Here's the thing. Someone got into the software that runs American drinking water — the systems that manage chemical levels, pressure, and treatment processes — and did it across at least seven states before anyone said anything publicly.
The FBI and the Environmental Protection Agency confirmed the incidents in a joint statement, saying some of the attacks 'affected the functioning' of water systems. Minnesota was the first state to go public. Michigan followed, with spokesperson Dale George confirming 'a small number of reports from Michigan communities indicating activity consistent with what was described by the federal agencies,' while adding that systems remain operational and there are 'no known impacts that represented a public health concern.'
According to a New York Times investigation cited by Colombian outlet El Colombiano, the scope is wider than initially known and may extend beyond the seven states already counted. Federal officials and experts quoted by the Times believe the leading hypothesis points to actors linked to Iran — particularly given the pattern matching previous campaigns attributed to Iranian-linked hacker groups since tensions escalated between the U.S., Israel, and Iran. But the agencies are careful: no conclusive forensic evidence has been established.
Nate George, mayor of Braham, Minnesota, told the Times that local authorities are 'getting fragments of information from the state of Minnesota and the FBI,' and that investigators are 'pretty confident these are Iranian actors' — though they prefer not to say so publicly while the investigation continues.
Alex Orleans, former U.S. government cybersecurity contractor and current threat intelligence chief at Sublime Security, put it plainly: 'What is unprecedented here is that we are seeing direct and tangible effects on active industrial control systems within U.S. critical infrastructure.'
Some attacks forced manual operations. Others triggered precautionary boil-water advisories. CISA responded by recommending that operators disconnect vulnerable controllers from the internet entirely.
President Trump, for his part, pushed back on the Iran theory: 'I think Minnesota is behind this. I don't think there was an Iranian cyberattack,' he said. Minnesota Governor Tim Walz rejected that framing on social media, writing that 'this is what modern warfare looks like.'
The investigation is ongoing. No forensic attribution has been made final.
---
The deeper story here is infrastructure debt. Mayor George said it himself: 'The IT infrastructure upgrades are very expensive and we are a very small municipality.' Small water utilities — the kind serving towns of a few thousand people — are running internet-connected industrial controllers they cannot afford to replace or properly harden. That is not a cybersecurity problem. That is a decades-long failure of government to prioritize basic physical security over regulatory theater.
If Iranian actors — or anyone else — can force boil-water advisories in American towns by exploiting unpatched hardware, the answer is not another federal advisory. It is getting the bureaucracy out of the way and letting municipalities actually fix the firmware.



