Iran-Linked Hackers Claim AT&T Texas Outage as Company Blames Cable Theft

Iran-linked APT IRAN claims it caused a major AT&T outage in Texas, while the company says attempted cable theft was responsible.
AT&T logo above a severed fiber-optic cable on a dark blue cybersecurity background with subtle red and blue digital accents.

An Iran-linked hacking group has claimed responsibility for the widespread AT&T outage that disrupted internet service across parts of Texas on Sept. 7, but AT&T says its investigation has found no evidence of a cyberattack and instead points to attempted cable theft.

The group, known as APT IRAN and closely associated with the IRGC-linked CyberAv3ngers, reportedly claimed it targeted telecommunications infrastructure in Texas. It also claimed to have compromised an unidentified water utility in the state, although that separate assertion has not been independently confirmed.

AT&T directly disputed the group’s account. In a statement reported by WFAA, the telecommunications company said it had no evidence supporting the hacking group’s claim and that its assessment indicates attempted cable theft caused the outage.

Thousands reported AT&T service disruptions

The Sept. 7 outage generated thousands of customer reports and affected internet, television and phone services across parts of Texas, with significant disruption reported around Dallas and surrounding communities.

Outage reports peaked at nearly 6,000 shortly before 3 p.m., according to Downdetector data cited by WFAA, before falling rapidly as service recovered. AT&T later said internet service across Dallas and surrounding areas was operating normally and that it continued to monitor its network.

The outage provided an immediate target for APT IRAN’s attribution claim, but the group has not publicly presented technical evidence demonstrating that it accessed AT&T systems or caused the disruption.

Without evidence connecting the hackers to the outage, AT&T’s finding that attempted physical cable theft caused the incident remains the company’s official explanation.

APT IRAN also claims a Texas water utility

Alongside the AT&T assertion, APT IRAN reportedly claimed it had breached an unidentified water utility in Texas. No affected utility was named, and BreachNews has found no public confirmation establishing that a Texas water provider was compromised in connection with the group’s latest statement.

The claim is notable because Iranian-affiliated hackers have been targeting U.S. water infrastructure throughout 2026.

A joint U.S. government cybersecurity advisory warned that Iranian-affiliated actors have targeted internet-connected programmable logic controllers and other operational technology across U.S. critical infrastructure. The activity has affected government facilities, water and wastewater systems, and the energy sector.

The advisory connects similar historical activity to CyberAv3ngers, an actor affiliated with Iran’s Islamic Revolutionary Guard Corps Cyber Electronic Command. U.S. agencies have also identified APT IRAN as one of the names used in connection with this broader Iranian-linked activity.

Claim follows attacks on U.S. water systems

The latest statement follows a wave of confirmed cyberattacks against American water infrastructure this summer.

More than 30 community water systems in Minnesota were targeted during coordinated attacks in late July. The FBI later said water and wastewater organizations in at least 7 states had reported incidents, with some attacks causing operational effects including pressure loss and flooding.

Federal authorities did not publicly attribute those incidents to a specific actor at the time, although the activity shared characteristics with previously documented Iranian-affiliated operations targeting industrial control systems.

APT IRAN subsequently claimed involvement in attacks against U.S. water infrastructure and has issued additional threats involving telecommunications, water and energy systems.

The group has now reportedly threatened to intensify its activity ahead of the Sept. 11 anniversary, making its AT&T attribution part of a broader effort to portray itself as capable of disrupting U.S. critical infrastructure.

No evidence currently ties hackers to AT&T outage

Despite that history, previous Iranian-linked activity against critical infrastructure does not establish that APT IRAN caused the Sept. 7 AT&T disruption.

Threat actors frequently claim responsibility for high-profile outages after they become publicly visible, making technical evidence and victim confirmation particularly important when assessing attribution.

In this case, AT&T has explicitly rejected the group’s explanation and identified attempted cable theft as the apparent cause. The hackers have not publicly produced evidence showing access to AT&T infrastructure or demonstrating a technical mechanism that could have caused the outage.

The alleged compromise of a Texas water utility also remains unverified.

BreachNews will update this report if technical evidence emerges supporting the group’s claims, AT&T changes its assessment, or the unidentified Texas water utility is identified and confirms an intrusion.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site