More than thirty community water systems across Minnesota fell victim to coordinated cyberattacks this week, compelling several utilities to abandon automated operations in favor of manual control as state and federal investigators work to identify those responsible.
Federal officials are examining whether Iranian hackers orchestrated the intrusions, though investigators caution that attribution remains preliminary as technical evidence continues to be gathered and analyzed. Some officials are also considering the possibility that the attackers deliberately created the appearance of Iranian involvement to exploit current tensions between the United States and Iran.
Neither Minnesota authorities nor federal agencies have publicly identified the perpetrators.
The FBI, Environmental Protection Agency, and Cybersecurity and Infrastructure Security Administration issued a joint warning Thursday that hostile actors are actively targeting internet-connected industrial control systems used by water and wastewater treatment facilities nationwide. Federal authorities reported that in several instances, the attacks resulted in loss of monitoring and control capabilities at critical infrastructure sites, leading to pressure failures and flooding.
While federal agencies declined to identify specific affected states, they confirmed the problem extends well beyond Minnesota, with incidents documented in at least seven states.
The Minnesota attacks primarily targeted technology used for remote monitoring and control of water system equipment, including programmable logic controllers, according to Minnesota IT Services. These devices serve as the digital nerve centers for water treatment operations, managing everything from chemical dosing to pressure regulation.
Mike Ernster, a public information officer for the Minnesota Department of Public Safety, emphasized that none of Minnesota’s water supplies have been compromised. The Bureau of Criminal Apprehension’s Minnesota Fusion Center is coordinating response efforts with affected municipalities and state and federal partners.
Nick Anderson, acting director of the federal Cybersecurity and Infrastructure Security Administration, confirmed his agency is observing a significant increase in cyber threat actors targeting programmable logic controllers at water utilities across the nation. He urged critical infrastructure owners and operators to immediately remove publicly exposed programmable logic controllers and other operational technology from internet access.
Minnesota investigators have identified similarities in the timing of recent incidents and the types of technology affected, though they have not yet confirmed whether a single actor carried out every attack.
The city of South St. Paul identified suspicious activity early Monday morning and immediately activated contingency procedures. Public works employees transitioned to manual operations, maintaining uninterrupted water and wastewater services throughout the incident. City officials stated the intrusion was limited to technology supporting portions of their infrastructure.
The attacks underscore the vulnerability of American critical infrastructure to sophisticated cyber threats and raise serious questions about the security protocols protecting essential services that millions of Americans depend upon daily. As investigators continue their work, the incident serves as a stark reminder that the nation’s water systems remain attractive targets for hostile actors seeking to disrupt American life.
Related: California Grandmother Found Dead in Church Parking Lot, Son Charged with Murder
