United States intelligence agencies are investigating potential Iranian involvement in a cyberattack this week that targeted municipal water supply networks across Minnesota, according to reporting by the New York Times. Local officials reported that the well and treatment plant in at least one city were temporarily taken offline on Monday, July 27, while other municipalities across the state shifted to manual operating procedures to fend off automated system intrusions.
While investigators have not yet formally attributed the breach to Tehran, the incident follows urgent cybersecurity warnings issued by federal authorities in April and July. Those alerts cautioned that the Islamic Revolutionary Guard Corps had spent months targeting internet-connected devices governing water systems, wastewater treatment plants, and energy facilities across the United States, occasionally causing operational disruptions.
Local Impact and Municipal Response in Minnesota
In Braham, Minnesota, municipal services detected an intrusion early Monday morning, according to an online statement published by Mayor Nate George. After learning that at least four other communities in the state faced similar digital threats, local authorities concluded their water treatment plant had been compromised.
“The technical services isolated the affected system, restored a backup, and brought the plant back online in about 90 minutes,” George stated, adding that Braham residents continued to receive running water from the municipal water tower throughout the brief outage.
Further south in Plymouth, several devices controlling water and sanitation networks were also accessed, though the municipal water supply remained unaffected. Matthew Vogel, a spokesperson for the Federal Bureau of Investigation, confirmed that the agency is aware of the incidents and is coordinating with affected local entities to resolve the disruptions.
Patterns Pointing Toward Tehran
Observers point to the complete absence of any ransom demand, the focus purely on disruption rather than destruction, and Tehran’s documented, recent interest in compromising American critical infrastructure.
Since the onset of military conflicts earlier in the year, intelligence assessments indicate Iran has scaled up its digital probes against U.S. targets. In March, operations attributed to Iranian actors temporarily halted activities at Stryker, an important medical supply manufacturer. Other recent campaigns, including the unauthorized release of stolen emails and photographs from the personal account of FBI Director Kash Patel, have leaned more toward public nuisance than catastrophic infrastructure damage.
Alex Orleans, threat intelligence manager at email security firm Sublime Security, noted in interviews with the Washington Post that these operations appear designed to achieve psychological effects across distinct audiences. According to Orleans, such attacks aim to signal capability to the Iranian leadership while attempting to sway American public perception regarding the costs and stability of domestic infrastructure.
Precedents in Critical Infrastructure Targeting
The Minnesota incidents echo a similar intrusion late last year in Aliquippa, Pennsylvania, where a programmable logic controller at a municipal pumping station was breached. That event, which caused no significant service disruptions, was claimed by a hacker collective known as CyberAv3ngers, identified by security researchers as linked to the Islamic Revolutionary Guard Corps.
The Aliquippa station utilized controllers manufactured by Israeli firm Unitronics—hardware that was simultaneously targeted by the same group across deployments in the United States, the United Kingdom, Israel, and Ireland following the outbreak of conflict in Gaza.
Worth a look