Minnesota water hacks revive fears of Iranian attacks on US infrastructure

Investigators are examining whether the cyberattack may be linked to Iran, according to media reports
Minnesota's state IT agency said more than 30 community water systems were targeted in a coordinated cyberattack (AP Photo/Ellen Schmidt)
Minnesota's state IT agency said more than 30 community water systems were targeted in a coordinated cyberattack (AP Photo/Ellen Schmidt)

MINNEAPOLIS, MINNESOTA: A coordinated cyberattack targeting more than 30 community water systems across Minnesota has renewed concerns over the vulnerability of America's critical infrastructure as federal investigators examine whether the incidents could be connected to a cyber campaign previously associated with Iran-affiliated hackers.

While officials have not confirmed Iran was behind the attacks, a leaked industry memo has reportedly pointed investigators toward a possible connection, stressing that the assessment remains preliminary as the investigation continues.

The incident has drawn national attention not because drinking water was contaminated - it was not - but because it targeted systems that provide an essential public service to American communities. It has also revived questions about whether a cyber threat that US agencies have warned about for years is re-emerging at a time of heightened tensions between Washington and Tehran.



Why do Minnesota attacks matter beyond one state's water systems?

Minnesota IT Services said more than 30 community water systems were targeted between July 26 and 27 in what it described as a "coordinated cyberattack." While no communities were advised to stop using their drinking water, some utilities temporarily switched to manual operations after hackers accessed automated control systems.

The FBI said water and wastewater utilities in at least seven states have since reported related incidents, with some activity degrading water operations.

The attacks have become more significant because they come against the backdrop of repeated federal warnings about Iranian cyber activity targeting critical infrastructure. On April 7, the Environmental Protection Agency (EPA), FBI, Cybersecurity and Infrastructure Security Agency (CISA) and National Security Agency (NSA) issued a joint advisory warning US organizations, including water utilities, of an "urgent and ongoing Iranian-affiliated cybersecurity threat."



The agencies urged operators to disconnect vulnerable industrial control systems from the internet and strengthen remote-access protections against attacks targeting programmable logic controllers used in water and wastewater facilities.

Federal agencies have since intensified those warnings. On July 30, CISA warned that hackers were increasingly targeting technology used to operate water and wastewater systems, while the FBI said utilities in at least seven states had reported incidents and some had experienced operational degradation.

Although officials have not confirmed who was responsible for the Minnesota attacks, they said the investigation is being treated seriously because of similarities with previously observed campaigns targeting critical infrastructure.

Investigators examining a possible Iran connection

The investigation intensified after a leaked Water Information Sharing and Analysis Center (WaterISAC) memo reportedly suggested the Minnesota incidents shared characteristics with a cyber campaign previously identified by CISA and associated with Iran-affiliated hackers. Cybersecurity researchers cited by WIRED said the attacks bear similarities to tactics previously used by Iranian-linked groups targeting industrial control systems.

However, federal and state officials have stopped short of attributing the attacks to Iran. Investigators continue to analyze forensic evidence and have cautioned that attribution remains preliminary.

WASHINGTON, DC - JUNE 2: General Joshua M. Rudd, commander of the U.S. Cyber Command and director of the National Security Agency and Chief of the Central Security Service, arrives to a closed Senate Appropriations Committee hearing at the U.S. Capitol on June 2, 2026 in Washington, DC. The hearing at the Senate SCIF examined the 2027 budget proposals for intelligence agencies. (Photo by Eric Lee/Getty Images)
General Joshua M Rudd, commander of the US Cyber Command and director of the National Security Agency and Chief of the Central Security Service, arrives to a closed Senate Appropriations Committee hearing at the US Capitol on June 2, 2026 in Washington, DC (Photo by Eric Lee/Getty Images)

Officials have also acknowledged the possibility that attackers could be impersonating Iranian threat actors, a known tactic in cyber operations designed to complicate attribution.

Authorities have not reported evidence that drinking water quality was compromised or that permanent operational damage occurred. The FBI, CISA and Minnesota officials continue to investigate the incidents.

