U.S. spy agencies suspect Iran launched cyberattack on Minnesota water facilities
The agencies have assessed that Iran was likely behind a coordinated cyberattack on more than 30 municipal water systems in Minnesota this week, according to several U.S. officials.

U.S. intelligence agencies have assessed that Iran was likely behind a coordinated cyberattack on more than 30 municipal water systems in Minnesota this week, according to several U.S. officials.
The FBI is investigating the attack, which comes as a five-month-old military conflict between the United States and Iran threatens to escalate.
Though intelligence agencies have not definitively concluded that Tehran is responsible, the hack follows urgent warnings by federal cybersecurity officials that Iran for months has been targeting internet-exposed devices that control operations at water, wastewater, and energy facilities in the U.S. and, in some cases, causing disruptions.
Intrusions have been noted at several water and energy systems across the country since shortly after the war began on Feb. 28, said Joe Slowik, director of threat research for Dataminr, a real-time commercial intelligence platform.
“It is not a secret that these things have been taking place since the spring,” he said. “There have been disruptions in multiple critical infrastructure sectors. It’s a big deal.”
The New York Times earlier reported that federal and state investigators believe Iran was likely responsible for the Minnesota attacks.
At least one system was briefly offline and another saw its remote sensors disrupted, but the state’s information technology agency notes that there are no active requests for Minnesotans to modify their drinking water usage.
The attacks took place on Sunday and Monday, according to a statement by Minnesota IT Services, the information technology agency.
The agency, as well as the affected municipalities, are working with state and federal authorities to share threat intelligence and remediate the attack.
Nate George, the mayor of Braham, Minn., said in an online statement that his city’s public works department discovered the attack early Monday morning. After learning at least four other Minnesota communities were affected, they determined the plant had been hacked.
“Public works isolated the affected system, restored a backup, and restarted the plant within approximately 90 minutes,” George said of the city’s response, noting that Braham’s residents received water from the city’s water tower while the plant was offline.
In the city of Plymouth, several devices that control the water and sewer systems’ operations were hacked and taken offline but have now been restored, said Michael Thompson, the city’s public works director. The water supply was not affected, he added. But devices known as programmable logic controllers, or PLCs, which operate on the city’s cellular network and track water level, pressure, pump operations, and equipment alarms, were impacted.
Iran has been actively targeting the U.S. with cyberattacks since the war started on Feb. 28, but most have not drawn headlines.
Kurt Gaudette, head of intelligence for Dragos, a cybersecurity firm that specializes in protecting critical infrastructure, noted a pattern with attacks in March and in Minnesota: the targeting of small utilities that use internet-exposed controllers with default passwords. “It’s very low-hanging fruit,” Gaudette said.
He said he has seen such attacks in the past, notably in late 2023, when a PLC at a municipal water pumping station in Aliquippa, Pa., was hacked. The attack, which caused no major disruption, was claimed by a group affiliated with Iran’s hard-line Islamic Revolutionary Guard Corps and known as CyberAv3ngers.
The Aliquippa station used PLCs made by an Israeli firm, Unitronics, which were targeted by the hacking group across the U.S., Britain, Israel, and Ireland. Israel had just begun its invasion of Gaza in response to the attack by the Palestinian militant group Hamas that killed about 1,200.
In general, Iran’s goal with cyberattacks seems to be less outright destruction than to deliver psychological effects to two audiences, said Alex Orleans, head of threat intelligence at Sublime Security, an email security company.
“The first is the American people, to make us freak out and to turn sentiment against the war by making it look like it’s not worth the costs, when in reality our systems are pretty resilient,” Orleans said.
The second is the Iranian regime itself, he said. “They want to show their bosses that they’re contributing to the war effort.’'
Slowik, who tracks foreign cyber threat actors, said that the events in Minnesota and other states, including in the Eastern U.S., are the work of Iran’s Islamic Revolutionary Guard Corps’ Cyber Electronic Command.
Iran’s actions “reflect a desire or need to say, ‘Hey, we can hit you too, even if it’s not New York City or Los Angeles,” Slowik said.
The Department of Homeland Security’s Cybersecurity and Infrastructure Agency issued advisories in April and July noted that the IRGC was exploiting PLCs.
On Thursday, the agency issued a new advisory saying that it is seeing “a significant increase” in cyber threat actors targeting programmable logic controllers in the water and wastewater system sectors. CISA urged they be disconnected from the internet as soon as possible and that default passwords be changed.
In March, the IT systems of a major medical equipment maker, Stryker, were disrupted for two to three weeks by a hacktivist front group known as Handala, which the Justice Department said is operated by Iran’s Ministry of Intelligence and Security.
Handala also claimed earlier this year to have hacked the personal email account of FBI Director Kash Patel.