Authorities in Minnesota are working to determine the source of Minnesota water cyberattacks that targeted more than 30 water systems. The incidents occurred over the weekend, prompting local troubleshooting steps and renewed focus on the security of operational technology used to run drinking and wastewater infrastructure.
As of Thursday, state IT officials said they had not identified who was responsible. The FBI is investigating as well, but has not publicly named a suspect. Meanwhile, U.S. cybersecurity agencies issued earlier warnings that Iranian hackers have been focused on water and wastewater environments, including the systems that monitor and control day-to-day operations.
More than 30 water systems targeted in Minnesota
The attacks were reported to have taken place Sunday and Monday, with officials describing the scale as over 30 affected water systems across the state. In most cases, residents were not reported as being directly impacted. However, some communities took practical measures to manage uncertainty while they confirmed what had happened.
Minnesota IT Services reported that there were no active requests for residents to change drinking water usage as of Thursday. Still, one city asked residents to conserve water for a couple of hours while local teams worked to determine the cause of a problem at its facility.
What investigators say was actually affected
According to Minnesota IT Services, many of the confirmed incidents involved the kinds of technology water systems use for remote monitoring and control. That distinction matters: being “impacted” does not automatically mean that drinking water service was disrupted for everyone.
Investigators said “impacted” refers to malicious activity involving the operational technology used by the water systems, rather than every affected community experiencing loss of water service. The incidents also shared similarities, including timing and the types of technology used, though investigators had not yet confirmed whether a single culprit was behind all events.
In other words, officials are treating the cases as related enough to examine common patterns, while still working through whether the same attacker group—or the same campaign—reached multiple systems.
FBI investigation continues without named culprit
The FBI is leading a component of the investigation, but it has not publicly disclosed who it believes is responsible. A spokesperson declined to say Thursday who the bureau thought might be behind the attacks.
That gap between confirmed technical impacts and publicly shared attribution is common in early-stage cyber investigations. Investigators typically pursue indicators such as infrastructure, malware behavior, and access methods, while also assessing whether the attacks were opportunistic or part of a broader strategy.
Federal advisories highlight Iranian focus on water
In a separate development, federal agencies including the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory last week warning that Iranian hackers have been targeting water and wastewater systems. The advisory emphasized not only the digital networks around these utilities, but also the operational controls that support critical infrastructure sectors.
Digital conflict has increasingly blended into everyday technology, and water facilities can be especially exposed. Many local plants and related healthcare and municipal systems may lack budgets or specialized expertise needed for frequent patching and other security improvements.
That combination—valuable target plus uneven security resources—can make water operations attractive to attackers. Officials have also pointed out that even when physical safety is not immediately compromised, disruption can still create panic and serious operational stress.
Why “treat it as Iran” until proven otherwise
Cynthia Kaiser, a former deputy assistant director in the FBI’s cyber division and a longtime observer of threats to critical infrastructure, said the history and motives involved point strongly toward Iranian involvement. Kaiser said responders and researchers should treat the activity as Iranian “until proven otherwise,” noting that patterns of behavior and context matter when attribution is not yet finalized.
Kaiser referenced Iran’s long-standing interest in U.S. water systems, pointing to earlier activity connected to attacks on critical infrastructure.
Prior history: a 2016 dam-linked case
One previously reported example dates back to 2016, when the U.S. Department of Justice charged a group of Iranian hackers in connection with a cyberattack targeting a small dam near New York City. That earlier case is often used as context when agencies warn that water infrastructure may remain a recurring target.
While the Minnesota incidents are still being analyzed, officials say the broader threat environment is relevant: the same sector, similar operational targets, and overlapping attacker interests can suggest continuity across time—even if each event has unique details.
Braham and Plymouth: two snapshots of local impact
Two cities provided additional information that illustrates how these attacks can look in practice, ranging from limited operational effects to temporary service adjustments.
Braham: controls shut down briefly, water quality not reported as affected
For a few hours on Monday, the city of Braham—population about 1,700, roughly 70 miles north of Minneapolis—asked residents to minimize water use while officials determined why the water plant was offline. In a news release, the city said the outage was due to a cyberattack and did not cause any issues with water quality.
The city stated that attackers shut down operating controls used to stop the well and the water treatment plant. As a result, the city could rely only on water held in the water tower for a period of time.
Plymouth: communications restored, operations continued
In Plymouth, a city of about 80,000 located outside the Minneapolis area, officials posted updates on social media indicating their water infrastructure communications were restored by Tuesday afternoon after a cyberattack.
Crews were able to keep the system running during the outage, and officials said it did not have an impact on water levels or water quality. That suggests that not all incidents escalate into major service interruptions, even when operational systems are affected.
Why these attacks are especially concerning
Water utilities are part of critical infrastructure, and operational systems often connect monitoring and control functions that can influence how equipment runs. Unlike many traditional business IT environments, operational technology can have different constraints and safety expectations.
In practice, that can mean utilities face harder trade-offs when installing updates or making configuration changes. At the same time, attackers may aim to exploit remote management pathways because they can provide a route into the systems controlling physical processes.
The federal advisories highlight that risk: if attackers can influence operational controls, they may disrupt service, force emergency responses, and increase public concern—sometimes even without direct harm to water quality.
What happens next for Minnesota
State officials and federal investigators are continuing to examine the incidents, including the timing and the technology involved. Even with shared characteristics, investigators still need to determine whether one attacker group is responsible for every event or whether multiple campaigns with overlapping techniques occurred.
In the meantime, Minnesota IT Services reported no ongoing statewide requests for residents to alter water use. Local situations may still evolve as communities assess their systems, validate security controls, and confirm whether remote monitoring and control components were accessed or altered.
As attribution work continues, the broader warning from federal agencies remains in the background: similar targets and tactics can link cyber activity across regions, and water operations may continue to be a focus of sophisticated attackers.
Conclusion
Minnesota water cyberattacks affecting more than 30 water systems are under active investigation, with officials reporting limited direct impacts to residents. The FBI has not publicly named a culprit, while federal agencies emphasize a warning about Iranian hackers targeting water and wastewater operational environments.
For local utilities, these incidents reinforce the importance of securing remote monitoring and control systems, strengthening incident readiness, and sharing timely information so communities can respond quickly—without overreacting when water quality is confirmed to be unaffected.
