Iranian Hackers Suspected in Minnesota Water Systems Cyberattack

U.S. intelligence agencies suspect Iranian hackers orchestrated a coordinated cyberattack targeting operational technology at more than 30 municipal water systems in Minnesota this week. The breach prompted federal investigations, state emergency responses, and sharp political clashes over infrastructure security amid ongoing military tensions.

A coordinated cyberattack struck municipal water systems across Minnesota, prompting active investigations by federal and state authorities. Minnesota IT Services (MNIT) reported that the security breach targeted operational technology at more than 30 community water systems on Sunday and Monday.

Federal Intelligence Assessment and the Investigation into Minnesota Water Facilities

U.S. intelligence agencies have assessed that Iran was likely behind the intrusion into local utility networks. State and federal officials briefed on the probe indicated that the specific tradecraft used and the absence of any ransom demand led analysts to initially point toward Iranian actors. The FBI confirmed it is aware of recent public reporting concerning the water and wastewater sectors and remains fully engaged in protecting critical infrastructure.

State officials first detected the suspicious activity on Sunday. John Israel, MNIT assistant commissioner and Minnesota’s chief information security officer, noted that hackers targeted 36 municipal water systems in total. Israel stated that Minnesota was among the early detectors of the breach, but investigators are finding that this same threat activity has likely occurred in other states throughout the nation. Nick Andersen, acting director of the Cybersecurity and Infrastructure Security Agency (CISA), confirmed that the agency is aware of multiple potential incidents affecting local water utilities nationwide.

Local Impact and Emergency Response in Minnesota Communities

The breach directly affected computerized control systems used to manage and monitor water towers operated by municipal governments. In the city of Braham, a plant operator discovered that the water tower was calling for water while the well remained idle. City staff determined that the plant’s computerized control system had been compromised after learning of similar problems occurring in at least four other Minnesota communities.

Cyberattacks on Minnesota water systems investigated as officials warn about Iranian hackers

Braham public works isolated the affected system, restored a backup, and restarted the plant within approximately 90 minutes. While the facility was offline, residents continued receiving water from the city’s water tower, though city administration temporarily requested that residents conserve water to prevent the limited supply from being exhausted. Meanwhile, the Minnesota Department of Health reported it was not aware of any active requests from Minnesota cities to have residents modify their drinking water usage.

Political Fallout and President Trump’s Response

The cyber incident quickly triggered a political dispute. During a Cabinet meeting, President Donald Trump rejected the intelligence assessment pointing toward foreign interference, blaming state leadership instead.

Iranian hackers likely behind cyberattack on Minnesota water systems: report
Photo: Foxnews

“Today, I just want to mention that, we heard in Minnesota there was a cyberattack, and they blame it on Iran. I don’t think so. I think I blame it on Minnesota because they’re grossly incompetent. There was a cyberattack of 30 water plants, and I would blame it on Minnesota and the governor, the corrupt governor of Minnesota.”

President Donald Trump, Cabinet Meeting

Trump specifically referenced Minnesota Gov. Tim Walz, a Democrat, adding that Iran has larger domestic concerns to manage. State technology officials emphasized that the investigation remains active and that Minnesota has not officially attributed the activity to a specific actor while interagency cooperation continues.

A Decade of Iranian Cyber Activity Targeting U.S. Infrastructure

If investigators officially confirm state-sponsored Iranian involvement in the Minnesota water facility breach, it would fit a long-running pattern of malicious cyber activity targeting American targets. For more than a decade, Iranian-linked operators have scanned for widespread vulnerabilities to create disruption, intimidate adversaries, and undermine trust in government institutions.

Iranian Hackers Suspected in Minnesota Water Systems Cyberattack
Photo: The Washington Post

Past campaigns documented by federal investigators include distributed denial-of-service attacks on dozens of U.S. banks between 2011 and 2013, a 2013 intrusion into the control system of the Bowman Avenue Dam in Rye, New York, and a 2014 wipe of hard drives at the Las Vegas Sands casino company. More recently, federal agencies warned that actors associated with groups like Pioneer Kitten compromised municipal governments, schools, and healthcare organizations between 2017 and 2024, frequently transferring compromised systems to ransomware affiliates.

FBI warns of cyberattacks on water systems in 7 states

Leave a Comment