Michigan officials reported on Saturday that nine of the state’s water systems were targeted in cyberattacks, prompting a federal investigation into potential foreign involvement. The FBI is examining whether the incidents, which follow similar attacks in Minnesota, may be linked to Iran, though authorities emphasize the assessment remains preliminary.
Authorities in Michigan received a federal cyber alert on Tuesday regarding attempts to tamper with operational technology at water systems. All systems continued to operate safely, with local operators addressing issues and no known public health impacts reported, according to Dale George, director of communications at Michigan’s Department of Environment, Great Lakes, and Energy. The attacks have now affected at least seven states, including 30 sites in Minnesota alone.
In Minnesota, cities such as Plymouth and Braham were impacted. Braham Mayor Nate George told the New York Times that federal and local officials suspected Iranian involvement but were cautious about making public attributions. “I think the troubling thing on the horizon is how do we move forward to a more secure system,” he said. “IT infrastructure upgrades are very costly and we are a very small municipality.”
Federal investigators are analyzing whether the cyber actors may have attempted to mimic Iranian-linked groups to sow confusion amid heightened U.S.-Iran tensions. Iran has long denied involvement in such attacks. Officials noted that official confirmation of attribution could take weeks or months as technical evidence is collected.
Background: Prior Iranian-linked cyber incidents in the U.S.
Between 2011 and 2013, Iranian-linked actors were charged with distributed denial-of-service (DDoS) attacks against 46 U.S. financial institutions, disabling websites and costing victims tens of millions of dollars in remediation. In 2013, an Iranian defendant accessed the control system for the Bowman Avenue Dam in New York, though the sluice gate was disconnected for maintenance at the time. In 2014, the Las Vegas Sands casino company suffered data wipes and network damage, with hackers leaving condemnations of the CEO.
Political responses
Former President Donald Trump criticized Minnesota Governor Tim Walz this week, suggesting the state’s cybersecurity failures—rather than foreign actors—were to blame. “I just want to know why the incompetency of the governor’s administration… was able to allow this to happen,” Trump stated. Walz’s office has not publicly addressed the claim.
Federal agencies, including the FBI and Cybersecurity and Infrastructure Security Agency (CISA), are coordinating responses. Local officials in affected municipalities are prioritizing short-term fixes while seeking long-term funding for infrastructure upgrades. The incidents underscore ongoing concerns about the vulnerability of critical infrastructure to cyber threats.