Late last week, federal authorities issued a stern warning that cyber threats had intensified as malicious actors targeted water and wastewater facilities in at least seven U.S. states. Minnesota appeared to be the hardest hit, with 30 of its water systems falling victim to cyber-attacks, leading to a range of disruptions. These included reduced water pressure in homes and mandatory boil-water advisories for residents. Despite these issues, there have been no reports of drinking water contamination, which helped prevent a wider public health crisis. The U.S. government has taken note and emphasized the urgency of the situation, especially as infrastructure becomes increasingly interconnected.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) outlined in a statement that the attackers are targeting water systems regardless of their size or scale. This highlights a growing vulnerability within the water infrastructure sector, especially as many systems are now connected to the internet. Hackers have been able to exploit this connectivity by gaining unauthorized access, altering system passwords, and even locking out legitimate operators. CISA warned that these actions can lead to severe disruptions, which could threaten public safety and essential services.
Iran is under suspicion but not officially confirmed
Government officials who have spoken to various news outlets anonymously have pointed to Iran as the likely perpetrator behind the coordinated cyber-attacks. Since the U.S.-Iran conflict intensified nearly six months ago, Tehran has been reported to increase its cyber-activities in the United States. However, so far these efforts have not resulted in major breaches or damages. The FBI has launched an investigation into the cyber intrusions, but it has not yet officially attributed the attacks to any specific country or group. This lack of confirmation has left room for speculation and debate among officials and the public.
Former President Donald Trump offered his own perspective during a cabinet meeting last Friday at Camp David in Maryland. He claimed the attacks were due to Minnesota’s failure and called the state’s leadership “grossly incompetent.” Trump added that he would hold the governor accountable, even suggesting that Iran might not be focusing on Minnesota given their own problems. His comments were met with criticism, as many saw them as dismissive of the actual threat and a failure to address a national security concern.
Minnesota Governor Tim Walz responded by taking to social media to counter Trump’s remarks. He stated that Trump was aware of who was responsible for the cyber-attack and that other states were also affected. Walz stressed that such attacks are a part of modern warfare and criticized the lack of a comprehensive strategy to address threats from Iran and similar actors. His message aimed to highlight the broader implications of the incident and the need for a unified response.
CISA issues urgent warnings and guidance
CISA has a history of warning about cyber threats linked to Iran, particularly in the realm of critical infrastructure. In April, the agency issued a specific alert regarding Iranian-backed cyber-attacks targeting programmable logic controllers used in water systems. On July 22, CISA updated its advisory with detailed guidance for organizations on how to secure their systems against potential breaches. The agency also named specific manufacturers whose systems might be vulnerable, urging businesses to take immediate action. In its advisory, CISA emphasized the urgency of the situation, stating that U.S. organizations must prepare for ongoing cyberthreats targeting internet-connected operational technology.
Calls for better cybersecurity in infrastructure
Cybersecurity experts and industry leaders have repeatedly raised alarms about the vulnerabilities in the U.S. infrastructure. Tatyana Bolton, the executive director of the Operational Technology Cybersecurity Coalition, recently pointed out the consequences of the nation’s lack of investment in cybersecurity for essential systems. She argued that the United States is facing a reckoning as the risks to public safety become more apparent. The coalition, representing a range of infrastructure and cybersecurity companies, has called on the federal government to take action and reinvest in critical defenses.
Bolton and her coalition are advocating for the extension and funding of the State and Local Cybersecurity Grant Program, which is set to expire in September. This program, established in 2021 with a $1 billion allocation, was designed to strengthen defenses for critical infrastructure across the country. Without this funding, Bolton stated, small communities would be left exposed to sophisticated cyber threats from actors like Iran. She emphasized that Congress must step in to ensure that these grants continue, or else the gap in protection could become a serious issue.

