Iranian-Linked Hackers Suspected in Cyberattacks on Minnesota Water Systems

Federal investigators are looking into whether hackers linked to Iran are behind a wave of cyberattacks that hit more than 30 community water systems in Minnesota, raising fresh alarm about the security of America’s critical infrastructure.

The attacks, which struck on Sunday and Monday, targeted systems used to remotely monitor and control essential equipment, including programmable logic controllers, known as PLCs, which help operate water infrastructure across the state.

The Cybersecurity and Infrastructure Security Agency moved quickly, issuing an alert warning that cyber threat actors had been targeting those PLCs and changing passwords to lock out operators. “This activity has resulted in boil water notices and sustained manual operations,” CISA said.

According to a report, multiple U.S. officials told ABC News that investigators are examining whether Iran or hackers associated with the country carried out the attacks. Those officials cautioned that the forensic review is still ongoing and that no formal attribution has been made by the U.S. government. The New York Times first reported that authorities were probing possible Iranian ties.

Minnesota IT Services confirmed the scope of the compromise, noting that “impacted” does not necessarily mean every affected community experienced a disruption to water service. It means investigators confirmed malicious activity involving a system’s technology.

State officials also clarified that residents have not been asked to change their water usage at this time.

Minnesota Chief Information Security Officer John Israel addressed the situation directly. “We have provided relevant information to the federal government, which is evaluating this activity in the broader national context and leading efforts to determine whether it can be attributed to a specific threat actor,” he said in a statement.

The FBI confirmed it is aware of the intrusions but has not assigned responsibility for the attacks.

The incidents bear a striking resemblance to previous cyber campaigns targeting U.S. critical infrastructure through internet-connected industrial control systems. Federal officials have warned repeatedly that Iran-linked hackers have sought to exploit exactly these types of systems in the past.

CISA is urging water utilities nationwide to strengthen their defenses. The agency recommends disconnecting internet-facing PLCs wherever possible. When remote access is necessary, operators are advised to route connections through a VPN or a secure gateway device to reduce exposure to future attacks.

The investigation remains active, and federal agencies are working to determine who is ultimately responsible for the intrusions.