Skip to main content

U.S. probes if Iran was behind cyberattack on utilities in Michigan, Minnesota

▶ Watch Video: Trump blames Minnesota cyberattacks on its governor, not Iran

Malicious cyber activity affected technology at water systems in at least seven states in late July, including Minnesota and Michigan, forcing some utilities to switch to manual operations as state and federal authorities dig into who is behind the attack, CBS News has learned.

Investigators are probing to determine whether the activity is the work of Iranian hackers, according to U.S. officials and sources familiar with the incident. Sources cautioned that since they had not definitively attributed the attack, their assessment could change as additional technical evidence is collected. They are also probing whether the actor could have attempted to appear Iran-based as a way of stirring the pot amid the ongoing U.S. conflict with Iran

The FBI reported incidents in “at least seven states” but didn’t identify them. On Saturday, Aug. 1, Michigan joined Minnesota in reporting cyberattacks on the state’s water systems but an official said all systems were operating “safely.”

Dale George, the director of communications at the state’s Department of Environment, Great Lakes, and Energy, told CBS News in a statement that the state received “a small number of reports from Michigan communities indicating activity consistent with what federal agencies described.”

“All systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern,” he added.

Clayton County, Georgia, also said it was investigating “unauthorized cyber activity” that may have caused a temporary disruption in its water system operations.

CBS News has learned more than 30 community water systems across Minnesota were affected. Minnesota and the federal government have not publicly attributed the activity to a particular actor.

Even as the investigation continues, President Trump said he doesn’t think Iran is to blame. Instead, he pointed the finger at Minnesota and its Democratic governor, Tim Walz, who is no stranger to criticism from the president.

“I think that Minnesota is behind it,” Mr. Trump said during a televised Cabinet meeting at Camp David on Friday, July 31. “You know who’s behind it? Minnesota. Because they’re grossly incompetent. I think the governor’s behind it. I don’t think there was an Iranian cyberattack. I think that Minnesota ought to get its act together.” 

“They like to say, ‘Oh, it was Iran.’ Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota,” the president said.

Following Mr. Trump’s accusations, Walz said on social media that the Trump administration “took an axe” to the federal Cybersecurity and Infrastructure Security Agency and “left the U.S. exposed to cyber attacks.”

“Trump knows exactly who is responsible for this attack, and knows that other states were hit too,” Walz, who was the vice presidential candidate on the ticket facing Mr. Trump in 2024, said. “This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran.”

Iran-linked hackers have previously targeted U.S. water utilities. Federal agencies confirmed previously that actors affiliated with Iran’s Islamic Revolutionary Guard Corps used a similar playbook, accessing multiple water and wastewater facilities in 2023 by exploiting internet-connected controllers that retained their default passwords.

Officials warned of water systems being targeted

The FBI, Environmental Protection Agency and CISA all warned on July 30 that attackers are targeting internet-exposed industrial controllers used by water and wastewater utilities. 

In at least some cases, federal authorities reported loss of monitoring and control functionality at critical infrastructure sites, leading to pressure loss and flooding.

Most confirmed cases in the Minnesota cyberattack involved technology used to remotely monitor and control water system equipment, including devices called programmable logic controllers, according to Minnesota IT Services.

None of Minnesota’s water supply has been reported compromised as a result of the attack, Mike Ernster, a public information officer for the Minnesota Department of Public Safety, told CBS News. The Bureau of Criminal Apprehension’s Minnesota Fusion Center was working with municipalities, as well as state and federal partners, to address the issue, he added.

US Water Systems Cyberattack Minnesota
A water tower is seen in Plymouth, Minnesota, on July 30, 2026. A cyberattack targeted the operating technology at over 30 water systems in the state, including Plymouth’s, earlier this week, state officials said. 

AP Photo/Ellen Schmidt

Nick Anderson, acting director of CISA, confirmed that the agency “is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLC) at water utilities.” 

“We urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible,” he added.

Minnesota said investigators identified some similarities in the timing of the recent incidents, in addition to the types of technology impacted, but had not yet confirmed that every incident was carried out by the same actor.

A spokesperson for the city of South St. Paul told CBS News it identified an issue early Monday, July 27, and immediately implemented contingency procedures. Public works employees transitioned to manual operations, allowing water and wastewater services to continue without any interruption to service. The city added that the incident was limited to technology supporting portions of its water utility, while drinking water treatment, quality, pressure and delivery were not impacted. 

Officials in South St. Paul found no indication that resident or customer data was accessed.

In Braham, located in a more rural area north of Minneapolis, public works personnel also discovered the problem on July 27 after noticing the well supplying the city’s water tower was malfunctioning. Workers isolated the affected system, restored a backup and restarted the plant in about 90 minutes, Mayor Nate George confirmed to CBS News. 

Residents experienced no loss of water service, George added. The city’s water tower typically holds enough drinking water to last about two days, and operators discovered the problem before receiving an automated alert, leading the city to believe the pump had been offline for only a brief period. The city has since ensured the system is not connected to any public-facing internet networks and is meeting with its technology provider about remediation.

In suburban Plymouth, Minnesota, officials detected an outage the evening of Sunday, July 26, after noticing compromised PLCs at two water towers and 14 sewer lift stations, then disconnecting them from the cellular network. 

