An Iranian-linked hacking group says it knocked out AT&T internet service across parts of Texas, but the company attributes Monday’s outage to attempted cable theft, not a cyberattack.
AT&T said a Monday outage that knocked out internet service across parts of Dallas and other Texas cities was caused by attempted cable theft, disputing a claim by an Iranian-linked hacking group that it disrupted the company’s network as part of a broader campaign against U.S. infrastructure.
An Iranian-linked group known as APT Iran, tied to the Islamic Revolutionary Guard Corps and the CyberAv3ngers hacking group, said on Telegram Tuesday that it had targeted telecommunications and other critical infrastructure across Texas, claiming responsibility for disruptions to AT&T internet service in Houston, Dallas, Austin and San Antonio. The group also said it had breached an unnamed Texas water utility and disrupted its services, though no public reports have confirmed a cyberattack against a Texas water system matching that claim.
AT&T said it has no evidence to support the group’s claim and that its assessment indicates the outage was caused by attempted cable theft. The company said internet service across Dallas and surrounding areas is operating normally and that it continues to monitor its network and review relevant information.
The claims followed a surge of outage reports across Texas. DownDetector recorded nearly 1,700 reports shortly after noon Monday, with the largest concentration in Houston, followed by Spring, Dallas, Fort Worth, Cypress and Austin; more than 7,000 households in Dallas were affected. More than 40% of the reports involved 5G home internet, with broadband and WiFi problems accounting for much of the rest. APT Iran’s claim came Tuesday evening, after outage reports had already begun to subside, leading Cybernews researchers to suggest the group may have simply pointed to an existing outage to claim credit. One Cybernews researcher described it as resembling a typical hoax in which Iranian hackers monitor public outage feeds and claim credit for disruptions to capture media attention.
Alongside its statement, APT Iran posted a video showing the phrases “HACKED_BY_APT_IRAN” and “HACKED_BY_CyberAv3ngers” inserted into a system’s program file; the system’s name was obscured, though the visible portion appeared to end with “PLC1,” a term associated with industrial control systems.
APT Iran has grown increasingly vocal about targeting U.S. telecommunications, energy and water systems. At the end of August, the group warned that the U.S. would soon see “unexpected and critical events” affecting those sectors, and it has previously claimed responsibility for attacks on water systems in several states. At the end of March, APT Iran and the affiliated group Handala issued a joint infrastructure threat alongside CyberAv3ngers.
Click Here For The Original Source.
