U.S. investigating whether Iranian actors were behind cyberattacks on Minnesota water systems
Malicious cyber activity affected programmable logic controllers at more than 30 community water systems across Minnesota, according to CBS News reporting. U.S. officials are investigating whether Iranian actors were responsible, though sources cautioned that attribution remains unconfirmed and could change as evidence is collected. The FBI, EPA and CISA warned that attackers are targeting water utilities across at least seven states.
Malicious cyber activity has affected programmable logic controllers at more than 30 community water systems across Minnesota, according to CBS News reporting. U.S. officials are investigating whether Iranian hackers were responsible, though sources cautioned that they have not definitively attributed the attack and their assessment could change as additional technical evidence is collected.
The investigation centers on whether the activity represents a direct attack by Iranian state-sponsored actors or whether someone attempted to appear Iran-based as a way of stirring tensions amid the ongoing U.S. conflict with Iran. Minnesota and the federal government have not publicly attributed the activity to any particular actor.
The affected systems rely on programmable logic controllers, or PLCs, which are devices that remotely monitor and control water system equipment. According to reports from the FBI, Environmental Protection Agency and Cybersecurity and Infrastructure Security Agency, federal authorities have documented loss of monitoring and control functionality at critical infrastructure sites in at least some cases, leading to pressure loss and flooding. The FBI and EPA reported that the issue extends beyond Minnesota, with incidents reported in at least seven states.
Across three Minnesota municipalities detailed in available reporting, water supply safety was maintained. South St. Paul, which identified an issue early Monday and transitioned to manual operations, reported that drinking water treatment, quality, pressure and delivery were not affected and that no resident data was accessed. In Braham, public works personnel discovered the problem Monday after noticing the well supplying the city's water tower was malfunctioning; workers isolated the affected system and restored backup systems in about 90 minutes, with no loss of water service reported, according to Mayor Nate George. Plymouth officials detected an outage Sunday evening after noticing compromised PLCs at two water towers and fourteen sewer lift stations; they moved systems into manual operation temporarily until normal communications were restored by Tuesday afternoon, with water quality, treatment and pressures reported unaffected throughout.
Minnesota investigators identified similarities in the timing of recent incidents and the types of technology impacted, but have not yet confirmed that every incident was carried out by the same actor. The FBI, EPA and CISA all warned Thursday that attackers are targeting internet-exposed industrial controllers used by water and wastewater utilities. Nick Anderson, acting director of the federal Cybersecurity and Infrastructure Security Administration, confirmed that the agency "is currently observing a significant increase in cyber threat actors targeting programmable logic controllers at water utilities." CISA urged critical infrastructure owners and operators to "remove publicly exposed PLCs and other operational technology from the internet as soon as possible."
Historically, Iran-linked hackers have targeted U.S. water utilities; federal agencies confirmed previously that actors affiliated with Iran's Islamic Revolutionary Guard Corps accessed multiple water and wastewater facilities in 2023. However, the current investigation remains in preliminary stages with no confirmed attribution.
Cyberattacks affected monitoring and control systems at 30+ Minnesota water systems; no water supply contamination reported, but officials investigating potential Iranian involvement without definitive attribution.
Attribution of the Minnesota attacks remains unconfirmed, with investigators openly examining the false-flag possibility. Watch for technical forensic analysis over the coming weeks and whether the federal government issues a formal attribution statement. Any definitive finding would reshape assessment of Iran's cyber offensive capabilities against U.S. infrastructure.
Every story, sourced. Every source, rated.
Sources
- cbsnews.com lean-left / high
Single-source report. As published, only cbsnews.com had reported this development. No independent outlet had corroborated it.
Outlet ratings are the public AllSides and Media Bias/Fact Check charts' calls, not ours. How we rate sources.
GoCheckMyNews reports events. It does not editorialize and it does not advise. Nothing here is political advocacy, legal advice, or financial advice.