• 4 mins read
  • Published

Trump Rejects Iran Link to Minnesota Water Cyberattack

Jenny Kerr Personal Finance Contributor FinancialSumo

Post by Jenny Kerr

Trump Rejects Iran Link to Minnesota Water Cyberattack FinancialSumo
Trump Rejects Iran Link to Minnesota Water Cyberattack

The president said he blames Minnesota officials, not Iran, for a reported cyberattack on more than 30 water systems, even as federal warnings had flagged Iranian-affiliated hackers targeting similar infrastructure

President Donald Trump brushed aside speculation that Iran was responsible for a reported cyberattack on dozens of water systems in Minnesota, instead putting the blame on state officials and Gov. Tim Walz.

Speaking at a Cabinet meeting Friday at Camp David, Maryland, Trump said the reported intrusion at about 30 water plants was a problem for Minnesota, not a sign of Iranian retaliation or espionage. His comments came after U.S. and state officials reportedly shared a preliminary assessment that Iranian hackers were likely behind the incident.

The split matters because water utilities sit inside a broader U.S. critical infrastructure network that has become a recurring target for foreign and criminal hackers. Even when an attack does not contaminate drinking water, it can still force utilities to shut down automated controls, switch to manual operations, and spend money on recovery, monitoring, and upgrades.

Minnesota IT Services said the coordinated attack targeted operational technology at more than 30 community water systems on Sunday and Monday. The agency said the probe was still active and had not yet identified a specific actor. State health officials said they were not aware of any active requests for residents to change how they used drinking water.

Officials said the intrusions disrupted operations in several communities. In Braham, malicious software temporarily shut down controls for a well and water treatment plant. Plymouth and South St. Paul shifted some operations to manual control. No known threat to drinking water was reported.

The episode came days after federal agencies warned that Iranian-affiliated hackers were targeting the computerized controls used by water systems, power facilities and local governments. Investigators said the campaign had already disrupted some facilities and caused financial losses, with the apparent goal of creating disruption inside the U.S.

That warning was consistent with earlier incidents. In 2023, hackers linked to Iran's Islamic Revolutionary Guard Corps breached programmable controllers at several U.S. water and wastewater facilities by exploiting equipment exposed to the internet and protected by default or missing passwords, according to the Cybersecurity and Infrastructure Security Agency. The affected utilities moved some operations offline, and drinking water was not compromised.

A separate case involved an Iranian hacker who was charged by the Justice Department after repeatedly accessing the control system of a small dam in Rye, New York, in 2013. Prosecutors said the intrusion could have allowed remote operation of the sluice gate, but the gate had been disconnected for maintenance at the time.

Walz responded on X, saying Trump knew who was behind the attack and that other states had also been hit. Trump has repeatedly attacked Walz over fraud in Minnesota's state-administered social services programs. Walz, the 2024 Democratic vice presidential nominee, ended his bid for a third term in January amid scrutiny of his administration's handling of those schemes, though he has not been accused of taking part in the fraud.

For households, the practical takeaway is that cyber incidents at utilities can create costs long before anyone sees an obvious service failure. Manual workarounds, emergency vendor support and forensic cleanup can raise operating expenses for local systems, while weak passwords and exposed equipment remain common points of failure. Those costs ultimately land on ratepayers, taxpayers or both, depending on how local governments finance recovery and security upgrades.

Critical infrastructure operators have been under steady pressure to tighten controls around remote access, internet-facing devices and default credentials. Water systems are especially vulnerable because many are small, under-resourced and run on industrial technology that was not designed for constant online exposure. Even when an attack is limited, it can reveal how quickly a local utility can be forced offline when basic defenses are missing.

Related articles