel_explore
web search
NEUTRAL
— Cyberattacks targeting water and wastewater facilities in at least seven US states appear to have been intended less to cripple infrastructure than to demonstrate Iranian reach, intimidate the public …
https://www.iranintl.com/en/202608056777
travel_explore
web search
NEUTRAL
— Cyberattacks on municipal water systems were reported in at least seven states this week, according to a joint public service announcement from the FBI and the Environmental Protection Agency – and in…
https://www.alexjoneslive.com/2026/08/02/water-system-hacks-…
travel_explore
web search
NEUTRAL
— Georgia and Michigan have become the latest US states to report cyberattacks targeting water systems, as federal authorities investigate a wave of intrusions affecting utilities across at least seven …
https://www.computing.co.uk/news/2026/security/georgia-and-m…
info
Claim 5: “the devious group began posting on the dark web about plans to hit the US within weeks of war breaking out with Iran”
SINGLE SOURCE
While evidence confirms the group's existence and attacks on water systems, the specific claim about posting on the dark web regarding plans to hit the US 'within weeks of war breaking out' is not explicitly detailed in the provided evidence.
web search
NEUTRAL
— Following CyberAv3ngers’ late 2023 hacking campaign, and missile launches against Israel by Iranian-backed Houthi rebels, Predatory Sparrow retaliated again by knocking out thousands of Iran's gas sta…
https://www.wired.com/story/cyberav3ngers-iran-hacking-water…
schedule
Claim 6: “President Trump denied any Iranian involvement — and instead blamed Minnesota’s “corrupt” Gov. Tim Walz”
PENDING
This claim was extracted as a checkable statement from the article. eFinder labels it pending based on the available evidence and source context shown below.
check_circle
Claim 7: “No significant disruptions or harm came from the attacks and order was quickly restored at all sites”
CORROBORATED
IBTimes UK reports that no water contamination occurred, and other sources mention that while operations were disrupted, the primary goal appeared to be demonstration of reach rather than crippling infrastructure.
travel_explore
web search
NEUTRAL
— Cyberattacks on water systems can lead to severe operational disruptions, including flooding or contaminated water supplies. Such incidents threaten public health and safety, prompting facilities to s…
https://www.theedadvocate.org/sinister-water-attacks-this-is…
travel_explore
web search
NEUTRAL
— Most local water systems are operated by local authorities, don’t have a dedicated IT team, and lack the money or resources to thoroughly protect themselves without some extra help. Hackers know this,…
https://www.vox.com/future-perfect/498156/cyberattack-iran-w…
travel_explore
web search
NEUTRAL
— Cyberattacks Target US Drinking Water Systems. Hackers have targeted water and wastewater utilities across at least 12 US states, prompting some small-town operators to disconnect vulnerable equipment…
https://www.ibtimes.co.uk/hackers-target-drinking-water-syst…
verified
Claim 8: “The group has been around since at least 2020”
VERIFIED
The MITRE ATT&CK reference explicitly states that the CyberAv3ngers have been known to be active since at least 2020.
menu_book
wikipedia
NEUTRAL
— The Rewards for Justice Program (RFJ) is the United States' national security interagency program that offers reward for information leading to the location or an arrest of leaders of terrorist groups…
https://en.wikipedia.org/wiki/Rewards_for_Justice_Program
schedule
Claim 9: “typically targets infrastructure systems within Iran’s enemies in the Middle East”
PENDING
This claim was extracted as a checkable statement from the article. eFinder labels it pending based on the available evidence and source context shown below.
check_circle
Claim 10: “hackers, who booted administrators and prevented water from being pumped into systems like water towers”
CORROBORATED
Multiple sources confirm that hackers locked out administrators and prevented water from being pumped into systems such as water towers.
travel_explore
web search
NEUTRAL
— News and popular culture portray hackers variously as criminals, cyberterrorists, socially isolated technical prodigies, activists, defenders, and security professionals.
https://en.wikipedia.org/wiki/Hacker
travel_explore
web search
NEUTRAL
— Hackers is a 1995 American crime thriller film directed by Iain Softley and starring Jonny Lee Miller, Angelina Jolie, Fisher Stevens, and Lorraine Bracco, with Jesse Bradford, Matthew Lillard, Lauren…
https://en.wikipedia.org/wiki/Hackers_(film)
travel_explore
web search
NEUTRAL
— Sep 15, 1995 · Hackers: Directed by Iain Softley. With Jonny Lee Miller, Angelina Jolie, Jesse Bradford, Matthew Lillard. Teenage hackers discover a criminal conspiracy with plans to use a computer vi…
https://www.imdb.com/title/tt0113243/
check_circle
Claim 11: “A notorious Iran-linked hacker group was likely behind the recent attacks on dozens of water systems across the US”
CORROBORATED
Multiple independent web search results confirm that Iranian-linked hackers are suspected of targeting drinking water systems across several US states.
travel_explore
web search
NEUTRAL
— Iranian-linked hackers are suspected of targeting drinking water systems in at least seven states, forcing some communities to switch to manual operations and issue boil-water notices.
https://www.linkedin.com/posts/aipac_iranian-linked-hackers-…
web search
NEUTRAL
— Pro-Iran hackers have disrupted some industrial-control systems, US says. Others agreed that, given how vulnerable OT is, these attacks highlight massive weaknesses in systems, and they warned of the …
https://www.route-fifty.com/cybersecurity/2026/08/more-us-wa…
schedule
Claim 12: “water systems being hit in Pennsylvania during a spate of attacks from Oct. 2023 to Jan. 2024”
PENDING
This claim was extracted as a checkable statement from the article. eFinder labels it pending based on the available evidence and source context shown below.
check_circle
Claim 13: “Those attacks resulted in dozens of internet-connected water control systems — over 30 in Michigan alone — being taken over by hackers”
CORROBORATED
Two independent web search results explicitly state that over 30 internet-connected water control systems in Michigan alone were taken over by hackers.
menu_book
wikipedia
NEUTRAL
— On February 11, 2013, the Emergency Alert System (EAS) of five different television stations across the U.S. states of Montana, Michigan, Wisconsin, and New Mexico were hijacked, interrupting each tel…
https://en.wikipedia.org/wiki/2013_Emergency_Alert_System_hi…
menu_book
wikipedia
NEUTRAL
— Hacker-Craft is the name given to boats built by The Hacker Boat Co., an American manufacturer founded in Detroit, Michigan, in 1908 by John L. Hacker (1877–1961). It is one of the oldest constructor…
https://en.wikipedia.org/wiki/Hacker-Craft
menu_book
wikipedia
NEUTRAL
— The Handala Hack Team is a hacktivist group supposedly operating from Iran that runs cyberattacks against U.S. and Israeli organizations. It has released personal documents and emails from thousands o…
https://en.wikipedia.org/wiki/Handala_Hack_Team
+ 3 more evidence sources
infoDisclaimer: This analysis is generated by AI and should be used as a starting point for critical thinking, not as definitive truth. Claims are verified against publicly available sources. Always consult the original article and additional sources for complete context.