More than 30 Minnesota community water systems got hit by malicious cyber activity this week, forcing some utilities to ditch their automated controls and run things by hand while federal investigators try to figure out whether Iran just attacked America's drinking water. No water supplies were reported compromised. But the fact that we are even having this conversation should alarm you.
What Actually Happened Out There
The attacks, which CBS News first reported, targeted programmable logic controllers, the devices that remotely monitor and operate water system equipment. Think of them as the nervous system of a water utility. Hit those, and the whole operation goes haywire.
In South St. Paul, city officials spotted the problem early Monday and immediately flipped to manual operations. Water kept flowing. In Braham, a small city north of Minneapolis, workers noticed their well pump had gone offline and traced it back to a compromised system. They isolated it, restored a backup, and had things running again in roughly 90 minutes. Mayor Nate George confirmed to CBS News that residents never lost service.
The good news is that the attackers, whoever they are, did not manage to contaminate or cut off the water supply. The unsettling news is that more than 30 utilities were hit in what appears to be a coordinated wave, and investigators have not yet confirmed whether the same actor was behind every single incident.
Iran Is the Leading Suspect, With a Caveat
U.S. officials and sources familiar with the investigation told CBS News that investigators are probing whether Iranian hackers carried out the attacks. But those same sources were careful to flag that the attribution is not yet definitive, and that the technical evidence is still being assembled.
There is a wrinkle here worth sitting with. Investigators are also considering whether whoever did this deliberately made themselves look Iran-based, specifically to stir the pot at a moment when U.S.-Iran tensions are already at a boil. Someone staging a false flag on American water infrastructure would be a remarkable escalation. But so would Iran actually doing it. Either way, someone with serious capabilities decided this week was a good time to poke America's drinking water.
This is not Iran's first rodeo with U.S. water systems. Federal agencies previously confirmed that hackers affiliated with Iran's Islamic Revolutionary Guard Corps hit multiple U.S. water and wastewater facilities in 2023, exploiting internet-connected controllers that still had their factory default passwords set. The same basic playbook, apparently, used again.
The Feds Are Watching, and They Are Worried
Nick Anderson, acting director of the Cybersecurity and Infrastructure Security Agency, confirmed to CBS News that his agency is "currently observing a significant increase in cyber threat actors targeting programmable logic controllers at water utilities." CISA is part of the Department of Homeland Security, and its public advisory this week made clear the targeting covers water entities of all sizes, not just large urban systems.
CISA's advisory included a detail that should give every local water utility manager a cold sweat: the targeting activity includes cellular modems installed by operators, vendors, or outside system integrators that may not even be documented or included in routine security scans. In plain English, there are back doors into some of these systems that the people running them may not know exist.
The agency's guidance was blunt: get your programmable logic controllers off any public-facing internet connection immediately. The FBI told CBS News it was aware of the incidents and in contact with victims, and then declined to say anything else useful, which is very on-brand for the FBI.
The Password Problem That Will Not Die
The 2023 IRGC attacks on U.S. water facilities worked because the targeted controllers were sitting on the internet with their default passwords unchanged. Default passwords. The kind that come printed in the manual. The kind that are, by definition, the same for every device of that model ever manufactured.
We do not yet know exactly how the attackers got into these Minnesota systems. Investigators are still working that out. But the fact that CISA felt compelled to issue an advisory telling water utilities to take their equipment off the public internet suggests the vulnerability window here is not complicated or exotic. These are basic security hygiene failures exploited at scale.
That should make you furious, because the targets here are not defense contractors or intelligence agencies with multi-million-dollar security budgets. They are small municipal water departments in places like Braham, Minnesota, a city where the mayor is personally fielding calls from CBS News about a cyberattack. These communities do not have cybersecurity teams. They have public works employees who noticed something was wrong with a pump.
The Dingo Take
Thirty-plus water systems. One week. A foreign adversary, possibly Iran, possibly someone pretending to be Iran, apparently scanning American infrastructure for open doors and walking right through them. And the door in question is not some sophisticated zero-day exploit requiring a nation-state's best hackers. It is a programmable logic controller plugged directly into the public internet, maybe with a default password, maybe with a cellular modem that nobody bothered to put in the security scan. This is the state of American critical infrastructure security in 2026.
The Trump administration has spent the better part of this year gutting the federal agencies responsible for exactly this kind of threat. CISA has had its budget pressured, its workforce hollowed out through DOGE-adjacent cuts, and its leadership left in acting roles. The agency that just told every water utility in America to get their equipment off the internet is the same agency that has been treated as expendable by the administration now overseeing this investigation. You do not get to slash cybersecurity infrastructure and then act surprised when critical infrastructure gets hit.
And for the record: the 2023 IRGC water facility hack worked because of default passwords. The same issue, apparently still alive and well three years later. If a small city in rural Minnesota getting its pump knocked offline by a foreign cyberattack does not prompt a serious national conversation about hardening the most basic public infrastructure Americans depend on every single day, nothing will. At some point the lesson has to land.
Comments