The recent cyberattacks on water systems in 30 community water systems in Minnesota as well as at least six other states as reported by the FBI reflects a growing concern about hacking of critical infrastructure by foreign governments, primarily Iran. Water systems have long been particularly attractive targets for our adversaries as these utilities provide essential services but often use outdated industrial control systems with many water systems lacking even basic cybersecurity precautions.

HISTORY OF WARNINGS

I first warned about these attacks in 2016 and again in 2022.

Congress’ Cyberspace Solarium Commission issued a report in 2020 concluding that “water utilities remain largely ill-prepared to defend their networks from cyber-enabled disruption.”

In 2023 the EPA issued cybersecurity best practices and updated them in 2024 recommending security practices and risk management for water systems, however these standards were voluntary rather than mandatory.

In 2023 the EPA did attempt to implement regulations requiring states to evaluate cybersecurity during water system inspections, however, this was challenged in court by Missouri, Arkansas and Iowa arguing that the EPA did not have the authority under the Safe Drinking water Act to enact such regulations which led to the EPA withdrawing its proposed regulations.

In a letter to the governors of all 50 states on March 18, 2024, then EPA Administrator Michael Regan and White House National Security Advisor Jake Sullivan urged the states to implement plans to prevent cyberattacks on water systems. In their letter they wrote “Drinking water and wastewater systems are an attractive target for cyberattacks because they are a lifeline critical infrastructure sector but often lack the resources and technical capacity to adopt rigorous cybersecurity practices.”

In 2024 the EPA issued a warning that attacks against water systems were occurring increasingly more often. According to the EPA 70% of federally inspected water utilities failed to meet necessary cybersecurity standards.

In an April 2026 warning the EPA, FBI, Cybersecurity and Infrastructure Security Agency (CISA), and National Security Agency (NSA) issued a joint advisory warning of an urgent and ongoing Iranian-affiliated cybersecurity threat. In the warning they indicated that water and wastewater systems were being attacked through their operational technology.

Even more recently, the attack against the Minnesota water facilities occurred only four days after the CISA issued a warning that Iranian backed hackers were targeting critical infrastructure including water systems through attacking Internet connected automated devices used to manage infrastructure systems.

HOW THE ATTACKS OCCURRED

Most of the confirmed Minnesota cyberattacks involved the technology used to remotely monitor and control water system equipment including programmable logic controllers which are devices used to remotely monitor and control machinery. This brings up the distinct possibility of the attacks being supply chain attacks Supply chain attacks generally involve hacking a third party such as a software provider, cloud service provider, manufacturer of industrial control equipment or, as in this case, a remote monitoring company. Many water utilities use the same contractors to manage industrial control systems remotely.

In 2023 and 2024 the Iranian hacker group CyberAV3ngers hacked water systems in the United States by attacking programmable logic controllers These are the same devices used in the attacks on Minnesota water systems. Most disturbingly inn the 2023 and 2024 attacks the hackers exploited internet connected controllers used by water facilities where the facilities negligently failed to change the default passwords that came with the equipment. These default passwords are readily available to anyone.

While the attacks of late July have not yet been conclusively determined to have been done by Iranian hackers, researchers have noted the attacks follow the pattern previously associated with Iranian based hackers such as CyberAV3ngers.

PRESIDENT TRUMP WEIGHS IN

Despite all evidence pointing to the attacks being done by Iranian backed hackers, President Trump thinks otherwise. According to Trump, “I think that Minnesota is behind it. You know Who’s behind it? Minnesota. Because they’re grossly incompetent. I think the governor’s behind it. I don’t think there was an Iranian cyberattack.”

HOW TO FIX THE PROBLEM

Meanwhile there are specific steps that can be taken to reduce the threat of similar attacks including the following:

  • Removing internet exposure of industrial control systems;
  • Use of complex passwords. The use of default passwords for programmable equipment is inexcusable.
  • Requiring multifactor authentication for remote access;
  • Continuous vulnerability scanning and monitoring;
  • Replacement of out-of-date equipment and regular software updating of software programs with security patches;
  • Cybersecurity training for personnel;
  • Increased federal funding to small utilities that lack proper cybersecurity personnel.

We have been warned for years about this problem and the fixes, many of which are easily achievable, are long overdue.