Federal and state investigators are investigating a coordinated cyberattack that disrupted dozens of municipal water systems in Minnesota, and officials suspect Iranian-affiliated hackers played a role. Agencies are racing to secure operational technology, restore controls, and push for accountability while the investigation continues.
Minnesota IT Services reported that the “coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems” on Sunday and Monday, and the state health agency said it is “not aware of any active requests from Minnesota cities to have their residents modify their drinking water usage.” Local operators scrambled to understand the scope while emergency teams moved to isolate affected systems and restore backups. The breach exposed vulnerabilities in systems that manage essential public services.
Multiple U.S. and state officials told national press that analysts initially linked the activity to Iranian operators, pointing to familiar tradecraft and the absence of a ransom demand. Investigators have been careful to note that conclusions could evolve as forensic work continues, but the pattern matched prior Iranian-affiliated campaigns. This type of stealthy interference fits a broader pattern of probing U.S. infrastructure.
“The FBI is aware of recent public reporting around Water and Wastewater sectors. The FBI and our interagency partners are fully engaged to protect critical infrastructure and we remain well-equipped to protect against cyber threats of all varieties,” the FBI said in a statement to Fox News Digital on Friday. Federal involvement is necessary, and Republicans will insist on firm, unambiguous measures to deter future attacks. The initial federal posture looks right: investigate, harden defenses, and prepare consequences.
IRAN-LINKED HACKERS TARGET US MEDICAL TECH COMPANY
Investigators say the attackers focused on infrastructure that manages and monitors municipal water towers, systems critical to everyday life and public safety. When supervisory control and data acquisition tools are tampered with, towns can face cascading outages or misleading telemetry that complicates operations. National security and local services intersect here, and the risk goes far beyond a single outage.
Braham Mayor Nate George described how a “plant operator found that the water tower was calling for water, but the well was not operating.” That discovery led city staff to identify similar anomalies in at least four other nearby communities. Officials quickly realized the plant’s computerized control system had been compromised and took emergency steps.
“After learning that similar problems were occurring in at least four other Minnesota communities, Braham staff determined that the plant’s computerized control system had been compromised,” he continued. “Public works isolated the affected system, restored a backup, and restarted the plant within approximately 90 minutes. While the plant was offline, residents continued receiving water from the city’s water tower. City administration temporarily requested that residents conserve water to prevent the tower’s limited supply from being exhausted,” George added.
State officials emphasized caution: MNIT said that “the investigation remains active, and Minnesota has not attributed the activity to a specific actor.” John Israel, MNIT Assistant Commissioner and Minnesota Chief Information Security Officer, warned that “Cyberattacks against critical infrastructure require a coordinated, whole-of-government response.” He added that “MNIT is working side by side with our partners to share intelligence, support affected communities, and help utilities restore operations safely while strengthening defenses against future attacks.”
Israel told investigators the breach was detected on Sunday and that hackers hit 36 municipal systems, and he noted “Minnesota was one of the early detectors of this, but we’re seeing that this same threat activity has likely been occurring in other states throughout the nation.” CISA’s acting director said the agency was tracking “multiple potential incidents affecting local water utilities.” These cross-jurisdictional incidents demand a national playbook for rapid containment and resilient recovery efforts.
In the days before the incident, federal agencies warned U.S. organizations of “ongoing Iranian-affiliated cyber activity targeting internet-connected operational technology (OT) devices.” Assistant Director Brett Leatherman of the FBI’s Cyber Division stated, “Iranian cyber actors continue to target U.S. critical infrastructure, and the FBI is committed to identifying, disrupting, and imposing costs on those responsible.” The bulletin added that a “group of Iranian-affiliated actors” has “targeted devices spanning multiple U.S. critical infrastructure sectors, including Water and Wastewater Systems, Energy and Government Services and Facilities, to include local municipalities,” underscoring the broad footprint of the threat.