HomePolitics

Trump Dismisses Iranian Cyber Threat After Water Utilities Hit Across Seven States

Federal authorities and state officials are investigating a series of cyberattacks targeting water and wastewater infrastructure across at least seven states, including Minnesota, where over 30 community water systems were affected.

According to a joint public service announcement issued by the Federal Bureau of Investigation and the Environmental Protection Agency, malicious cyber actors began targeting internet-exposed programmable logic controllers on July 27, 2026.

The attacks specifically focused on Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series devices, though officials noted that similar vulnerabilities may exist in other control hardware brands.

The intruders gain remote access to internet-facing controllers, then alter device configurations by setting new passwords and modifying IP addresses. These changes cause utility operators to lose both visibility and control over connected equipment. In some instances, affected facilities reported altered project files and discrepancies in ladder logic across multiple sites.

President Donald J. Trump
President Donald J. Trump

The disruptions have directly impacted operations in several locations, resulting in loss of pressure and localized flooding. Federal officials noted that pressure drops in municipal water networks create a risk of untreated groundwater seeping into distribution pipes.

“Operational effects reported to the FBI have included loss of pressure and flooding,” the agencies stated in the alert. They added that the total operational impact on each victim depended on “the type of function for which the PLC was configured (monitoring versus controlling equipment), the equipment itself (1100 versus 1400), the function the device supported, and capability to switch to manual operations.”

Investigators are probing whether the activity is the work of Iranian hackers, according to U.S. officials and sources familiar with the incident. Sources cautioned that since they had not definitively attributed the attack, their assessment could change as additional technical evidence is collected. Investigators are also probing whether the actor could have attempted to appear Iran-based to stir political tension amid the ongoing U.S. conflict with Iran. Iranian-linked hackers previously targeted U.S. water utilities in 2023 by exploiting internet-connected controllers that retained default passwords.

President Donald Trump stated Friday during a televised Cabinet meeting at Camp David that he does not believe Iran is responsible. “I think that Minnesota is behind it,” Trump said. “You know who’s behind it? Minnesota. Because they’re grossly incompetent. I think the governor’s behind it. I don’t think there was an Iranian cyberattack. I think that Minnesota ought to get its act together.”

“They like to say, ‘Oh, it was Iran.’ Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota,” Trump added.

Following the president’s statements, Minnesota Governor Tim Walz responded on social media, writing that the Trump administration “took an axe” to the federal Cybersecurity and Infrastructure Security Agency and “left the U.S. exposed to cyber attacks.”

Minnesota Gov. Tim Walz
Minnesota Gov. Tim Walz

“Trump knows exactly who is responsible for this attack, and knows that other states were hit too,” Walz wrote. “This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran.”

In Minnesota, public works crews in multiple municipalities moved to manual operations after detecting compromised devices. Officials in South St. Paul implemented contingency procedures early Monday after identifying network issues, transitioning staff to manual controls to prevent service interruptions.

Nick Anderson, acting director of CISA, confirmed that the agency “is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLC) at water utilities.” CISA urged critical infrastructure operators to remove publicly exposed PLCs and operational technology from the internet immediately, emphasizing that water organizations should validate external connections, including cellular modems installed by third-party vendors.

To mitigate ongoing threats, federal recommendations advise setting physical key switches on PLCs to “run” mode to block logic modifications, enforcing access control lists, maintaining complex passwords, routinely testing manual override procedures, and replacing end-of-life hardware that no longer receives manufacturer security updates.

Victims of operational technology outages or related intrusions are advised to contact their local FBI field office, the Internet Crime Complaint Center, or CISA’s 24/7 Operations Center.

Please make a small donation to the Tampa Free Press to help sustain independent journalism. Your contribution enables us to continue delivering high-quality, local, and national news coverage.

Sign up: Subscribe to our free newsletter for a curated selection of top stories delivered straight to your inbox.