U.S. Officials Point to Iranian Hackers in Minnesota Water System Breach Affecting Dozens of Communities

💛 A quick favor, if you've got a second.

We're really happy that you chose to read one of our stories and sincerely hope you'll stick around to read more. We took our paywall down — for now — but that won't last forever, and when the gate goes back up, we'd love for you to already be on the inside.

It's free. So please enter your email here and don't forget to like and follow us on all of your favorite Social Media platforms!

Share this story:


✉️ Email


💬 Text

Federal authorities have determined that Iranian hackers likely orchestrated a coordinated cyberattack targeting operational technology infrastructure at more than 30 community water systems across Minnesota on Sunday and Monday, according to reporting citing U.S. and state officials briefed on the incident. The Minnesota Department of Health has not received requests from municipalities asking residents to alter their drinking water consumption patterns, officials said.

Three state officials involved in the investigation told The New York Times that the methods employed by the attackers and the absence of ransom demands initially pointed investigators toward Iran as the responsible party. However, officials cautioned that assessments could shift as investigators gather additional evidence, according to the report.

The breach targeted infrastructure that controls and monitors water towers managed by municipal governments across the state. In Braham, a plant operator discovered Sunday that the water tower was signaling a need for water while the well pump remained inactive, prompting city staff to identify a compromise to the computerized control system.

Braham public works personnel isolated the affected system, restored backup controls, and restored the plant to operation within approximately 90 minutes, according to Mayor Nate George. During the outage, residents continued receiving water from the city’s storage tower, though officials temporarily requested water conservation to protect limited reserves.

Minnesota IT Services stated that the investigation remains ongoing and has not formally attributed the attack to any specific actor. The agency is coordinating with federal, state, local, tribal, and private-sector partners to support affected communities and bolster critical infrastructure defenses.

John Israel, MNIT’s assistant commissioner and chief information security officer, emphasized the need for coordinated government response to such threats. Minnesota was among the first to detect the breach, though similar attack activity has likely occurred in other states nationwide, Israel told the Times.

The Cybersecurity and Infrastructure Security Agency’s acting director, Nick Andersen, confirmed the agency was monitoring multiple potential incidents affecting local water utilities. CISA had issued an advisory days before the Minnesota incident warning organizations of ongoing Iranian-affiliated cyber activity targeting internet-connected operational technology devices.

The FBI’s Cyber Division Assistant Director Brett Leatherman stated in the advisory that the bureau remains committed to identifying and disrupting those responsible for such attacks on American critical infrastructure. According to CISA, Iranian-affiliated actors have targeted devices across multiple U.S. critical infrastructure sectors including water and wastewater systems, energy providers, and government facilities.

Share this story:


✉️ Email


💬 Text