Iran or Incompetence? Where the Minnesota Water Hack Investigation Stands

AP Photo/Ellen Schmidt

President Trump rejected the Iran explanation on Friday and blamed Minnesota Gov. Tim Walz instead. At a televised Cabinet meeting at Camp David, Trump was asked about the cyberattacks that hit more than 30 water systems in the state beginning July 26.

Advertisement

"I think that Minnesota is behind it," Trump said. "You know who's behind it? Minnesota. Because they're grossly incompetent. I think the governor's behind it. I don't think there was an Iranian cyberattack. I think that Minnesota ought to get its act together."

"Iran should be so lucky," he added. "Iran's got bigger problems than worrying about Minnesota."

Walz answered on X.

"Trump knows exactly who is responsible for this attack, and knows that other states were hit too. This is what modern warfare looks like, and it further illustrates there's no plan to win a war with Iran."

In a separate post, he accused the administration of taking "an axe" to the Cybersecurity and Infrastructure Security Agency and credited Minnesota's own cybersecurity staff with finding the vulnerability and helping contain it. Federal investigators have not said the White House knows who carried out the attacks.

The question of who did it remains open. One senior law enforcement official told media sources that the Minnesota attacks bore the hallmarks of Iran-backed hackers, but investigators are also examining whether someone planted evidence to make the operation look Iranian. No federal agency has publicly named a suspect.

Water systems in at least seven states reported incidents to the FBI beginning July 27, and Michigan later confirmed attacks on nine of its systems. Hackers reached internet-facing Rockwell Automation programmable logic controllers, specifically the MicroLogix 1100 and 1400 series, changed IP addresses and set new passwords, and locked operators out of systems used to monitor and run physical equipment. The FBI also received reports of pressure loss and flooding. A pressure drop can allow untreated groundwater to enter distribution pipes. At least one victim found altered project files and programming discrepancies across several locations.

Advertisement

Minnesota activated its statewide cybersecurity response after the first confirmed incidents on July 26 and 27, bringing in the FBI, EPA, CISA, and several state agencies. Braham employees isolated a malfunctioning well and restarted the plant in about 90 minutes. Plymouth disconnected compromised controllers at two water towers and 14 sewer lift stations. South St. Paul moved to manual controls. All three cities kept water running without reported problems involving quality or pressure. Michigan officials said operators handled nine affected systems without any known public health consequences.


Read More: Iranians Now Possibly Implicated in MN Water System Hack

Iran-Linked Hackers Are Targeting America's Water Systems - Most Still Lack Basic Security


Four days before the Minnesota attacks, the FBI, CISA, NSA, EPA, Energy Department, Treasury Department, and U.S. Cyber Command updated a warning about Iranian-affiliated hackers targeting internet-connected industrial controllers at water systems, energy facilities, and government sites. The agencies said the group was acting "to cause disruptive effects within the United States.” The activity resembled earlier operations by CyberAv3ngers, a group affiliated with Iran's Islamic Revolutionary Guard Corps that compromised at least 75 devices beginning in November 2023. The July advisory expanded the scope to include equipment made by Rockwell Automation, Schneider Electric, and Siemens. Investigators have not connected CyberAv3ngers or any other Iranian group to the current attacks.

Advertisement

RedState reported in June that more than 70 percent of drinking water systems inspected by the EPA beginning in 2023 were violating federal requirements. Some still had factory-default passwords. Others used shared credentials that remained available to former employees. More than 153,000 drinking water systems operate nationwide without a mandatory federal cybersecurity standard.

The FBI is telling utilities to remove controllers from the public internet, replace default passwords, restrict remote access, inspect project files for unauthorized changes, and maintain the ability to run systems manually. In at least three Minnesota cities, operators were already doing that under live attack conditions.

Editor's Note: For decades, former presidents have been all talk and no action. Now, Donald Trump is eliminating the threat from Iran once and for all. 

Help us report the truth about the Trump administration's decisive actions to keep Americans safe and bring peace to the world. Join RedState VIP and use promo code FIGHT to get 60% off your VIP membership.

Recommended

Join the conversation as a VIP Member

Trending on RedState Videos