Sunday, August 23, 2026

FBI Probes Water System Cyberattacks in Michigan, Minnesota

Valyrian News Network 6 min read

FBI Probes Water System Cyberattacks in Michigan, Minnesota

The FBI is investigating after Michigan joined Minnesota in reporting cyberattacks on water systems, raising urgent concerns about the vulnerability of America’s critical infrastructure to state-sponsored cyber threats. Michigan reported intrusions on nine of its water systems on Saturday, days after Minnesota disclosed that more than 30 of its municipal water systems had been targeted in a coordinated attack.

According to AP News, the attacks came amid federal warnings that Iranian hackers have been focused on water and wastewater systems across the United States. The FBI, Cybersecurity and Infrastructure Security Agency (CISA), and other federal agencies issued an advisory last week warning that Iranian hackers have been targeting operational technology at water systems and other critical infrastructure sectors.

Coordinated Attacks Across Multiple States

The attacks in Minnesota occurred July 26-27, targeting operational technology at community water systems. Cities including Braham, Plymouth, South St. Paul, and Maple Plain publicly confirmed they were affected. In Braham, a city of about 1,700 people located roughly 70 miles north of Minneapolis, the water plant went offline for several hours as officials worked to determine the cause.

The Register reported that Georgia also confirmed it was affected by the attacks, though damage was limited. Rapid City, South Dakota, confirmed a cyber incident involving one of its lift stations used in the wastewater system. Wisconsin issued a bulletin saying intelligence officials believed systems within the state may be susceptible to connections from malicious cyber actors.

The FBI advisory stated that since July 27, Water and Wastewater Sector utility companies in at least seven states have reported incidents to the bureau, and some of that activity degraded water operations. The attacks targeted Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), specifically exploiting CVE-2021-22681, an authentication bypass with a CVSS score of 9.8 that has no patch available.

All Systems Operating Safely

Despite the scale of the intrusions, officials emphasized that all affected water systems continued to operate safely. Dale George, director of communications at Michigan’s Department of Environment, Great Lakes, and Energy, said “all systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern.”

The FBI said in a statement: “The FBI is aware of recent public reporting around Water and Wastewater (WWS) sectors. The FBI and our interagency partners are fully engaged to protect critical infrastructure and we remain well-equipped to protect against cyber threats of all varieties.”

Iran Emerges as Leading Suspect

While the FBI has not publicly identified a culprit, NBC News reported that the attacks had hallmarks of Iranian meddling, according to a law enforcement official. The New York Times reported a preliminary assessment suggesting Iranian hackers were likely responsible, though it stressed the assessment was subject to change.

Cynthia Kaiser, former deputy assistant director of the FBI’s Cyber Division and now senior vice president at Halcyon’s Ransomware Research Center, told AP News: “I think most credible researchers and responders would be right to treat it like it’s Iran until proven otherwise. When it walks like a duck and talks like a duck, it’s really important to call it out.”

Security researchers at Tenable were among the first to publicly suspect Iran’s involvement, citing similarities with previous attacks by the IRGC-linked CyberAv3ngers group. A restricted WaterISAC notice shared with water utilities, leaked to WIRED, said the Minnesota activity aligned with an earlier Iran-affiliated campaign.

The CISA advisory documents Iranian-affiliated exploitation of internet-exposed Rockwell PLCs, and was updated on July 22 to expand the manufacturer scope to include Schneider Electric and Siemens. The advisory noted that “these threat actors are targeting water entities of all sizes” and urged utilities to disconnect PLCs from the internet.

Political Fallout

President Donald Trump claimed without evidence that Minnesota and Gov. Tim Walz were responsible for the attacks, rejecting the Iran theory. At a Cabinet meeting at Camp David on July 31, Trump said: “I think that Minnesota is behind it. You know who’s behind it? Minnesota. Because they’re grossly incompetent. I think the governor is behind it. I don’t think there was an Iranian cyber attack.”

Gov. Tim Walz responded on social media, saying Trump “knows exactly who is responsible for this attack, and knows that other states were hit too. This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran.” Walz also blamed the Trump administration’s Department of Government Efficiency for gutting CISA and leaving the U.S. “exposed to cyberattacks.”

The AP Fact Check found no evidence to support Trump’s claims, noting that authorities have not yet publicly identified the source of the attacks.

A Vulnerable Sector

Local water plants often lack the funds and know-how to install the latest software patches or take other security steps, making them a favorite target for cyber attackers. The U.S. water sector consists of roughly 50,000 community systems, most serving under 10,000 people. Small municipal water systems run dozens of unstaffed remote assets tied back to SCADA head ends over cellular modems.

Iran’s interest in U.S. water systems dates back years. In 2016, the Justice Department charged a group of Iranian hackers in connection with a cyberattack targeting a small dam near New York City. The 2026 Iran war, which began with Operation Epic Fury on February 28, provides the geopolitical context for the current attacks.

What’s Next

Federal authorities are working with state and local officials to assess the full scope of the intrusions. CISA has issued an alert urging water and wastewater systems to protect operational technology against activity targeting PLCs, recommending that operators disconnect PLCs from the internet, enable password protection, and allowlist IPs.

Bryson Bort, founder of cybersecurity company Scythe, said: “We need to be prepared. Attacks like this illustrate that there are folks who mean the U.S. harm today.”

As the investigation continues, the key questions remain: who is ultimately responsible, how widespread the intrusions truly are, and whether America’s water infrastructure can be hardened against future attacks. The answer to the first question may come soon, but the latter two represent long-term challenges that will persist regardless of attribution.