Morgan Wright, founder of the National Center for Open and Unsolved Cases, said Thursday that he has “at least moderate confidence” that Iran was behind the recent cyber intrusions at water facilities across Minnesota. He pointed to a federal advisory issued days before the attacks that warned of Iranian hackers targeting such systems.
“There was an alert that was put out four days before this describing that they believed Iran was going to launch an attack like this four days later — and an attack is launched,” Wright told News Nation’s Blake Burman.
Minnesota IT Services (MNIT) reported that the attacks occurred on Sunday and Monday and targeted programmable logic controllers (PLCs) and human-machine interfaces, according to an advisory released Thursday. These components are critical to the operation of water and wastewater treatment plants.
The attacks came just after a July 22 joint advisory from the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and other federal agencies that warned Iranian hackers were focusing on PLC systems. The advisory urged operators of operational technology to “restrict direct internet access and ensure secure PLC deployment.”
John Israel, Minnesota’s chief information security officer, said the state has shared information with federal authorities, who are “evaluating this activity in the broader national context.”
Wright stressed that the attackers are “targeting one of the most vulnerable things in these plants now,” referring to the PLC systems that control water treatment processes. He warned that while the U.S. dominates Iran on land and sea, cyberspace is an area where Tehran can “punch at or above their weight at a near peer level with us.”
The FBI’s assistant director of the Cyber Division, Brett Leatherman, said in the federal advisory that Iranian actors “continue to target U.S. critical infrastructure” and aim to “disrupt the essential services Americans rely on.” The attacks on Minnesota’s water systems are part of a broader pattern of Iranian cyber aggression against American infrastructure, which has drawn increased scrutiny from policymakers and cybersecurity experts.
This incident underscores the growing threat to the nation’s water supply, a concern that has been highlighted by recent efforts to fortify cybersecurity defenses through open-source AI coalitions. Experts have also warned that the intensified U.S. strikes on Iran may not deter such cyberattacks. Meanwhile, Minnesota’s political landscape has been turbulent, with recent surges in GOP primaries and a murder case involving a former House Speaker drawing attention away from cybersecurity issues.
The federal government has been criticized for its response to such threats, with some experts pointing to federal inaction that allows malicious actors to thrive. As the investigation continues, Minnesota officials are working with federal agencies to assess the full scope of the attack and prevent future breaches.
