The FBI and Environmental Protection Agency (EPA) have issued a joint warning about a wave of cyberattacks targeting municipal water systems in at least seven states. This alert comes after more than 30 water facilities in Minnesota were compromised in an attack with suspected Iranian involvement. Authorities are urging utilities nationwide to bolster their cybersecurity defenses.
The recent incidents highlight the vulnerability of critical infrastructure to cyber threats. The FBI and EPA have not named the states affected, but the attacks have raised concerns about the potential for widespread disruption. The Minnesota IT Services Agency confirmed that the breaches did not contaminate any water supplies, but the federal Cybersecurity and Infrastructure Security Agency (CISA) reported that some attacks resulted in boil water notices and manual operations.
Minnesota Under Siege: Cyberattacks on Water Systems
Minnesota has been at the epicenter of these cyberattacks, with hackers targeting the operating technology of over 30 water systems, including Plymouth’s. The attackers remotely accessed internet-facing devices, changed IP addresses and passwords, and disrupted monitoring and control capabilities. Despite these intrusions, Minnesota officials emphasized that there was no evidence of widespread pressure changes or law enforcement responses triggered by the attacks.
The Wisconsin Department of Natural Resources issued a bulletin warning that systems within the state could be susceptible to similar cyber threats. While no confirmed breaches have been reported in Wisconsin, officials expressed concern about the ongoing risk. The bulletin highlighted that Minnesota had reported incidents where hackers managed to drop system pressures, triggering alarms and law enforcement responses in several cases.
Political Reactions and Attribution Challenges
President Donald Trump has publicly blamed Minnesota’s leaders and Governor Tim Walz for the cyberattacks, calling them ‘grossly incompetent.’ Trump dismissed suggestions of Iranian involvement, stating, ‘Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota.’ In response, Governor Walz accused Trump of deflecting responsibility and emphasized the broader context of modern warfare and the lack of a plan to address Iran’s cyber capabilities.
The FBI and EPA advisory focused on the tactics used in the attacks rather than attributing blame to a specific actor. The federal advisory highlighted that malicious cyber actors targeted specific brands of control systems used by municipal water utilities. Operators were urged to take precautions, including removing programmable logic controllers (PLCs) from direct internet exposure and using strong passwords.
Federal Response and Cybersecurity Measures
The federal government has been proactive in addressing these cyber threats. CISA, along with the FBI and other federal agencies, issued a public advisory on July 22, urging companies to boost their defenses Against Iran-backed hackers. U.S. intelligence agencies have cautioned that Iran is increasingly capable and willing to carry out aggressive cyber operations, including previous attempts to target water systems in 2026.
Bryson Bort, founder of the cybersecurity company Scythe, emphasized the need for public awareness of the risks posed by infrastructure breaches. ‘We need to be prepared,’ Bort said. ‘Attacks like this illustrate that there are folks who mean the U.S. harm today.’ The federal advisory calls on system operators to implement robust cybersecurity measures, including securing PLCs behind firewalls and limiting communications between authorized control system devices.
As the investigation continues, authorities are working to attribute the attacks and develop strategies to mitigate future threats. The recent incidents serve as a stark reminder of the importance of cybersecurity in protecting critical infrastructure.



