What We Actually Know About Iranian Cyber Activity Against U.S. Targets in 2026
Water systems. Fuel tanks. A medical device maker. This week, AT&T in North Texas. The headlines run together and the numbers get repeated without anyone showing where they came from.
Start with AT&T, because this is how a claim becomes a fact. A group calling itself APT IRAN posted on Telegram that it took down AT&T service in four Texas cities on September 7. AT&T said it has no evidence to support that and its investigation points to attempted cable theft. The same group claimed it disrupted an unnamed Texas water utility. Nobody has verified that either. Sources: Dallas Morning News, Threat Beat
Those qualifications belong next to the claims. Leave them out and you are helping the actor tell its story.
Being careful about attribution does not make the scale disappear. In July, CISA saw malicious activity against more than 100 internet exposed systems in the water sector. Researchers suspected Iran. CISA did not publicly attribute it. A timeline that collapses all of that into one line item makes a broad campaign look like one incident. Source: The Register
There is no authoritative public total of Iranian attacks on the United States in 2026. That does not mean the number is small. It means people are counting the wrong things. A campaign can hit dozens of organizations. One company can have thousands of affected devices. An advisory revised in July is still one advisory. When a company, a campaign, an advisory, and a Telegram post all count as one entry each, the total tells you nothing about damage or reach.
The CSIS master list is the source most people start with. It runs through June and applies a significance threshold. It is a selective chronology, not a victim census. CSIS’s separate August water sector analysis describes a much larger set of targets that the master list would never show you. Sources: CSIS Significant Cyber Incidents, CSIS water sector analysis
The timeline
The table separates when activity happened from when it became public. The count column gives the number the public record actually supports, with its unit. Where no defensible count exists, it says unknown. Unknown is not zero. Entries overlap across months. Do not sum them.
| Month | Activity or disclosure | Defensible count | Scale and limits |
|---|---|---|---|
| February | Seedworm (MuddyWater) active on U.S. networks from early February. Broadcom disclosed March 5. | 3 U.S. networks | Three U.S. networks described: a bank, an airport, a nonprofit. Researcher attribution. Same campaign as the March entry. Broadcom |
| March | Seedworm disclosure. Stryker wiper attack. FBI Director Patel personal email disclosure. PLC campaign later dated to at least March. | 1 company disrupted. 1 personal account. PLC victims unknown. | Stryker is one company with broad business disruption. Patel is one personal account, not an FBI network breach. PLC victim total unknown. Stryker, Patel, AA26-097A |
| April | St. Joseph County, Indiana responds to Handala claim. AA26-097A published April 7. | 1 county, via a third party vendor. Advisory adds no count. | County confirmed an incident at an external fax service and disputed the claimed scope. The advisory describes a multi-sector campaign with no unique victim count. County, AA26-097A |
| May | CSIS reports suspected Iranian manipulation of gas station tank gauges. | Unknown. Multiple stations, several states. | Multiple stations across several states. No exact count. The concern was false readings hiding leaks. I could not find the underlying official disclosure. CSIS |
| June | Handala claims California Water Service breach. | 1 utility. Data exposure confirmed, control not. | One named utility. Dataminr corroborated exposed customer data and access to a GPS correction service. No evidence of control over treatment or distribution. Dataminr |
| July | Water system intrusions. FBI/EPA warning July 30. AA26-097A revised July 22. | 100+ systems targeted. Intrusions in 7+ states. Confirmed Iranian breaches unknown. | More than 100 exposed water sector systems targeted, per CISA figures reported in August. Targeting volume, not confirmed breaches. FBI/EPA, The Register |
| August | Expanded reporting on July water campaign. Siemens controller advisory August 19. DOJ Mabna Institute charges August 18. | 0 new confirmed victims. 1 technical advisory, no Iran attribution. | No defensible count of newly breached organizations. The Siemens advisory does not name Iran. The Mabna case is a 2013 to 2017 university campaign with new defendants added; its 144 university figure is historical and does not belong on this timeline. CSIS, Siemens advisory, DOJ |
| September 1 to 10 | APT IRAN claims AT&T outage and a Texas water utility. | 0 confirmed. 2 claimed. | Two claims. AT&T disputes one. The other is unverified. Neither is an established attack. Dallas Morning News |
A newly identified victim can belong to an existing campaign. A March disclosure can describe access gained in February. An August story can expand what we know about July. A technical advisory can add evidence without adding a victim. The publication date alone cannot tell you which is which.
Three parts of this record deserve a closer look.
The water campaign
This is where the counting gets worst, because there are at least four different units in play and they get mixed constantly.
