Federal and state officials are investigating a recent cyberattack targeting dozens of municipal water systems in Minnesota, with preliminary assessments linking the incident to hackers believed to be affiliated with Iran. The intrusion, detected late July 26 and 27, affected approximately 36 community water systems, primarily involving the remote management and monitoring infrastructure for water towers.

Authorities cautioned that attribution remains tentative and subject to revision as the investigation progresses, and noted the possibility that the attackers might be attempting to impersonate Iranian actors to exacerbate geopolitical tensions. Nonetheless, cybersecurity experts and former intelligence officials consider an Iranian origin plausible, citing the nature of the attack—which focused on disruption rather than financial extortion—and past patterns of Iranian cyberactivity against U.S. critical infrastructure.

Local officials in Minnesota reported that at least one municipal water well and treatment plant temporarily went offline, while other systems implemented manual overrides to maintain service continuity. There were no reports of contamination or compromised water safety. Several affected municipalities issued conservation advisories briefly but subsequently lifted them once systems were restored.

John Israel, Minnesota’s chief information security officer, described state authorities as early detectors of the attack and emphasized ongoing warnings to municipalities nationwide about similar threats. He noted evidence that comparable cyber intrusions may be underway in other states, though details were not disclosed.

The Federal Bureau of Investigation confirmed awareness of the incident and engagement with victims as part of an active investigation but declined to provide further specifics. Matthew Vogel, an FBI spokesperson, affirmed ongoing efforts to resolve the matter.

Separately, the Cybersecurity and Infrastructure Security Agency (CISA) issued a public advisory just days before the Minnesota breach, highlighting attempts by Iranian-affiliated actors to compromise operational technology systems integral to water and wastewater management. Acting CISA director Nick Andersen emphasized the urgency for system operators to disconnect vulnerable devices from the internet to mitigate risk.

Since the escalation of hostilities between the United States and Iran earlier this year, there has been an uptick in Iranian cyber operations targeting U.S. entities. While most have had limited disruptive effects, notable incidents include a March attack on medical equipment manufacturer Stryker, causing a temporary shutdown, and the release of personal communications from a former government official by an Iranian-linked group.

Nate George, mayor of Braham, Minnesota—one of the affected communities—urged policymakers to recognize the increasing sophistication of cyber threats facing local infrastructure. He highlighted the challenges small municipalities face in securing essential services amid constrained resources and aging technology.

Iranian officials have not publicly responded to inquiries regarding the suspected attacks. Investigations remain ongoing as federal and state authorities work to assess the full scope and implement protective measures across critical water systems.