More than 30 water and wastewater utilities across Minnesota, and an unspecified number of utilities in at least six other states, have been targeted in a series of cyberattacks that have disabled digital controls and, in some cases, led to boil-water notices. The Federal Bureau of Investigation (FBI) and the Environmental Protection Agency (EPA) are working with the affected utilities, while the Cybersecurity and Infrastructure Security Agency (CISA) has issued advisories regarding the incidents.
The attacks represent a significant campaign against American industrial control systems, which connect digital software to physical equipment in critical infrastructure. While the FBI's alert did not specify the other affected states or the full extent of the disruption, CISA's advisory indicated potential water contamination due to the disabling of digital controls.
Iranian-affiliated hackers are the leading suspects behind this wave of attacks. A CISA advisory in April initially linked Iranian actors to similar incidents, and a leaked memo obtained by a news outlet confirmed this connection to the more recent Minnesota utility attacks.
In response to the threats, the FBI and CISA have urged utilities to immediately remove internet-connected programmable logic controllers (PLCs) from public access. They also recommend protecting these devices with strong passwords and implementing allow-lists to restrict connections to authorized devices only.
The attacks have drawn a political response, with former President Donald Trump blaming Minnesota's Democratic Governor Tim Walz's administration. This mirrors his past denials of Russian interference in the 2016 election.






