TodaySaturday, August 01, 2026

Iran Hackers Hit Thirty Minnesota Water Systems. Trump Says It Wasn’t Iran.

Federal agencies assessed Iran likely behind the coordinated PLC attack on over thirty Minnesota water utilities. Trump pointed at Tim Walz.
August 1, 2026
Tehran Iran Milad Tower skyline as US intelligence assesses Iran behind cyberattack on Minnesota water infrastructure
Tehran, Iran, where the government denied involvement in the coordinated cyberattack on over thirty US water utilities, even as federal intelligence assessed Iran as the likely perpetrator. [Image Source: Sputnik]

WASHINGTON – The call came early on a Tuesday morning in Plymouth, Minnesota: the programmable logic controllers governing two municipal water towers and fourteen sewer lift stations had been accessed remotely, their configurations altered, their control panels no longer responding the way operators expected. No water was contaminated, pressure held, and the city kept the taps running. But for a window of time that Plymouth officials declined to specify precisely, the logic governing the hardware that keeps an American city’s water system functional was not under American control.

The Plymouth incident was one of more than thirty similar breaches recorded across Minnesota in a single week, part of a coordinated assault on municipal water infrastructure spanning at least seven states. The Federal Bureau of Investigation and the Environmental Protection Agency issued a joint public service announcement Thursday warning utilities nationwide about a “significant increase” in malicious activity targeting internet-exposed programmable logic controllers, the industrial automation hardware at the core of water treatment, distribution, and wastewater operations across the country, NBC News reported.

What happened next in Washington illustrated why these breaches may stay in the news cycle longer than the technical facts alone would warrant. President Trump, informed of the attack at a Thursday cabinet meeting, did not point to Iran. He pointed to Minnesota. “I think that Minnesota is behind it,” Trump said. “I don’t think there was an Iranian cyberattack.” The president described the breaches as evidence of governance failure by Governor Tim Walz, characterizing the situation as a product of “weak management” and adding, “look at who runs that state.”

His own intelligence community reached a different conclusion. US officials, speaking to multiple news organizations on condition of anonymity because the assessment had not been formally declassified, said the attack bore “hallmarks of Iranian meddling.” Analysts assessed Iran as the “likely” perpetrator, CBS News reported. The assessment stopped short of definitive attribution, which typically requires time and corroborating evidence that agencies had not yet assembled, but the gap between what Trump said publicly and what his intelligence services told him privately was, by any reasonable reading, substantial.

The operational details give the breach texture that political disputes can obscure. In Braham, Minnesota, operators switched to backup procedures after PLCs were compromised and restored normal operations within approximately ninety minutes. South St. Paul activated contingency procedures and conducted a review before certifying that water quality and pressure had not been affected. Plymouth’s situation was more complex: PLCs at two separate water towers and fourteen sewer lift stations had been accessed and their configurations altered in ways that took longer to document and untangle. All three cities reached the same determination on water quality, but the operational picture was of a system probed in depth, not merely tested at the edges.

The Cybersecurity and Infrastructure Security Agency had tried to warn utilities that this was coming. On July 22, nine days before the attacks, CISA and the FBI issued a joint advisory warning that Iran-linked hackers were targeting critical infrastructure, specifically naming internet-facing programmable logic controllers at water utilities as a high-priority vulnerability. Many small municipal water systems operate with limited cybersecurity staff; PLCs purchased years or decades ago were not designed with internet connectivity in mind and were retrofitted into remotely-accessible configurations without the security hardening that connectivity requires. CISA described the attacks as exploiting exactly that gap.

Iranian Arash-series drone as US intelligence assessed Iran behind coordinated cyberattacks on American water infrastructure
File photo of Iranian military drone technology. US intelligence assessed Iran as the likely perpetrator of coordinated cyberattacks on municipal water systems across seven American states. [Image Source: Sputnik / Tasnim News Agency]

The infrastructure vulnerabilities CISA warned about are not new. The same combination of internet-exposed PLCs and under-resourced municipal utilities was identified as a critical weakness in a 2023 EPA advisory that triggered a legal dispute with water industry groups who argued the compliance burden was excessive. That dispute was resolved in the industry’s favor; the EPA’s cybersecurity mandate for water utilities was stayed. The Minnesota breaches happened, in part, into an oversight gap that existed because the water industry successfully argued against closing it.

Against the backdrop of the Iran-US military conflict running since the spring, the cyberattacks carry a dimension beyond their technical specifics. Iran has struck US military bases across the region in successive waves, and Iranian forces struck two oil tankers under US air escort in the Strait of Hormuz on Friday, the same day the water system advisory was published. The pattern suggests Iran is pursuing simultaneous pressure across multiple domains: military, maritime, and now civilian infrastructure. Each domain carries its own deterrence calculus, and the civilian infrastructure domain is the one where US defensive posture has most visibly lagged.

The financial consequences of the broader Iran-US conflict are already flowing to unexpected places. ExxonMobil and Chevron posted their largest quarterly profits in years Thursday as Iran war-driven oil prices kept Brent crude above $100 a barrel. American families paying above $4.50 a gallon absorbed the cost on one end while the intelligence community absorbed a different message: that Iran’s campaign to impose costs on the United States has found a new and relatively cheap vector in the control systems running infrastructure that American cities have never seriously hardened against remote access.

Trump’s dismissal of the intelligence community’s assessment is not unprecedented. His first administration was marked by repeated public divergences from intelligence conclusions, particularly on Russia. The Iran pattern follows a different logic: acknowledging that Iran successfully hacked thirty American water systems in a week while CENTCOM was conducting air strikes against Iranian targets would raise uncomfortable questions about whether the air campaign was producing the deterrence Trump has claimed. Blaming Tim Walz requires no such reckoning.

What the week’s events do not yet resolve is whether Iran will push further. A PLC compromise that produces no contamination is a demonstration, not a catastrophe. CISA has described its current observation as a “significant increase” in such activity, phrasing that implies the pattern is ongoing. The FBI advisory noted that the same methods used in Minnesota could be replicated at water utilities in any state with internet-exposed PLCs, which according to federal data is most of them. The technical gap exploited in Plymouth, Braham, and South St. Paul last week exists in hundreds of other municipalities that have not yet been targeted, or have not yet discovered they were.

Synthia Rozario

Synthia Rozario

Synthia Rozario is a Senior Correspondent at The Eastern Herald covering technology, geopolitics, business, and international affairs across multiple continents.

Leave a Reply

Don't Miss