READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Leaked Memo Ties Minnesota Water Hacks to Iran, But FBI Says Attribution Isn't Final

Leaked Memo Ties Minnesota Water Hacks to Iran, But FBI Says Attribution Isn't Final
A memo shared with water utilities links the cyberattacks that hit more than 30 Minnesota water systems this week to Iran-affiliated hackers, but CBS News and federal officials say formal attribution hasn't happened. Investigators are also checking whether someone faked an Iranian signature to stir chaos amid the ongoing U.S.-Iran conflict.

Since Iran's hackers began striking U.S. targets after Washington launched military action against Iran in late February, hitting medical supplier Stryker and breaching FBI Director Kash Patel's personal email among other intrusions, the campaign has now reached American tap water. A memo obtained by Wired and circulated to members of the Water Information Sharing and Analysis Center (WaterISAC) ties this week's cyberattacks on more than 30 Minnesota water and wastewater utilities to Iran, marking what Wired calls the widest and most disruptive strike by Iranian hackers against the U.S. since the war began.

The memo, drafted with input from the Minnesota Fusion Center, says the state-level intelligence unit found the attacks were "aligned" with a hacking campaign the Cybersecurity and Infrastructure Security Agency (CISA) first described in April as the work of "Iran-affiliated" hackers. Both the WaterISAC note and the fusion center alert were marked unclassified but "for official use only," according to Wired.

Federal officials have not been willing to put their names on this assessment publicly. CBS News reported that U.S. officials and sources familiar with the investigation are still probing whether Iran is actually responsible, and cautioned that any assessment could change as more technical evidence comes in. Investigators are also examining a second possibility: that whoever carried out the attack tried to make it look Iranian, using the ongoing U.S.-Iran conflict as cover to sow confusion. As of Thursday, neither Minnesota nor the federal government had officially attributed the intrusions to any specific actor.

What Actually Happened

The attacks hit programmable logic controllers, the industrial devices utilities use to remotely monitor and run pumps, valves and treatment equipment, according to Minnesota IT Services. Most confirmed cases involved this remote monitoring technology rather than the water supply itself. Mike Ernster, a public information officer for the Minnesota Department of Public Safety, told CBS News that none of Minnesota's water supply has been reported compromised.

CBS News reported federal authorities found loss of monitoring and control functionality at some critical infrastructure sites, leading to pressure loss and flooding in certain cases. The FBI and EPA said the problem isn't confined to Minnesota, with incidents reported in at least seven states, though they didn't name which ones.

On the ground, the disruption was manageable. A spokesperson for South St. Paul told CBS News the city caught an issue early Monday, switched public works staff to manual operations, and kept water and wastewater service running without interruption. The city of Braham, population roughly 1,700, asked residents for a few hours Monday to cut back on water use while crews figured out why the plant had gone offline, according to the Associated Press as carried by ClickOrlando.

The Case for Iran, and the Case for Caution

The argument that Iran is behind this isn't speculation pulled from thin air. Cynthia Kaiser, former deputy assistant director of the FBI's cyber division and now senior vice president at Halcyon's Ransomware Research Center, told the Associated Press that Iran has both the "geopolitical motivations" and a track record of going after water systems. "I think most credible researchers and responders would be right to treat it like it's Iran until proven otherwise," Kaiser said. "When it walks like a duck and talks like a duck, it's really important to call it out."

That history is real. The Justice Department charged Iranian hackers in 2016 over a cyberattack on a small dam near New York City. CISA's April advisory naming "Iran-affiliated" actors as targeting water utility controllers predates this week's Minnesota incidents by months, giving the fusion center something concrete to compare against.

Pattern-matching isn't proof, and federal investigators are the ones saying so on the record. CBS News's sourcing is explicit that no public attribution has been made and that assessments could shift. Nick Anderson, acting director of CISA, confirmed the agency is seeing "a significant increase in cyber threat actors targeting programmable logic controllers (PLC) at water utilities" but stopped short of naming Iran in his public comments, according to CBS News. The FBI similarly declined to name a culprit when asked directly, according to ClickOrlando's reporting on the Associated Press wire.

Water utilities are attractive targets precisely because they're under-resourced. Local plants and healthcare facilities often can't afford the latest security patches, according to the Associated Press, which makes them easier to breach and better at generating public panic when they are.

What Happens Next

CISA's new advisory, released Thursday, tells utilities to disconnect PLCs from the internet, lock them down with strong passwords, and allow-list only trusted devices. Joe Slowik, a former Los Alamos National Labs researcher working under contract for the Department of Energy, told Wired the tradecraft on display, including modification of safety and protection parameters, has rarely been seen outside Russia's war against Ukraine. He warned there's no reason to think the attacks stop with Minnesota: "There are plenty of other sites that have the same targeted technology."

The unresolved question is whether the Minnesota Fusion Center's internal attribution to Iran holds up once the FBI and CISA complete their own technical review, or whether the alternate theory, a copycat spoofing Iranian tradecraft, turns out to be correct. Until federal officials attach their names to a formal attribution, the memo obtained by Wired represents the assessment of one state-level intelligence unit, not a finalized U.S. government conclusion.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
WiredA Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran
center-left
CBS NewsU.S. investigating whether Iran was behind cyberattack on Minnesota water systems
unknown
clickorlandoCyberattacks on Minnesota water systems investigated as officials warn about Iranian hackers