FBI points to Iran in water-utility hacks, but Walz says DOGE cuts are to blame
The attacks locked operators out of their systems. The FBI says utilities in at least 7 states were hit. Investigators point to Iran — but Minnesota's governor is blaming DOGE.
How the attackers locked operators out of their own systems
Mechanism: Password lockout
Impact: Boil water notices
Operational state: Manual
CISA described a specific attack pattern: intruders modified passwords to lock out operators, then disconnected the PLCs by changing their IP addresses. The result, the agency said, was boil water notices and sustained manual operations at affected utilities. Changing an IP address on a controller effectively orphans it from the network monitoring that operators rely on, forcing facilities to run processes by hand. For a water system, that can mean physically checking and operating pumps and valves. The technique is notable for its simplicity — no sophisticated malware, just credential and network manipulation — and its outsized impact on essential service delivery. CISA said the activity has resulted in boil water notices, which are issued when there is a risk that water pressure has dropped enough to allow contamination into the distribution system.
Recorded Future therecord.media
A coordinated attack began July 26 across Minnesota
Timeline: July 26
Scope: 30+ systems
State: Minnesota
Minnesota's state IT agency said earlier this week that "more than 30 Minnesota community water systems" were affected by a coordinated cyberattack beginning July 26. The attack hit systems across the state simultaneously, suggesting advance reconnaissance and a deliberate, synchronized approach rather than opportunistic scanning. According to CISA, the threat actor is targeting water entities of all sizes, and the agency has warned that even mature utilities may have unnoticed entry points due to cellular modems not included in routine scans. Investigators, including the FBI and the Environmental Protection Agency, are working to determine the full scope of the incident. The coordinated nature of the campaign, which began on July 26, indicates a high level of planning, and the affected systems serve communities across the state. While the attackers' specific methods remain under investigation, CISA has noted that such intrusions often involve locking out operators and disrupting operations.
The FBI says utilities in at least 7 states reported incidents
Scope: 7 states
Response: FBI and EPA
Action: Allow-lists
The FBI said that utility companies in at least seven states have reported incidents involving PLCs to the bureau, underscoring that the Minnesota attacks were not an isolated event. The bureau has not disclosed which states are affected or the full extent of the disruption, but the reports indicate a widespread campaign targeting water systems of all sizes. The FBI, along with CISA and the Environmental Protection Agency, is working with affected utilities to respond and mitigate the impact. The incidents involve unauthorized access to programmable logic controllers, which are central to water treatment processes. While the FBI has not detailed the specific methods, CISA has warned that such intrusions often involve changing passwords and IP addresses to lock out operators, forcing facilities to issue boil water notices and operate manually. The response is ongoing, and utilities are being advised to remove internet-exposed OT assets and validate their external connections.
The evidence pointing to Iran: a WaterISAC memo and an April advisory
Attribution: Iran
Evidence: WaterISAC memo
Advisory: AA26-097A
WIRED obtained a memo from WaterISAC, the water industry's cybersecurity information-sharing body, tying the Minnesota attacks to Iran — the first official documentation of Iran's likely responsibility. The memo connected the more recent attacks to a CISA advisory from April, designated AA26-097A, titled "Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across U.S. Critical Infrastructure." That April advisory had warned that Iranian-affiliated hackers were targeting PLCs in water and other sectors. WaterISAC executive director Tom Dobbins said the organization is "confident in our government partners' assessment that the confirmed activity is aligned" with that advisory, adding that there is evidence of earlier attacks from Iran predating the current conflict. He noted that cyber attacks are the most viable way Iran can directly attack the US homeland, especially given the challenges of absolute attribution.
Walz fired back, pointing to DOGE's cuts at CISA
Response: Walz
Context: DOGE cuts
State: Minnesota
Minnesota Governor Tim Walz struck back at Trump in a Facebook post, noting that the Department of Government Efficiency had taken an axe to CISA, leaving the US exposed to cyber attacks. CISA has shrunk considerably under the Trump administration, and his administration has pushed states to defend against cyberattacks that federal agencies once countered. "Trump knows exactly who is responsible for this attack, and knows that other states were hit too," Walz wrote. "This is what modern warfare looks like, and it further illustrates there's no plan to win a war with Iran." He credited Minnesota's experts with identifying the vulnerability quickly and working with local communities to stop it. Trump has used federal power aggressively in Minnesota, a state Walz has led as a Democrat who was the 2024 vice presidential nominee.
A former top FBI official: 'if it walks like a duck'
Source: Halcyon
Attribution: Iran
Response: Multi-agency
Cynthia Kaiser, a former top FBI cyber official now serving as senior vice president at cybersecurity firm Halcyon, said the bureau's attribution process looks at technical indicators, who has the capability, who has conducted similar attacks in the past, and what the purpose of the attacks is. "Iran ticks all these kinds of things," Kaiser said. "My view is, if it walks like a duck, if it talks like a duck, I strongly suspect it's a duck. I'd be shocked if we found out it wasn't Iran." WaterISAC's Tom Dobbins echoed that confidence and called on Congress to provide funding for the ISAC, noting the water sector is often viewed as one of the most vulnerable critical infrastructure sectors. The FBI, CISA, and EPA have all been involved in the response as the investigation continues.
Where this came from. This breakdown is based on source material published at
therecord.media.
Images above are used with the credits shown beneath each one.