Full Report
Iranian hackers who recently took credit for an array of attacks on U.S. water systems claimed that they were behind an AT&T outage across major Texas cities on Monday and vowed to “intensify” critical infrastructure attacks in the run-up to Friday’s 25th anniversary of the 9/11 attacks. APT IRAN, which threatened at the end of…
Analysis Summary
# Incident Report: APT IRAN Critical Infrastructure Campaign (Texas)
## Executive Summary
In early September 2026, the Iranian-linked threat group APT IRAN claimed responsibility for a significant telecommunications outage affecting AT&T customers across major Texas cities. The group, associated with the IRGC-linked CyberAv3ngers, also claimed to have breached a Texas water utility as part of a vowed escalation of attacks leading up to the 25th anniversary of 9/11.
## Incident Details
- **Discovery Date:** September 7, 2026 (Labor Day)
- **Incident Date:** September 7–8, 2026
- **Affected Organization:** AT&T; unnamed Texas water utility
- **Sector:** Telecommunications and Water/Wastewater Systems
- **Geography:** Texas, USA (Houston, Dallas, Austin, San Antonio, Fort Worth)
## Timeline of Events
### Initial Access
- **Date/Time:** Sunday, September 6 – Monday, September 7, 2026
- **Vector:** Exploitation of Operational Technology (OT) and critical infrastructure vulnerabilities (specific entry point not disclosed by AT&T).
- **Details:** Reports of service disruptions began Sunday, peaking with a massive surge in outages around noon on Labor Day.
### Lateral Movement
- **Details:** The threat actors released video evidence showing the addition of malicious files ("HACKED_BY_APT_IRAN") to system directories. The video specifically indicated movement or access toward Programmable Logic Controllers (PLCs), as evidenced by a system labeled "PLC1."
### Data Exfiltration/Impact
- **Impact:** Over 7,000 families were placed under "red alert" due to fiber outages; 40% of reports cited 5G home internet failure. The group claims to have simultaneously disrupted water services at a Texas utility.
### Detection & Response
- **Detection:** User reports surged on Downdetector; internal monitoring triggered a "red alert" status for AT&T fiber services.
- **Response actions taken:** AT&T technical teams were deployed to resolve the fiber "interruption." Public statements were issued via social media (X) to acknowledge the outage.
## Attack Methodology
- **Initial Access:** Likely exploitation of internet-facing industrial control systems or telecommunications infrastructure.
- **Persistence:** Addition of files to "programs" directories in target systems.
- **Discovery:** Target identification of specific geographic clusters (Texas cities) and specific infrastructure components (PLCs).
- **Lateral Movement:** Movement from general network access to Operational Technology (OT) environments.
- **Impact:** Denial of Service (DoS) via fiber/telecommunications disruption and potential manipulation of water utility PLCs.
## Impact Assessment
- **Financial:** Significant, given the "red alert" status and the scale of recovery for fiber services across multiple major metropolitan areas.
- **Data Breach:** None reported; focus was on operational disruption.
- **Operational:** Widespread loss of 5G home internet and fiber connectivity for thousands of customers; potential water service disruption.
- **Reputational:** High public visibility due to the timing (Labor Day) and the threat group's public claims on Telegram.
## Indicators of Compromise
- **File indicators:** Files named `HACKED_BY_APT_IRAN` and `HACKED_BY_CyberAv3ngers` placed in system directories.
- **Behavioral indicators:** Unauthorized access to and modification of Programmable Logic Controller (PLC) files.
- **Communication:** Threat group activity via Telegram channel "APT IRAN."
## Response Actions
- **Containment:** AT&T identified the fiber "interruption" and isolated the affected segments.
- **Eradication:** Removal of unauthorized files from system directories (implied).
- **Recovery:** Restoration of service to the Houston, Dallas, Austin, and San Antonio clusters by late Tuesday.
## Lessons Learned
- **OT Security Gap:** The group continues to successfully target PLCs and OT environments, mirroring their previous attacks on Minnesota water systems.
- **Public Warning Signs:** The threat actor provided specific warnings on August 30 regarding "telecommunications" and "energy" that were either unheeded or difficult to defend against.
- **Interconnected Risk:** Disruption in one sector (telecom) coincided with attacks on another (water), indicating a coordinated campaign against regional critical infrastructure.
## Recommendations
- **Asset Hardening:** Ensure all PLCs and industrial controllers are behind firewalls and not accessible via the public internet.
- **Multi-Factor Authentication (MFA):** Enforce strict MFA for all remote access points into utility and telecom management networks.
- **Proactive Hunting:** Organizations in the Energy and Water sectors should hunt for the specific "HACKED_BY..." file strings and review PLC logs for unauthorized modifications.
- **Geopolitical Monitoring:** Increase vigilance and security posture during periods of heightened geopolitical tension (e.g., significant anniversaries like 9/11).