Trump Dismisses Iranian Cyber Threat After Water Systems Hit in Seven States
A sweeping wave of cyberattacks has targeted water and wastewater infrastructure across at least seven U.S. states, prompting emergency responses from federal and state authorities.
A sweeping wave of digital intrusions targeting water and wastewater infrastructure has expanded across the United States, impacting facilities in multiple states and prompting emergency responses from federal and state authorities, according to reporting by Scripps News and other outlets. The cyberattacks represent one of the most serious incidents to hit American industrial control systems in years, leaving officials on edge as investigations unfold.
Malicious actors began targeting internet-exposed programmable logic controllers, specifically focusing on Rockwell Automation and Allen-Bradley MicroLogix equipment, according to a joint public service announcement issued by the Federal Bureau of Investigation and the Environmental Protection Agency. The intruders achieve remote access to internet-facing controllers, alter device configurations by setting new passwords, and modify Internet Protocol addresses. These changes strip utility operators of visibility and control over connected equipment, occasionally resulting in altered project files and discrepancies in ladder logic across multiple sites.
Media additions
Operational consequences have included a loss of system pressure and localized flooding. Federal officials warned that pressure drops in municipal water networks create a risk of untreated groundwater seeping into distribution pipes, though authorities have repeatedly reassured the public that there is currently no evidence that drinking water has been contaminated or rendered unsafe for consumption.
In Minnesota, public works crews in multiple municipalities moved swiftly to manual operations after detecting compromised devices. Officials in South St. Paul implemented contingency procedures after identifying network issues, transitioning staff to manual controls to prevent service interruptions. State officials in Michigan confirmed that a small number of communities reported activity matching federal warnings, while Wisconsin officials detected malicious activity at their water facilities and urged immediate defensive action, according to coverage from Scripps News.
Federal investigators are actively probing whether the activity is the work of Iranian hackers, according to Wired and The New York Times. Sources cautioned that because they have not definitively attributed the attack, their assessment could shift as additional technical evidence is collected. Investigators are also examining whether an actor could have attempted to appear Iran-based to stir political tension amid ongoing geopolitical conflicts. Iranian-linked hackers previously targeted United States water utilities by exploiting internet-connected controllers that retained default passwords.
Despite the accumulating evidence pointing toward foreign state-backed actors, President Donald Trump rejected suggestions that Iran was responsible. Speaking during a televised Cabinet meeting at Camp David, Trump stated that he does not believe Iran is responsible for the digital disruptions, according to reporting by AOL and Scripps News. Trump added that Iran has larger concerns than worrying about Minnesota.
Following the president's statements, Minnesota Governor Tim Walz responded on social media, writing that the federal administration previously damaged cybersecurity readiness by cutting resources at the Cybersecurity and Infrastructure Security Agency, leaving the nation exposed.
Nick Anderson, acting director of CISA, confirmed that the agency is observing a significant increase in cyber threat actors targeting programmable logic controllers at water utilities. CISA urged critical infrastructure operators to remove publicly exposed programmable logic controllers and operational technology from the internet immediately, emphasizing that water organizations must validate external connections, including cellular modems installed by third-party vendors.
Key Defensive Recommendations for Critical Infrastructure
- Remove publicly exposed programmable logic controllers and operational technology from the internet immediately.
- Set physical key switches on controllers to run mode to block unauthorized logic modifications.
- Enforce access control lists and maintain complex passwords.
- Routinely test manual override procedures and replace end-of-life hardware that no longer receives manufacturer security updates.
Industry specialists have emphasized the inherent vulnerabilities within the sector. Gus Serino, a longtime cybersecurity specialist focused on the water sector, noted that while the inherent resilience of water systems helped limit operational impacts, many drinking water utilities continue to rely on technology architectures lacking fundamental cybersecurity controls. Joshua Corman, an industrial cybersecurity expert, added that while water systems have long benefited from remote connectivity, those who wish the nation harm now possess that same access.
As investigations continue into the digital intrusions affecting utilities across multiple states, federal agencies advise victims of operational technology outages or related intrusions to contact their local FBI field office, the Internet Crime Complaint Center, or CISA’s operations center.