Minnesota Water Systems Hit by Coordinated Cyberattack Amid Iran Tensions

More than 30 community water systems in the US state of Minnesota were affected by a cyberattack over the weekend and into Monday, according to Minnesota IT Services, the state's technology agency. The incident prompted a response from government and municipal agencies, though affected cities issued no instructions regarding residents' drinking water use.

The FBI confirmed it was "actively engaged with victims" of the alleged attacks. In a social media post, the agency's cyber division emphasized its "joint commitment to support critical infrastructure entities against malicious cyber actors attempting to harm the United States."

Suspected Iranian Involvement

US officials have suggested that the attacks resemble incidents attributed to hackers aligned with the government of Iran, though they cautioned that such assessments are preliminary. Emily Zimmer, a spokesperson for Minnesota IT Services, told Reuters that "the timing, methods of access, and targeted infrastructure share characteristics with other coordinated cyber incidents our federal partners have observed involving critical infrastructure."

The New York Times reported that government officials believe the attack was likely the work of Iranian hackers, citing unnamed state and federal officials. However, those figures noted that they have not definitively determined who is behind the attack.

US investigators are also looking into whether the hackers could have posed as Iran-based as a ruse to sow further discord amid the US war with Iran, according to CBS, the BBC's US partner.

Expert Analysis

Experts consulted by the BBC and The Washington Post said that similar attacks have occurred in water and energy systems across the United States since the beginning of the war with Iran. Joe Slowik, director of threat research for Dataminr, told the Post: "It is not a secret that these things have been taking place since the spring. There have been disruptions in multiple critical infrastructure sectors. It’s a big deal."

Kurt Gaudette, head of intelligence for Dragos, noted that the cyberattacks had generally targeted "very low-hanging fruit" — vulnerable systems such as small utilities using default passwords and whose controllers were open to the internet.

Alex Orleans, head of threat intelligence at Sublime Security, told the Post that Iran's goal seemed to be the psychological effect rather than outright sabotage and destruction.

The biggest threat of the hacks, according to some experts, was not to the water supply itself but in degrading public confidence in the security of their water.

Federal Warning and Context

On Thursday, the US Cybersecurity and Infrastructure Security Agency (CISA) warned that it had noticed "a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector."

The incident comes at a time of heightened tensions between Iran and the US. Morgan Wright, a former US State Department anti-terror adviser, told the BBC that these kinds of attacks are usually attributed to North Korea or Iran. "And who are we in conflict with right now? Well, it's Iran. So they become, they go to the top of the listed terms of nations capable, and also having a desire to do something like this," he said.

Political Reactions

At a cabinet meeting last Friday, President Donald Trump blamed "grossly incompetent" Minnesota officials, including Governor Tim Walz, for the water hack. Walz, a Democrat, responded: "Trump knows exactly who is responsible for this attack, and knows that other states were hit too."

Jake Braun, former acting White House Deputy National Cyber Director, told the BBC that the Trump administration is involved in its own information war and therefore might be unlikely to admit that Iran did infiltrate US water infrastructure, even if it was confirmed.

Iran has yet to comment on these incidents, but Tehran has repeatedly denied involvement in other cyberattacks over the years, which include water systems, presidential campaigns, hospitals, and a casino company in Las Vegas in 2014. After a 2016 accusation linked to the targeting of banks and a dam outside New York City, Iran's foreign ministry spokesman said the US should prove such accusations. Iran has "never had on its agenda any dangerous measures in cyberspace and does not support such moves," spokesman Hossein Jaberi Ansari said on state TV at the time.

Iran has a documented history of this kind of activity, experts told the BBC. They noted that groups supportive of Iran, but located outside the country could be responsible. "It makes it harder to assign attribution because if all of your attacks and groups are coming out of Iran, you can pretty much link it to Iran," Wright said.