FBI: Hackers Targeted Water Utilities in at Least 7 States

Z Patel

Thirty water systems breached in a single Minnesota weekend. Michigan, South Dakota, and California followed days later. Federal investigators lean toward Iran. Trump blamed the state’s governor instead — calling him “grossly incompetent.”


Federal agencies confirmed Thursday that hackers breached water and wastewater systems across at least seven US states since 27 July, with some incidents degrading operations enough to cause pressure loss and flooding. The FBI, EPA, and CISA issued a joint public service announcement warning utilities nationwide that attackers are targeting internet-exposed industrial controllers. The federal alert did not name which states were hit, though separate reporting confirmed Minnesota, Michigan, South Dakota, and California among the affected. The most severe cluster hit Minnesota, where hackers breached more than 30 municipal water facilities in a single weekend, in an attack investigators say bears the hallmarks of Iranian involvement.

What’s Happening & Why It Matters

What Broke — and What Didn’t

Minnesota IT Services confirmed the intrusions targeted programmable logic controllers, the industrial devices utilities use to monitor and manage water system equipment. Some breaches caused loss of monitoring and control functionality at affected sites, leading to pressure drops and flooding at certain facilities. A Minnesota IT spokesperson said Thursday there’s no indication the breaches contaminated any municipal drinking water supply, a distinction federal officials have repeated across every affected state so far.

Michigan reported cyberattacks on nine of its own water systems days after the Minnesota cluster emerged, suggesting either a coordinated campaign or copycat activity following the same exploitation method. CISA and the FBI urged affected utilities to disconnect vulnerable PLCs from the public internet, or route remote access through a VPN or secure gateway device instead of leaving controllers exposed.

Iran and The President’s Hypothesis

Investigators are probing whether the attacks trace to Iran, following a pattern federal agencies say Tehran-linked hackers have used before. CISA warned on 22 July, just days before the Minnesota breach, that Iran-backed hackers were targeting automated infrastructure devices amid escalating military tension between Washington and Tehran. Iran-affiliated actors, including groups linked to the Islamic Revolutionary Guard Corps, breached multiple US water facilities in 2023 using the same basic technique: exploiting internet-connected controllers still running default factory passwords.

President Trump offered a different explanation when reporters asked about the Minnesota breach. “I heard in Minnesota there was a cyberattack, and they blame it on Iran. I don’t think so,” Trump said. “I blame it on Minnesota because they’re grossly incompetent. Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota.” Federal investigators have not confirmed attribution, and sources familiar with the probe told CBS News the assessment could change as more technical evidence comes in. Investigators are also weighing whether the actual perpetrator mimicked Iranian tactics to stir tension amid the ongoing conflict, rather than originating from Tehran.

A Sector Needing Cybersecurity in Design

Mark Rorabaugh, CEO of critical infrastructure security firm InfraShield, described the deeper vulnerability underneath the specific incident. “Critical infrastructure facilities like water and wastewater systems are … part of … geopolitical cyber conflicts, even when they are not the primary targets,” he said. “Much of the operational technology supporting [the] essential utilities was never designed with today’s rapidly evolving cyber threats in mind.”

That gap is structural, not incidental. Most municipal water systems run on equipment installed decades before cybersecurity became a standard design consideration, and many small utilities operate without the budget or staff to maintain dedicated security teams. Bryson Bort, founder of industrial security firm Scythe, noted the FBI’s warning is the kind of soft target Iran and other state-linked actors have found attractive: high public impact, low technical sophistication required, and defenders spread thin across thousands of independently operated small systems nationwide.

TF Summary: What’s Next

The FBI and EPA continue investigating the full scope of affected utilities, with officials cautioning that additional states beyond the seven confirmed may have experienced incidents not yet disclosed. Attribution to Iran is unconfirmed as forensic analysis continues. CISA’s recommendation to disconnect exposed PLCs from the public internet applies to every water utility nationwide, not just those already confirmed breached. Minnesota officials continue monitoring affected systems for any secondary effects beyond the initial operational disruption.

MY FORECAST: Expect formal attribution within the next month, once forensic analysis catches up to the political urgency already surrounding the story. Given the documented 2023 precedent using near-identical tactics, Iranian involvement is the most probable explanation regardless of Trump’s public scepticism. However, investigators will qualify any conclusion given the possibility of a false-flag operation. The more consequential outcome is regulatory, not diplomatic. Congress let a rule requiring cybersecurity audits for public water systems lapse after a court challenge from several states. Expect renewed legislative pressure to reinstate mandatory security testing for water utilities, given how the incident demonstrates the exact vulnerability that rollback left unaddressed.



[gspeech type=full]

Share This Article
Avatar photo
By Z Patel “TF AI Specialist”
Background:
Zara ‘Z’ Patel stands as a beacon of expertise in the field of digital innovation and Artificial Intelligence. Holding a Ph.D. in Computer Science with a specialization in Machine Learning, Z has worked extensively in AI research and development. Her career includes tenure at leading tech firms where she contributed to breakthrough innovations in AI applications. Z is passionate about the ethical and practical implications of AI in everyday life and is an advocate for responsible and innovative AI use.
Leave a comment