US authorities are tracing cyberattacks that struck more than 30 water systems in Minnesota. The incidents underscore warnings that vulnerable local utilities remain exposed amid suspected Iranian targeting.
Authorities in the US were working to trace the source of cyberattacks that hit more than 30 water systems in Minnesota, even as federal agencies recently warned that Iranian hackers have been focusing on such systems. State officials said they had not yet identified who was behind the attacks, which took place on Sunday and Monday.
There were no reports of residents being affected, though one city briefly asked people to conserve water while officials tried to understand the problem. The FBI is investigating, but has not publicly named a culprit. A spokesperson for the bureau declined on Thursday to say who investigators believed might be responsible.
Last week, the FBI, the Cybersecurity and Infrastructure Security Agency and other agencies said in an advisory that Iranian hackers have been targeting water and wastewater systems, along with operational controls in other critical infrastructure sectors. Digital conflict has become part of military confrontation, and local water plants and healthcare facilities often do not have the money or expertise to install the latest software patches or take other security measures. That has made them a frequent target because they can be easier to penetrate and because disruptions can trigger panic.
Cynthia Kaiser, the former deputy assistant director of the FBI's cyber division, said Iran has the "geopolitical motivations" and a recent record of targeting water systems. Kaiser, who is now the senior vice president of Halcyon's Ransomware Research Center, said, "I think most credible researchers and responders would be right to treat it like it's Iran until proven otherwise." She added, "When it walks like a duck and talks like a duck, it's really important to call it out." Iran's interest in US water systems goes back years. In 2016, the Justice Department charged a group of Iranian hackers over a cyberattack targeting a small dam near New York City.
Minnesota IT Services said on Thursday that there were no active requests from communities for residents to change their drinking water use. The agency said most of the confirmed attacks involved technology used by water systems to remotely monitor and control equipment. It added that a system being counted as impacted meant investigators had confirmed malicious activity involving its technology, and did not mean every affected community had its water service disrupted. The agency also said there were similarities across the incidents, including the timing and the kind of technology involved, but investigators had not determined whether the same attacker was behind each case.
In Braham, officials asked residents for a few hours on Monday to minimise water use while they tried to find out why the water plant was offline. The city later said the outage was caused by a cyberattack, but added that there was no issue with water quality. It said the attackers shut down the operating controls that shut down the well and water treatment plant, leaving the city temporarily able to supply only the water stored in its water tower. In Plymouth, officials said on social media that water infrastructure communications had been restored by Tuesday afternoon after a cyberattack. The city said crews kept the system running during the outage and that there was no impact on water levels or quality. Overall, authorities said the attacks affected multiple systems in Minnesota, but no direct impact on residents had been reported as the investigation continued.
With PTI Inputs
- Ends
Published By:
India Today Web Desk
Published On:
Jul 31, 2026 04:36 IST

1 hour ago

