Particle.news
Download on the App Store

U.S. Says Iran Likely Behind Cyberattacks on Dozens of Minnesota Water Systems

Federal agencies are leading an active probe and urge operators to remove internet‑exposed controllers to stop further disruption.

Overview

  • State officials say operational technology used to monitor and control water plants was targeted, with investigators confirming malicious activity at more than 30 community water systems.
  • Investigators have a preliminary assessment that Iranian‑linked hackers were probably responsible based on the tradecraft used and the absence of a ransom demand, though formal attribution is not yet complete.
  • Federal agencies including the FBI, CISA and EPA have opened an active investigation and issued advisories telling water operators to disconnect or shield programmable logic controllers, use gateways or VPNs, and change default passwords.
  • Some municipalities briefly lost automated control and switched to manual or backup procedures, and officials report no evidence that drinking water was contaminated.
  • The incidents, which federal notices say followed similar activity in multiple states and in some cases involved changed passwords and blocked remote access, highlight how aging, internet‑exposed controllers leave local utilities vulnerable and could raise broader security and diplomatic risks.