Federal and state authorities are investigating a coordinated cyberattack on Minnesota’s water systems, with at least seven states affected, including 30 sites in Minnesota alone. The attacks targeted remotely controlled operational technology, prompting some utilities to switch to manual operations. No federal agency has publicly attributed the incident to any specific actor, though preliminary assessments suggest possible links to Iranian-affiliated hackers.
President Donald Trump on Friday publicly dismissed claims that Iran may have been responsible, instead blaming Minnesota’s state government and Democratic Gov. Tim Walz for what he described as ‘gross incompetence’. Speaking during a Cabinet meeting at Camp David, Trump stated, “I think I blame it on Minnesota because they’re grossly incompetent,” adding that Iran “should be so lucky” to be involved. His remarks contradict preliminary assessments reported by multiple outlets, including Wired and The New York Times, which cited unnamed U.S. and Minnesota officials as saying the attacks were ‘aligned’ with an allegedly Iran-linked cyber-sabotage campaign.
Federal agencies, including the FBI and the Cybersecurity and Infrastructure Security Agency (CISA), have not formally attributed the attack to any group. In a joint advisory issued last week, the agencies warned that Iranian hackers have been targeting water and waste systems, though they did not specify whether this incident was linked. Minnesota IT Services confirmed the attack targeted operational technology at more than 30 community water systems but emphasized that state officials are not attributing the activity to a specific threat actor at this time.
State Response and Safety Assurances
Minnesota officials stated that the state’s water remains safe to drink, despite some other affected states issuing boil notices. The Minnesota Department of Health reported that it was ‘not aware of any active requests from Minnesota cities to modify tap water consumption’. Minnesota IT Services reiterated that federal partners are leading the attribution assessment and urged against speculation while the investigation is ongoing.
Scope and Technical Details of the Attack
The cyberattack involved hackers targeting programmable logic controllers (PLCs), which are used to remotely monitor and control equipment. According to CISA, threat actors modified passwords to ‘lock out operators’, a tactic consistent with previous Iranian-linked attacks on U.S. water facilities. These earlier incidents exploited internet-connected equipment protected by default or weak passwords. The FBI informed state officials that at least seven states were affected, though Minnesota received the most attention due to the scale of the intrusion.
Ongoing Uncertainty and Investigative Process
Authorities have cautioned that assessments remain preliminary and subject to change as additional technical evidence is analyzed. Some reports suggest investigators are examining whether the perpetrators may have sought to ‘make the activity appear Iranian in origin’, a tactic known as a false-flag operation. Federal and state agencies continue to collaborate on the probe, with no definitive conclusions yet reached.
Political Reactions and Broader Implications
Trump’s comments came amid heightened political scrutiny of Minnesota’s administration, with the president previously criticizing Gov. Walz over issues unrelated to cybersecurity. Walz, a 2024 Democratic vice presidential nominee, has not been accused of involvement in the cyber incident. The attack has raised broader concerns about the vulnerability of critical infrastructure, particularly water systems, which have increasingly become targets for state-sponsored and criminal cyber actors.
Federal advisories in recent months have highlighted the growing threat to operational technology in essential services, with CISA noting that Iranian-affiliated groups have historically exploited weak security protocols in such systems. The incident underscores the challenges of attributing cyberattacks in real time and the potential for misinformation or misdirection in high-stakes digital intrusions.