30+ Minnesota Water Utilities Hit in Cyberattacks Tied to Iranian Hackers
More than 30 water and wastewater systems across Minnesota were hit by coordinated cyberattacks on Sunday and Monday, prompting investigations by the FBI and state authorities. Minnesota IT Services confirmed malicious activity targeting the remote monitoring and control equipment used by municipal utilities, though it stressed that being "impacted" did not mean every community experienced service disruption. The city of Braham briefly asked residents to conserve water on Monday while technicians investigated anomalies, but no broader outages were reported as of Thursday.
The intrusions came one week after the FBI, CISA, and partner agencies issued an advisory warning that Iranian state-linked hackers were actively targeting U.S. water and wastewater facilities, along with operational technology (OT) in other critical infrastructure sectors. Former FBI cyber division deputy assistant director Cynthia Kaiser, now senior vice president at Halcyon's Ransomware Research Center, said the incidents should be treated as Iranian in origin until proven otherwise. "When it walks like a duck and talks like a duck, it's really important to call it out," Kaiser told reporters. The FBI has not publicly named a culprit, and an agency spokesperson declined to comment on attribution Thursday, while the state agency noted that timing and target technology shared similarities that investigators have not yet tied to a single actor.
The campaign exposes a longstanding weakness in municipal water infrastructure: small utilities often lack budgets and expertise to apply timely software patches or implement modern network segmentation. Attackers are increasingly drawn to OT environments because exposed remote-access interfaces, unpatched PLCs, and weak authentication controls make them comparatively easy to penetrate—and service disruptions generate outsized public attention. Security teams concerned about perimeter exposure can quickly audit the attack surface of remote management interfaces with a port scanner, verify that traffic between SCADA networks and the internet is properly encrypted using a SSL/TLS checker, and review administrative credentials protecting OT dashboards through a password checker to flag reused or weak logins.
Iran's interest in U.S. water systems is not new. In 2016, the Justice Department indicted a group of Iranian hackers for breaching the controls of a small dam near New York City. Minnesota IT Services confirmed Thursday that there were no active requests for residents to alter their drinking water usage, and emphasized that the malicious activity probed supervisory systems rather than necessarily disrupting service. With critical infrastructure remaining a top-tier target for state-aligned APTs, the Minnesota incident underscores the urgent need for OT-focused threat intelligence and incident response planning across the water sector.