Minnesota Water Cyberattacks Investigated; Iran Suspected
Authorities are investigating a coordinated cyberattack that targeted operational technology at more than 30 community water systems in Minnesota, with officials warning that Iranian state-backed hackers may be responsible. The attacks took place between Sunday, July 26, and Monday, July 27. State officials said Thursday there were no reports of injuries, water contamination, or loss of service to residents.
According to AP News, Minnesota IT Services said the attacks primarily targeted programmable logic controllers (PLCs) and similar technology that water utilities use to remotely monitor and control equipment. Four cities publicly confirmed impacts: Braham, Plymouth, South St. Paul, and Maple Plain.
Why It Matters
The intrusions come amid the ongoing 2026 U.S.-Iran war, and U.S. investigators have been examining whether the attacks amount to an “act of aggression” by Iranian state-sponsored hackers. The conflict has already drawn retaliatory Iranian cyber operations against U.S. targets this year, including a medical-supplies company and the personal email of FBI Director Kash Patel.
Iran has a documented history of targeting American water infrastructure. In 2016, the Justice Department charged Iranian hackers over a cyberattack on a small dam near New York City. In 2023, actors linked to Iran’s Islamic Revolutionary Guard Corps exploited default passwords on internet-connected controllers at multiple U.S. water and wastewater facilities.
What Happened
The attacks disrupted operations across four Minnesota cities, though none reported water contamination or service loss:
- Braham — The water plant went offline for about two hours Monday morning; residents were asked to minimize water use for a few hours. Officials said attackers shut down operating controls, which shut down the well and treatment plant, but the physical plant and water quality were never compromised.
- Plymouth — Compromised PLCs were found at two water towers and 14 sewer lift stations. The city disconnected the systems from the cellular network and restored communications by Tuesday afternoon; water quality and delivery were never affected.
- South St. Paul — Automated controls for parts of the water utility were affected; staff switched to manual operations and maintained normal service.
- Maple Plain — Certain automated control functions were affected; the mayor declared a local state of emergency, and the water was declared safe.
CBS News reported the FBI has logged incidents in “at least seven states,” with Minnesota the hardest-hit publicly known. State officials said there were no active requests for residents to modify drinking water use as of Thursday.
The Iran Question
Attribution has not been officially confirmed. The FBI declined to publicly name a culprit, and officials stressed that the assessment could change as more technical evidence is collected.
However, The New York Times reported that U.S. and state officials had preliminarily concluded Iranian state-sponsored hackers were “likely” responsible. A leaked WaterISAC memo obtained by WIRED also linked the attacks to Iran, citing a Minnesota Fusion Center alert that found the activity “aligned” with an April CISA-described campaign by Iran-affiliated hackers.
On July 30, CISA, the FBI, and the EPA issued a joint alert warning of a “significant increase” in threat actors targeting PLCs in the Water and Wastewater Systems sector. The activity has resulted in boil-water notices and sustained manual operations in some cases. Acting CISA Director Nick Anderson urged operators to “remove publicly exposed PLCs and other operational technology from the internet as soon as possible,” according to CISA.
Political Fallout
President Donald Trump on Friday dismissed the Iran assessment, saying at a Cabinet meeting at Camp David that he believes Minnesota and Gov. Tim Walz are to blame. “I think that Minnesota is behind it. You know who’s behind it? Minnesota. Because they’re grossly incompetent,” Trump said, according to CBS News.
Walz responded on social media that Trump “knows exactly who is responsible for this attack, and knows that other states were hit too,” adding that DOGE “took an axe to CISA” and that “this is what modern warfare looks like.”
Cybersecurity experts have pointed to Iran’s capabilities and motives. Cynthia Kaiser, former deputy assistant director of the FBI’s cyber division, told AP News: “I think most credible researchers and responders would be right to treat it like it’s Iran until proven otherwise.” Joe Slowik, a former Los Alamos National Labs researcher, told WIRED that the scale of the campaign “should really be making people concerned right now.”
What’s Next
The investigation remains ongoing, and officials caution that attribution could change. Utilities across the country face the same vulnerabilities, and analysts warn that similar internet-connected controllers remain exposed.
CISA is advising water systems to disconnect PLCs from the internet, use VPNs for remote access, change default passwords, and maintain clean backups. Local officials, meanwhile, say the episode highlights chronic underinvestment in water-utility cybersecurity — costs that may ultimately appear in higher water bills.
The attacks may be the widest and most disruptive Iranian hacking strike against the United States since the war began, and a reminder that civilian infrastructure has become a front line in modern conflict. The next few weeks will show whether investigators can confirm the source — and whether the nation’s water systems can be hardened before another strike.