Iranian Hackers Suspected Behind Wave of Cyberattacks Hitting Minnesota Water Systems
More than 30 water systems across Minnesota were hit by cyberattacks over a single weekend, and nobody is officially pointing fingers yet. Unofficially, the arrow is pointing pretty firmly at Iran.
The attacks occurred on Sunday and Monday. Minnesota IT Services confirmed malicious activity across multiple systems but said investigators had not yet attributed the attacks to a specific actor. The FBI is on the case and, true to form, its spokesperson declined to share who they thought was responsible.
For most residents, the disruption was invisible. One exception was Braham, a small city of around 1,700 people roughly 70 miles north of Minneapolis, where residents were asked to cut back on water use for a few hours on Monday after the water plant went offline. The attackers had shut down the operating controls for the well and treatment plant, leaving the city running on whatever was sitting in the water tower. Not ideal, but not a catastrophe either. Water quality was unaffected.
Plymouth, a much larger suburb outside Minneapolis with around 80,000 residents, also confirmed a cyberattack. Officials said water operations continued throughout and normal communications were restored by Tuesday afternoon.
Most of the confirmed attacks involved systems used to remotely monitor and control water infrastructure. In other words, the operational technology layer rather than purely IT systems. Investigators noted similarities in timing and the types of technology targeted across incidents, but have not confirmed whether it was all one coordinated campaign or several separate ones.
The timing is not coincidental. Just last week, the FBI, CISA, and several other agencies issued a joint advisory warning that Iranian state-linked hackers had been actively targeting water and wastewater systems, along with other critical infrastructure sectors.
Cynthia Kaiser, formerly deputy assistant director of the FBI's cyber division and now senior vice president at Halcyon's Ransomware Research Center, was blunt about the likely culprit. Iran has both the motive and the track record, she said, adding that serious researchers and incident responders would be right to treat these attacks as Iranian until proven otherwise. Her duck analogy needs no further elaboration.
Iran's interest in US water infrastructure is not new. Back in 2016, the Justice Department charged a group of Iranian hackers over a cyberattack targeting a small dam near New York City. The pattern is consistent and long-running.
The broader problem here is structural. Water utilities, particularly smaller ones, are chronically underfunded and short on cybersecurity expertise. They struggle to keep software patched, let alone deploy serious defensive tooling. That makes them attractive targets: relatively easy to penetrate, and capable of causing genuine public anxiety when disrupted. It is not a coincidence that state-sponsored actors keep coming back to them.
As of Thursday, Minnesota IT Services said no communities were asking residents to change how they use their drinking water.