ICNA

Iranian Cyber News Agency

Attack Cyber

Gorz Rostam Hacking Group Targeted US Water Infrastructure

The cyber arena has witnessed a surge of activity from a group known as “Gorz Rostam.” This group, a politically motivated pro Iran cyber actor, has made itself known in the cyber space through a series of global attacks and strategic data leaks.

On September 6th, 2026, the group announced via its official Telegram channel that it had launched a denial-of-service attack (DDoS) against US water infrastructure. The group specifically claimed to have attached Veoila, a North American water, energy and waste management company, and the American Water Works Association (AWWA), potentially disrupting data flow or access to critical water management systems.

Who is Gorz Rostam?

Gorz Rostam, or “Rostam’s mace” is an Iran affiliated group that presents itself as part of a broad and coordinated campaign. They use their Telegram channel, created on March 19th of this year which currently has 1272 subscribers, to announce their activities to the world.

It may be interesting to note that the group’s recent activities include several other attacks. On September 2nd, they claimed to have leaked 36 databases from Taiwan, covering judicial, educational and financial sectors.

Operation Seven Stages: Data obtained from the dark web shows that in June 2024, the group targeted the banking sectors of UAE and Bahrain. The attack was part of a seven stage operation the group has named “Haft Khan”, which was officially announced on August 14th. According to cybersecurity experts at “Brinztech”, the group also targeted Israeli companies, claiming it was part of the same anti-government campaign.

While Gorz Rostam appears to have a successful track record – including a confirmed DDoS attack on the Helekat.com website – experts have pointed out that their claims have not yet been officially verified. Since they rely heavily on Telegram to announce news, some analysts believe there is currently insufficient technical evidence to confirm the groups claims.

Furthermore, the group Gorz Rostam claims to operate a marketplace and a social forum on its dark web site. They are currently claiming to sell information about the structural design of the BGM 109 Tomahawk cruise missile and a collection of databases.

Whether Gorz Rostam is an independent team or a part of a larger cyber group in Iran, it has proven itself to be a persistent threat. From targeting US water systems to Israeli companies and Taiwanese databases, they have shown that they can strike any sector in the world to achieve their political goals.

LEAVE A RESPONSE

Your email address will not be published. Required fields are marked *