Hackers Hit Water Systems in Seven States. Trump Says the Culprit Is Minnesota.
The FBI, EPA and CISA warned this week that intruders seized control of internet-exposed equipment at water utilities, in some cases causing pressure loss and flooding. Federal investigators are examining whether Iran is behind it; the president blamed the state where more than 30 systems were hit.
Hackers have broken into industrial control equipment at drinking-water utilities in at least seven states, federal agencies said this week, and President Donald Trump responded by blaming not the intruders but the state where the largest cluster of victims sits.
"I blame it on Minnesota because they're grossly incompetent," Trump said, dismissing the possibility of Iranian involvement even as federal investigators actively examine it. More than 30 Minnesota community water systems were targeted between Sunday and Monday, including utilities in South St. Paul, Braham and Plymouth. Georgia and Michigan have reported similar intrusions, with nine separate incidents logged in Michigan after the FBI circulated a warning.
Gov. Tim Walz rejected the president's framing. "Trump knows exactly who is responsible for this attack, and knows that other states were hit too," Walz said, adding that the intrusions are "what modern warfare looks like" and arguing that federal budget cuts driven by the Department of Government Efficiency stripped away cybersecurity support that states had relied on.
The technical picture described by federal agencies is narrow but serious. Attackers went after programmable logic controllers — the small industrial computers that open valves, run pumps and regulate pressure — that operators had left reachable from the open internet. In some cases the intruders changed operator passwords to lock utility staff out of their own systems. The FBI said the attacks caused "loss of monitoring and control functionality at critical infrastructure sites, leading to pressure loss and flooding" at some locations. No contamination of drinking water has been reported.
Nick Anderson, the acting director of the Cybersecurity and Infrastructure Security Agency, issued the bluntest guidance: "We urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible." The FBI, the Environmental Protection Agency and CISA issued a joint nationwide warning Thursday. The Minnesota Department of Public Safety and the Bureau of Criminal Apprehension's Minnesota Fusion Center are working the state-level investigation.
Attribution remains unsettled. Federal agencies briefed state leaders on the possibility of Iranian involvement, which would fit a pattern of Iranian-linked groups targeting American water utilities that predates the current war. But investigators have also cautioned that infrastructure attacks are routinely staged to look like they originate somewhere they do not, and no agency has issued a formal attribution. Small municipal water systems, which often operate with a handful of staff and no dedicated security personnel, have been identified for years as among the softest targets in American critical infrastructure.
Originally reported by ABC News.