Technology

Who Is Behind the Cyberattacks on Minnesota's Water Systems?

Martin HollowayPublished 4d ago5 min readBased on 12 sources
Reading level
Who Is Behind the Cyberattacks on Minnesota's Water Systems?

President Donald Trump told reporters at a July 31, 2026 Cabinet meeting that he blames Minnesota, not Iran, for the coordinated cyberattacks targeting the state's water infrastructure. "I blame it on Minnesota because they're grossly incompetent," Trump said, explicitly rejecting the assessment of federal cybersecurity agencies by adding, "I don't think there was an Iranian cyberattack" (The Washington Post, The Verge).

Minnesota Governor Tim Walz rejected the president's assertion as unfounded (MPR News). The FBI, the EPA, and CISA, the nation's cybersecurity agency, have collectively stopped short of officially blaming Iran for the Minnesota intrusions, though the consensus among those agencies points to Iranian actors as the likely perpetrators (The Verge).

At least 30 community water systems in Minnesota were targeted in what appeared to be a coordinated attack. Officials confirmed the intrusions did not affect water quality. The attackers got into the computer systems that manage and monitor water facilities but did not manipulate the actual treatment processes that make water safe to drink (MPR News). The FBI has warned that similar attacks on American infrastructure are spreading to other states, with Georgia and Michigan now reporting intrusions on their water systems that mirror the Minnesota approach (The Verge, ABC News).

CISA has linked similar attacks earlier in the year to Iran (The Verge). In late 2024, CISA issued an advisory detailing cyber actors with ties to Iran's Islamic Revolutionary Guard Corps operating under the persona "CyberAv3ngers." That advisory documented the targeting of a specific type of industrial computer made by an Israeli company called Unitronics. These computers, used widely in water and wastewater facilities, control valves, pumps, and other machinery. The attackers exploited systems whose control panels were accessible from the internet without proper protection (CISA).

To support defensive efforts across the sector, CISA maintains its Water and Wastewater Cybersecurity toolkit, which consolidates key resources for systems at every level of cybersecurity readiness (CISA). The agency also previously published the Cyber Storm VIII After-Action Report, covering a three-day live exercise that gave stakeholders a realistic environment to test their cyber incident response plans (CISA).

The political dimension extends beyond the current cyber attribution dispute. Trump has separately threatened to invoke the Insurrection Act against Minnesota during a surge of ICE enforcement efforts in the state (The Verge).

The broader context here involves the friction between political attribution and technical incident response. When a president publicly disputes the working consensus of agencies like CISA and the FBI, it complicates the messaging around sector-wide vulnerability. Municipal water systems operate with notoriously thin security resources. Coordinated attacks on 30 facilities, regardless of who is ultimately responsible, reveal a systemic weakness in how the computers running water plants are exposed to outside access.

Worth flagging is the specific way these attacks work. If the current intrusions parallel the earlier Iran-linked activity targeting Unitronics devices, the root cause is less about state-level incompetence and more about the persistent use of older equipment that lacks basic protections. Think of it like a building where every room shares the same key: once an attacker gets through the front door, they can reach everything inside. CISA's existing toolkits and prior exercises were designed precisely to address these structural deficiencies, yet adoption at the local level remains uneven.

In this author's view, the most consequential element of this story is the geographic spread. The FBI's warning that attacks are migrating to Georgia and Michigan indicates a probing methodology. Threat actors, whether working for a government or not, scan for specific system setups across the national infrastructure. Finding and compromising exposed systems in one state naturally leads to replication elsewhere. The fact that water quality remained unaffected in Minnesota is a matter of timing and intent, not a guarantee of future outcomes. If the goal shifts from surveillance to physical disruption, the current vulnerabilities provide ample opportunity.

The long-arc hopefulness in this sector comes from the fact that the defensive playbooks already exist. CISA has mapped the vulnerabilities, issued the advisories, and provided the toolkits. The challenge is execution and resourcing at the local level, which requires sustained federal support rather than political friction. When the technical response operates independently of the political narrative, infrastructure security improves.