A 2023 Pennsylvania attack offers the precedent

The Minnesota investigation has inevitably drawn comparisons with a confirmed 2023 cyberattack on the Municipal Water Authority of Aliquippa in Pennsylvania, where the Iran-linked hacking group CyberAv3ngers breached a booster station that regulated water pressure.

US officials later attributed that attack to Iranian-affiliated hackers, prompting nationwide warnings that American water infrastructure had become a target for foreign cyber actors. The Pennsylvania incident established a documented precedent for Iran-linked attacks on US water utilities, but it does not prove Iran was behind the Minnesota attacks.

Instead, cybersecurity experts say it provides important context for why investigators are examining whether a previously documented threat may have resurfaced. Whether the current attacks are ultimately linked to Iran or another actor will depend on the outcome of the federal investigation, officials say.

Minnesota activates statewide response as investigation continues

Minnesota IT Services (MNIT) said it activated the state's cybersecurity incident response capabilities immediately after learning of the coordinated attacks, working alongside the FBI, Cybersecurity and Infrastructure Security Agency (CISA), US Environmental Protection Agency (EPA), Minnesota Department of Health, Minnesota Department of Public Safety, Bureau of Criminal Apprehension's Minnesota Fusion Center and local water utilities.

Officials said the investigation remains active as responders continue assessing affected systems and helping utilities recover. According to the Minnesota Department of Health, there is no indication that drinking water has been compromised, and the agency is "not aware of any active requests from Minnesota cities to have their residents modify their drinking water usage."

"Cyberattacks against critical infrastructure require a coordinated, whole-of-government response," John Israel, MNIT Assistant Commissioner and Minnesota Chief Information Security Officer, said in a statement.

A water tower is seen Thursday, July 30, 2026, in Plymouth, Minn. A cyberattack targeted the operating technology at over 30 water systems in Minnesota, including Plymouth's, earlier this week, state officials said. (AP Photo/Ellen Schmidt)
A water tower is seen Thursday, July 30, 2026, in Plymouth, Minn. A cyberattack targeted the operating technology at over 30 water systems in Minnesota, including Plymouth's, earlier this week, state officials said (AP Photo/Ellen Schmidt)

"MNIT is working side by side with our partners to share intelligence, support affected communities, and help utilities restore operations safely while strengthening defenses against future attacks. This incident demonstrates why Minnesota has invested in strong cybersecurity capabilities and partnerships. Our response worked as intended, enabling agencies at every level of government to rapidly coordinate, contain the incident, and help prevent more serious impacts to critical services."

MNIT said its teams continue to coordinate technical response efforts across government agencies, share threat intelligence and indicators of compromise, assist affected utilities with containment and recovery, and monitor for related malicious cyber activity while working with state and federal partners.

The agency said additional information will be released as the investigation progresses.

RELATED TOPICS US STRIKES IRAN

GET BREAKING U.S. NEWS & POLITICAL UPDATES
STRAIGHT TO YOUR INBOX.

MORE STORIES

The woman allegedly discussed attacking the White House but acknowledged its difficulty, then arranged an explosive device and bought materials
3 hours ago
Videos from a marathon Senate session showed Mitch McConnell appearing unusually still and relying on cues from colleagues while voting
5 hours ago
The confrontation with federal investigators reportedly occurred Saturday night at San Francisco International Airport
7 hours ago
Gabbard said she was relieved when she finally saw him after the operation, but the moment was also frightening
7 hours ago
Conservative commentators challenged the sympathy campaign, saying it centers Clancy over her three children who died
9 hours ago
Prosecutors also cited a text in which Tyler Robinson said he had 'enough' of Charlie Kirk’s hatred and that some hate could not be negotiated out
16 hours ago
Harp's primary function appears to be managing the president's emotional state rather than serving a traditional policy or communications role
20 hours ago
The DEA joined the probe a day after Greenville police released a report detailing findings at the home where Hayden Panettiere was pronounced dead
21 hours ago
Eric Trump is backing Natalie Harp after her brother’s CNN appearance, calling his comments 'absolute trash' and praising her loyalty to Donald Trump
22 hours ago
The announcement comes after a 60-day agreement expired without a final deal and as Washington and Tehran remain at odds over negotiations
23 hours ago