READ. SCROLL. LISTEN.

Unbiased headlines. Facts, not spin.

Every story is an unbiased news briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Suspected Iranian Hackers Hit Water Systems in a Dozen U.S. States, Trump Blames Minnesota

Suspected Iranian Hackers Hit Water Systems in a Dozen U.S. States, Trump Blames Minnesota
Water utilities in at least 12 states were hit by cyberattacks starting in late July, with U.S. intelligence officials pointing to Iran's Islamic Revolutionary Guard Corps. No formal attribution has been made, and President Trump instead blamed Minnesota Gov. Tim Walz for being "grossly incompetent." Drinking water stayed safe, but the attacks exposed just how exposed America's 150,000 water systems really are.

Water utilities across at least a dozen U.S. states got hacked starting in late July. Officials suspect Iran. President Trump blamed Minnesota.

Both things are apparently true at once, and neither one cancels out the other.

What Actually Happened

On July 28, Minnesota officials announced that more than 30 community water systems across the state had been hit by coordinated cyberattacks, according to TechCrunch. Two days later, the FBI, EPA and the Cybersecurity and Infrastructure Security Agency issued a joint warning that water and wastewater utilities in "at least seven states" had been remotely accessed, causing a "loss of monitoring and control functionality."

By August 6, CBS News reported the count had grown to at least 12 states, including Michigan, Minnesota, Georgia, New Jersey and South Dakota. In Georgia, the Clayton County Water Authority, which serves 300,000 customers in the Atlanta area, saw a water pressure drop and had to issue a boil water advisory. Service was restored within hours.

Hackers reportedly gained remote access to pumps, valves and pressure controls at some facilities. Several utilities lost remote-control capability entirely and had to switch to manual operation, according to CBS News and Foreign Policy. CISA said in its advisory that attackers modified passwords to lock operators out of programmable logic controllers, the devices that manage water flow and chemical composition.

No source in this reporting says drinking water was contaminated. CISA, CBS News and the Guardian all confirm drinking water safety was not compromised.

Who Did It

No one has been formally charged or officially named by the U.S. government.

What multiple outlets do report is that U.S. intelligence agencies believe Iran's Islamic Revolutionary Guard Corps is behind the campaign, based on anonymous officials cited by the Washington Post and New York Times, according to the Guardian's reporting. Foreign Policy quoted Cynthia Kaiser, who served as the FBI cyber division's deputy assistant director under President Biden, saying flatly: "I'm incredibly confident that these attacks are Iran. The geopolitical motivation, capability, the recent history of targeting that sector … all of that points to Iran, and there's not a plausible alternative."

CISA had already warned in April, and updated the warning on July 22, that Iranian-linked hackers were targeting internet-connected water system devices, per TechCrunch. That warning came before the Minnesota attacks were even discovered.

The BBC talked to Morgan Wright, a former State Department anti-terror adviser, who said this type of attack is usually attributed to North Korea or Iran, and given the current conflict with Iran, "they go to the top of the list." The BBC also noted U.S. investigators are examining whether the hackers could be posing as Iran-based actors as a deliberate ruse, according to CBS.

The tactics resemble a 2023 campaign by CyberAv3ngers, a group tied to Iran's Revolutionary Guard that exploited water-system controllers using default passwords, CBS News reported. That follows a real pattern rather than speculation.

The Trump-Walz Fight

At a cabinet meeting on July 31, Trump said he didn't think there was an Iranian cyberattack. Instead he blamed Minnesota directly. "I blame it on Minnesota because they're grossly incompetent," Trump said, according to the Guardian. "I would blame it on Minnesota and the governor, the corrupt governor of Minnesota… Iran's got bigger problems than worrying about Minnesota."

Walz shot back on X: "Trump knows exactly who is responsible for this attack, and knows that other states were hit too. This is what modern warfare looks like, and it further illustrates there's no plan to win a war with Iran."

Trump offered no evidence for his claim, and it doesn't hold up well against the fact that at least 11 other states beyond Minnesota reported similar attacks. If Minnesota's water utilities were simply "incompetent," that doesn't explain Georgia, New Jersey, Michigan, South Dakota and Arkansas getting hit with the same playbook in the same window.

There is a fair question buried in Trump's political jab that deserves separate airing from the blame game: are local water utilities, run by cash-strapped municipalities, actually equipped to defend themselves? The answer, per multiple outlets, is no.

The Bigger Problem Nobody's Fixed

IBTimes laid out the uncomfortable backstory. In March 2023, the EPA tried to require states to build cybersecurity assessments into water system reviews. Arkansas, Iowa and Missouri sued, arguing the EPA overstepped its authority and dumped unfunded costs on small communities. A federal appeals court sided with them, and the policy got pulled.

Now Arkansas, one of the states that sued to block those cybersecurity rules, has a water utility that got hit in the current wave, according to the Washington Post's reporting cited by IBTimes. Gus Serino, president of cybersecurity consultancy I&C Secure, told the Post: "The level of effort and expense to fix these systems is not that much. It wouldn't remove all the risk, but would certainly remove most of the low-hanging fruit."

Small municipalities pushed back on federal mandates because of cost and federal overreach concerns. Those concerns weren't unfounded given how thin some local budgets run. But the same systems they were protecting from regulation are now the ones getting popped by foreign hackers using default passwords, a vulnerability that's been flagged since at least 2022, when Microsoft caught a Chinese intrusion into a Guam water system.

No formal attribution has been announced by CISA, the FBI, or the White House as of this writing. No charges have been filed against any individual or group. The investigation into which states beyond the confirmed 12 were hit, and whether the perpetrators are actually Iranian state actors or impersonators, remains open.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
TechCrunchWhat we know about the alleged Iranian hacks on US water utilities
center-left
CBS NewsAt least 12 states report cyberattacks on water systems possibly linked to Iran-backed hackers, sources say - CBS News
left
The GuardianUS water facilities targeted by ‘malicious cyber actors’ – who’s to blame? | Hacking | The Guardian
center
BBCDid Iran hack water systems in at least seven US states?
unknown
foreignpolicyIran-Suspected Hacks of U.S. Water Systems Hit 12 States
unknown
ibtimesSuspected Iranian Hackers Targeted U.S. Water Utilities. Experts Say the Systems Are 'Low-Hanging Fruit' | IBTimes