The July 30 FBI/EPA warning documented intrusions affecting water systems in at least seven states, with consequences including loss of pressure and flooding. It did not name Iran. Source: FBI/EPA warning
CSIS’s August 18 mapping found nine states that publicly confirmed targeting and located 55 facilities out of reports of at least 100 nationwide. Wider reporting put it at 12 states. CSIS said disclosures were incomplete. Those are mapping and targeting numbers, not verified Iranian breaches. CSIS also reported that hackers shut down a Georgia pump station, dropped water pressure, and triggered a boil water advisory. No illnesses. That supports a physical service disruption and a contamination precaution. It does not support the word poisoned. Source: CSIS water sector analysis
The August 19 Siemens advisory describes active reconnaissance and capability development using AI-generated scripts disguised as monitoring tools, across manufacturing, energy, water, chemical, food and agriculture, and commercial facilities. It does not name Iran and does not add a breached victim. It belongs in the defensive picture with that gap visible. Source: Siemens advisory
Systems, facilities, states, and successful intrusions are different things. Report them with their definitions or do not report them.
The PLC advisory
AA26-097A is the strongest federal attribution in the OT record. Published April 7, revised July 22, it describes Iranian affiliated actors going after internet exposed programmable logic controllers across U.S. critical infrastructure since at least March. The original named Rockwell Automation Allen-Bradley equipment. The revision added other controller families. At one victim, a malicious project file changed controller logic that governed safe operation. That is a physical process risk, stated by the federal government, with Iran named. Source: AA26-097A
Unit 42 ties its late March Rockwell cluster, CL-STA-1128, to CyberAv3ngers. Its separate finding of Rockwell or Allen-Bradley equipment exposed on 5,600 IP addresses is global visibility data. It is not 5,600 compromised U.S. organizations, and I have seen it repeated that way. Source: Unit 42
Stryker and Handala
Stryker is the clearest business disruption in the set. The company disclosed the incident March 11 and confirmed disruption to order processing, manufacturing, and shipping. It said connected medical products and patient services were unaffected. Source: Reuters
Handala claimed it wiped more than 200,000 devices across 79 countries and stole 50 terabytes. Those are the attacker’s numbers. Reporting described abuse of Microsoft Intune’s legitimate remote wipe. The record supports calling this a destructive attack. It does not support repeating the attacker’s inventory as fact. Source: KrebsOnSecurity
The attribution goes past researchers. On March 19, DOJ announced seizure of domains it said Iran’s Ministry of Intelligence and Security used, including Handala’s site, and discussed the March 11 claim against a U.S. medical technology company by name. That is a government basis for linking Handala to MOIS. It does not validate every device count. Source: DOJ
This one is ours. We sent a TLP:AMBER report to subscribers on March 6 documenting infrastructure and operational artifacts we assessed as Iranian, including targeting and access activity. The public version followed March 14. The subscriber release was five days before Stryker went down. Sources: public technical report, distribution chronology
I will apply my own rule here. We saw the server. We did not see inside Stryker. Nothing public establishes that the infrastructure we documented enabled that specific attack. The dates are what they are, and so is the scope of the evidence.
Our Handala and Stryker detection pack and v2 update turn that research into hunts you can run against your own telemetry. Test the rules. Confirm the logs exist. Find out what your team can actually do when one fires.
Keep the names straight
CyberAv3ngers is associated with the IRGC Cyber Electronic Command. Handala and Seedworm are associated with MOIS. APT IRAN is a persona that reporting links to CyberAv3ngers. Shared branding and a Telegram post do not tell you who caused an outage. Attribution follows the evidence for the specific event, every time. Sources: AA26-097A, DOJ, Broadcom, Threat Beat
What to do with this
If you run OT, the work is concrete. Find every PLC, HMI, and tank gauge reachable from the public internet. Remove the direct exposure. Put remote access behind a controlled gateway. Replace default credentials. Restrict who can push changes. Monitor controller logic and configuration. Have a tested way to run the process and recover when remote visibility disappears. Source: federal mitigation guidance
Stryker is a different problem and most people are skipping it. The tool that did the damage was not malware. It was an approved management platform doing exactly what it was built to do, on the wrong instruction. Review who can wipe devices, change roles, and control your endpoint management. Log those actions. Alert on them. Test the response while you still have an environment to test in.
Related
- Stryker, Handala, MOIS, and MuddyWater: The Full Kill Chain and the Unified Detection Pack (v3) (April 16, 2026)
- CISA Got It Partially Right. Here’s What They Missed. (March 19, 2026)
- The Setup Was Already in Your Logs (March 14, 2026)
- Iranian Threat Actor: Tools, Techniques, IOCs, and IOAs (March 14, 2026)
- Handala Detection Pack v2: Pre-Positioning, PIM Gap, and Bulk Wipe Controls (March 14, 2026)
- Iran-Linked Handala Wipes 56,000-Employee Medical Device Giant (March 12, 2026)
ThreatHunter.ai published a TLP:AMBER intelligence report on March 6, 2026 documenting an exposed Iranian operational server showing pre-positioning and scanning activity five days before the Stryker wipe. Full IOCs and technical details are available to subscribers. Contact us for access.