A city official in Plymouth told CBS News that operators moved into a manual operation mode temporarily until the systems were brought back online, with normal communications restored by the afternoon of Tuesday, July 28. Still, officials say water quality, treatment and pressures were never affected, with delivery remaining undisrupted throughout.

Michael Thompson, the Plymouth Director of Public Works, told CBS News Minnesota his team first noticed there was a problem when communication between devices started to become interrupted on Sunday evening. By just after midnight, Thompson said it was an all-hands-on-deck situation.

“I think you never expect it to happen to you,” Thompson said.

CISA said Thursday, July 30, that was “currently observing a significant increase in cyber threat actors” that are targeting PLCs in the Water and Wastewater Systems sector, noting those actors are targeting “water entities of all sizes.”

“CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible,” said CISA, which is part of the Department of Homeland Security. 

“Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans,” CISA added in its advisory.

Agente de ICE apunta con un arma a una mujer; el DHS afirma que ella usó su vehículo como arma

Un enfrentamiento captado en video entre una mujer que insultó a agentes del Servicio de Inmigración y Control de Aduanas (ICE, por sus siglas en inglés), mientras realizaban un operativo inmigratorio en el norte de Virginia, se intensificó el lunes cuando uno de ellos le apuntó con un arma.Un portavoz del Departamento de Seguridad Nacional (DHS, por sus siglas en inglés) describió a la mujer en un comunicado como “una agitadora anti-ICE” que condujo su vehículo “en círculos alrededor de nuestros agentes del ICE y luego intentó hacerles daño al utilizar su vehículo como arma contra ellos, todo ello para ayudar a escapar a inmigrantes indocumentados”.La mujer, Carolina Molina, dijo a WUSA, afiliada de CNN, que es consejera profesional con licencia y que se dirigía a una reunión con abogados de inmigración en Bailey’s Crossroads cuando vio a los agentes del ICE esposar a dos hombres latinos y llevarlos hasta un vehículo sin identificación oficial. Ese encuentro no aparece en el video.Molina también relató lo ocurrido durante una conferencia de prensa este miércoles por la tarde.“Entonces bajé la ventanilla y les dije: ‘Ustedes están mal’”, contó Molina a WUSA.Molina dijo que vio a más agentes mientras continuaba hacia el despacho de los abogados.El video de la cámara instalada en su vehículo muestra que insultó a los agentes y les gritó que estaban “jo**dos”.Según escribió Molina en Instagram al publicar las imágenes, dio la vuelta para evitar llamar la atención sobre el despacho de los abogados, “donde posiblemente podría haber inmigrantes”.Fue entonces cuando agentes federales enmascarados le cerraron el paso con una camioneta gris y bajaron rápidamente. Uno de ellos gritó: “¿Nos estás siguiendo?” y afirmó que ella “casi nos atropella”, de acuerdo con las imágenes de la cámara del vehículo y un video que Molina grabó con su teléfono.Uno de los agentes amenazó con arrestarla y le apuntó con un arma, que mantuvo desenfundada durante gran parte del enfrentamiento, según las imágenes.“Soy ciudadana y estoy legalmente en el país”, respondió Molina. “¿Cuándo intenté atropellarlos? ¡Lo tengo grabado! ¡Tengo una cámara en el vehículo! ¡Eso es mentira! Nunca intenté atropellarlos”.Los agentes finalmente regresaron a sus vehículos y se marcharon.El DHS dijo a CNN que los agentes realizaban “un operativo dirigido contra inmigrantes indocumentados con antecedentes penales, cuyos delitos incluían darse a la fuga tras un choque y tráfico de drogas, así como contra inmigrantes indocumentados con órdenes definitivas de deportación”.El organismo también afirmó que la mujer intentaba “ayudar a escapar a inmigrantes indocumentados” y que “podría enfrentar un proceso penal como consecuencia de sus acciones”.“Nuestros agentes están registrando un aumento de más del 1.300 % en las agresiones en su contra, del 3.300 % en los ataques con vehículos y del 8.000 % en las amenazas de muerte. Ante circunstancias peligrosas, los agentes del DHS actuaron conforme a su capacitación para protegerse, proteger a sus compañeros y proteger al público”, señaló el portavoz en el comunicado.El enfrentamiento es el incidente más reciente de los últimos meses en el que declaraciones del DHS fueron posteriormente puestas en duda por videos, otras pruebas, policías locales o jueces. Las causas judiciales contra personas acusadas de atacar a agentes federales se han desmoronado repetidamente.Molina negó la versión del DHS.“Si hay algo que no soy, es mentirosa”, escribió al publicar el video de la cámara de su vehículo en Instagram.El representante demócrata por Virginia Don Beyer, cuyo distrito incluye Bailey’s Crossroads, en las afueras de Arlington, dijo en una publicación en X que ha estado en contacto con Molina, a quien describió como “madre y originaria del norte de Virginia”.Beyer pidió respuestas y rendición de cuentas por lo ocurrido.“Aunque me alivia que esté a salvo, la deshonestidad habitual y la escalada peligrosa e injustificada que se observan en este video coinciden con lo que hemos visto de los agentes del ICE en todo el país. Este tipo de conducta indebida y amenaza de uso de la fuerza contra miembros de nuestras comunidades no puede tolerarse”, escribió Beyer en X.The-CNN-Wire™ & © 2026 Cable News Network, Inc., a Warner Bros. Discovery Company. All rights reserved.
Read Next Story