Iran Hackers Claim They Crippled AT&T in Texas: But the Telecom Giant Says It Wasn’t a Cyberattack

Authorities face mounting pressure as digital adversaries threaten widespread infrastructure shutdowns

AT&T Network Security Incident and Hackers Threat
State-sponsored cyber threats escalate as APT IRAN mocks official denials regarding a Texas network blackout AT&T

Iranian hackers have doubled down on claims that they infiltrated critical American infrastructure, firing back after AT&T dismissed their responsibility for a major Labor Day service outage in Texas.

AT&T dismissed the hackers' claim over a widespread network outage in Texas, prompting a swift, mocking retort from the Iran-linked hackers, who insisted the company's leadership remains completely blind to the true scope of their alleged network access.

Iran Hackers Claim Texas Infrastructure Attack

APT IRAN – a group that warned in late August of impending disruptions across three key U.S. infrastructure industries following prior water system breaches – announced on its Telegram channel Tuesday that it claimed responsibility for the holiday network outage alongside an undisclosed utility breach in the Lone Star State.

The Houston Chronicle reported that complaints on Downdetector began climbing sharply over the weekend before a 'massive surge of reported outages' occurred after noon on Labor Day, with the 'largest cluster of outages' coming from the Houston area, followed by Spring, Dallas, Fort Worth, Cypress and Austin, while 'more than 40 per cent of reported outages cited problems tied to 5G home internet.'

APT IRAN, which has been described as closely linked to the Islamic Revolutionary Guard Corps-affiliated CyberAv3ngers, with a history of targeting operational technology, published a statement on its Telegram channel on Tuesday evening Eastern time to claim responsibility for the disruption.

Comment on CyberAv3ngers persona

APT IRAN said in its statement, 'We have attacked telecommunications and other critical infrastructure in Texas, including disrupting AT&T internet service in Houston, Dallas, Austin, and San Antonio, and we have also penetrated a water utility in Texas, disrupting water service.'

The group further declared, 'The American people, you know who is responsible for these disruptions!' and warned that 'Trump's adventures have allowed these attacks to continue and will intensify until September 11th, we will show you what is happening.'

An AT&T spokesman responded that 'we have no evidence to support' the claim made by APT IRAN, adding, 'Our assessment indicates that attempted cable theft led to the outage.' The spokesman also noted that 'internet service across Dallas and surrounding areas is operating normally, and we continue to monitor our network and review relevant information.'

APT IRAN Mocks AT&T Denial

Following the telecom firm's statement on Wednesday afternoon Eastern time, APT IRAN published a Telegram post citing its 4 September message to the U.S.: 'From this moment on, any disruption, disruption or instability in infrastructure, etc., regardless of its scale and duration, must be assessed within the framework of a new phase of confrontation and mutual pressure between the United States and Iran, because the rules of the game have changed.'

The collective added Wednesday, 'Oh yes, we warned on this date, and we are still saying it,' and called it 'ridiculous that a country that claims to own everything in cyberspace is now resorting to lies and honeypots!'

'You know what's the funniest thing?' the hackers asked. 'That those idiots don't even know what we tampered with, what we have access to, and what things were disrupted!'

The recent statement omitted any explicit mention of AT&T or specific targets.

Water Utility Breach Claim Remains Unverified

There have been no known public reports of a recent breach of a Texas water system, though a video from APT IRAN showed 'HACKED_BY_APT_IRAN' and 'HACKED_BY_CyberAv3ngers' injected into an unknown system file with a greyed-out name ending in 'PLC1'.

In April, the Cybersecurity and Infrastructure Security Agency issued an advisory regarding Iranian-affiliated targeting of operational technology, including programmable logic controllers, and updated the advisory in July. Shortly after, the Trump administration announced that Texas would be the first state in a new pilot programme to assist water utilities with cybersecurity.

Iranian Hackers Escalate Threats to U.S. Infrastructure

APT IRAN previously claimed that late-July attacks on water systems in multiple states were conducted merely to 'warn' of wider capabilities, claiming on 23 August that 'whenever America acts arrogantly, we will press the button' across national power, telecom and water grids.

On 30 August, APT IRAN warned on Telegram of 'unexpected and critical events in the energy, water and telecommunications industries', vowing that 'this time we will sew the lips and mouths of the American people together.'

The group renewed threats last week, stating Americans 'will face numerous problems' following a 1 September U.S. airstrike near a wedding in Kuhestak. The Washington Post reported Sunday that the Pentagon was investigating whether a U.S. bomb that missed a nearby target caused the explosion.

The hackers asserted that retaliatory self-defence 'may take the following forms: A few days of no drinking water, disruptions to mobile phone and internet networks, disruptions to energy, gas and electricity infrastructure.'

Iran-linked hacking groups have focused on U.S. infrastructure since the war began, with APT IRAN and Handala previously issuing a joint March threat warning that 'irreparable damages will be inflicted' if threats against Iran's water infrastructure continue.