Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers

Minnesota’s Water Systems Under Siege: Iranian Hackers Suspected in String of Cyberattacks

A coordinated cyberattack has targeted over 30 water systems in Minnesota, leaving officials scrambling to identify the source and mitigate potential damage. The incidents have sparked concerns about the vulnerability of critical infrastructure to digital threats, particularly from Iranian hackers who have been linked to similar attacks on US water systems.

The FBI is leading the investigation into the attacks, which occurred on Sunday and Monday, with no reported disruptions to public drinking water supplies. However, one city was forced to ask residents to conserve water for a few hours while officials worked to determine the cause of the problem. The Minnesota IT Services agency has confirmed that most of the affected systems used technology to remotely monitor and control equipment, but emphasized that being impacted does not necessarily mean every system had its service disrupted.

The timing and tactics employed by the attackers are eerily similar, with investigators yet to confirm whether multiple perpetrators were involved or if it was a single entity. The similarities have led experts to point fingers at Iranian hackers, who have been actively targeting water systems in the US for several years. In 2016, a group of Iranian hackers was charged with a cyberattack on a small dam near New York City.

Cybersecurity expert Cynthia Kaiser, former deputy assistant director of the FBI’s cyber division, believes that Iran has both the geopolitical motivations and the track record to justify suspicion. “When it walks like a duck and talks like a duck, it’s really important to call it out,” she said. Kaiser notes that Iranian hackers have consistently targeted critical infrastructure, including water systems, due to their relative ease of penetration and potential for disruption.

The incident serves as a stark reminder of the digital threat landscape facing local governments and critical infrastructure operators. With many small municipalities struggling to keep pace with cybersecurity best practices, the risk of successful attacks remains high. As Kaiser pointed out, “digital warfare has become ingrained in military conflict,” making it essential that these organizations prioritize their security posture.

In practical terms, this means that water system operators must take proactive steps to fortify their defenses, including implementing robust monitoring and detection tools, conducting regular software updates, and engaging with cybersecurity experts. For residents, being aware of potential disruptions and taking simple precautions such as conserving water during emergencies can help minimize the impact of these events.

Ultimately, this incident highlights the pressing need for enhanced collaboration between government agencies, critical infrastructure operators, and cybersecurity experts to stay one step ahead of emerging threats. By acknowledging the digital risks facing our most vital systems and working together, we can mitigate the potential damage caused by malicious actors like Iranian hackers.


Source: SecurityWeek — 2026-07-31