What happened in Minnesota
Starting the weekend of July 25 and continuing into the following week, attackers targeted operational technology at water utilities across Minnesota. In Braham, a small city of roughly 1,700 residents about 70 miles north of Minneapolis, attackers disabled operating controls for the city's well and treatment plant, prompting officials to ask residents to minimize water use for several hours while they investigated the outage. In Plymouth, a much larger suburb of about 80,000 people outside Minneapolis, water infrastructure communications were disrupted before being restored.
State officials said more than 30 water systems across Minnesota showed signs of the same coordinated activity. By the following Thursday, officials confirmed there had been no active attempts to alter water treatment chemistry or safety parameters, and that the investigation into the intrusions was ongoing. CISA and the FBI subsequently updated public advisories warning that Iranian hackers have been actively targeting programmable logic controllers and other operational technology across water and wastewater systems and other critical infrastructure sectors.
The attribution fight
What should have been a straightforward critical infrastructure incident response turned into a political dispute. President Trump publicly rejected the Iran attribution, telling reporters, I think that Minnesota is behind it, because they're grossly incompetent, I don't think there was an Iranian cyberattack. That statement put the White House at odds with its own federal cybersecurity agencies, which had already issued advisories describing the activity as consistent with Iranian tactics against water infrastructure.
Minnesota Governor Tim Walz pushed back directly, saying Trump knows exactly who is responsible for this attack, and knows that other states were hit too, and characterizing the intrusions as what modern warfare looks like. WaterISAC, the sector's information sharing organization, said it had confidence in the government's technical assessments linking the activity to known Iranian tactics. Cynthia Kaiser, a former FBI cyber division deputy assistant director, offered the sharpest technical framing of the dispute: I think most credible researchers and responders would be right to treat it like it's Iran until proven otherwise. When it walks like a duck and talks like a duck, it's really important to call it out.
Why water utilities keep getting hit
This is not an isolated event. Water and wastewater systems have been a recurring target for Iran-linked actors, most notably in the 2023 campaign against Unitronics PLCs used in water treatment facilities across multiple U.S. states, and the sector has repeatedly topped CISA's list of critical infrastructure categories with the weakest baseline cybersecurity posture. Small municipal utilities like Braham typically operate with minimal IT staff, legacy PLCs never designed with network security in mind, and internet-facing remote access left in place for vendor convenience rather than locked behind properly segmented networks. Unlike large investor-owned utilities that can fund dedicated OT security teams, a town of 1,700 residents is unlikely to have anyone on staff whose job is specifically to monitor for this kind of intrusion, which is exactly the asymmetry nation-state actors are positioned to exploit at scale. The fact that this wave spread across more than 30 systems in a single state within days also points to automated scanning for a known exposure pattern rather than hands-on-keyboard targeting of individual utilities.
That combination, high public-safety stakes paired with minimal security investment, is exactly the profile that makes water utilities attractive for nation-state actors looking to demonstrate disruptive capability against U.S. infrastructure without needing sophisticated zero-day tooling. Default credentials, exposed Modbus and other industrial protocols, and unpatched HMI software are usually enough.
The cost of a public attribution dispute
Beyond the immediate technical incident, the public disagreement between the White House and state officials over attribution carries real operational cost. Utilities deciding how much to invest in incident response, threat hunting, and OT network segmentation take cues from how seriously federal leadership treats a threat. A public dispute over whether an attack even happened as described complicates that calculus and can slow the flow of federal assistance, threat intelligence sharing, and funding to the utilities that need it most, particularly for small systems that depend heavily on state and federal grant programs to fund any security upgrades at all. It also risks becoming a template other officials reach for after future incidents, treating a technical attribution question as a partisan one rather than something to resolve through the normal joint FBI, CISA, and sector-specific investigative process.
It also creates a confusing signal for other critical infrastructure operators nationally who are trying to gauge their own risk exposure. If CISA and the FBI say Iranian actors are actively targeting PLCs sector-wide, but the White House disputes the underlying attribution, operators outside Minnesota are left to decide independently how urgently to act on federal guidance that appears internally contested.
What critical infrastructure and adjacent enterprise security teams should do
Regardless of how the attribution dispute resolves, the technical guidance from CISA's advisory stands on its own: water and wastewater operators should immediately inventory internet-exposed PLCs and HMIs, remove default credentials, enforce multi-factor authentication on all remote access to OT networks, and segment OT from IT networks so a compromised business system can't reach operational controls. Any utility using Unitronics, Modbus-based, or similarly exposed industrial protocols should assume they are in scope for this campaign, not just the systems already publicly confirmed as affected, and should prioritize this review over waiting for a formal notification that never arrives. Utilities that lack the in-house expertise to run this assessment themselves should reach out to their state's water sector cybersecurity liaison or WaterISAC directly rather than deferring the work indefinitely.
For enterprise security leaders outside the water sector, particularly those overseeing physical operations, manufacturing, or any OT environment, this incident is worth a direct question to your own OT and ICS teams: could a small, under-resourced facility in your supply chain or operating footprint be running exposed PLCs the way Braham was, and would you know if it happened to you the same weekend it started.



