Skip to main content

U.S. probes if Iran was behind cyberattack on utilities in Michigan, Minnesota

▶ Watch Video: Trump blames Minnesota cyberattacks on its governor, not Iran

Malicious cyber activity affected technology at water systems in at least seven states in late July, including Minnesota and Michigan, forcing some utilities to switch to manual operations as state and federal authorities dig into who is behind the attack, CBS News has learned.

Investigators are probing to determine whether the activity is the work of Iranian hackers, according to U.S. officials and sources familiar with the incident. Sources cautioned that since they had not definitively attributed the attack, their assessment could change as additional technical evidence is collected. They are also probing whether the actor could have attempted to appear Iran-based as a way of stirring the pot amid the ongoing U.S. conflict with Iran

The FBI reported incidents in “at least seven states” but didn’t identify them. On Saturday, Aug. 1, Michigan joined Minnesota in reporting cyberattacks on the state’s water systems but an official said all systems were operating “safely.”

Dale George, the director of communications at the state’s Department of Environment, Great Lakes, and Energy, told CBS News in a statement that the state received “a small number of reports from Michigan communities indicating activity consistent with what federal agencies described.”

“All systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern,” he added.

Clayton County, Georgia, also said it was investigating “unauthorized cyber activity” that may have caused a temporary disruption in its water system operations.

CBS News has learned more than 30 community water systems across Minnesota were affected. Minnesota and the federal government have not publicly attributed the activity to a particular actor.

Even as the investigation continues, President Trump said he doesn’t think Iran is to blame. Instead, he pointed the finger at Minnesota and its Democratic governor, Tim Walz, who is no stranger to criticism from the president.

“I think that Minnesota is behind it,” Mr. Trump said during a televised Cabinet meeting at Camp David on Friday, July 31. “You know who’s behind it? Minnesota. Because they’re grossly incompetent. I think the governor’s behind it. I don’t think there was an Iranian cyberattack. I think that Minnesota ought to get its act together.” 

“They like to say, ‘Oh, it was Iran.’ Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota,” the president said.

Following Mr. Trump’s accusations, Walz said on social media that the Trump administration “took an axe” to the federal Cybersecurity and Infrastructure Security Agency and “left the U.S. exposed to cyber attacks.”

“Trump knows exactly who is responsible for this attack, and knows that other states were hit too,” Walz, who was the vice presidential candidate on the ticket facing Mr. Trump in 2024, said. “This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran.”

Iran-linked hackers have previously targeted U.S. water utilities. Federal agencies confirmed previously that actors affiliated with Iran’s Islamic Revolutionary Guard Corps used a similar playbook, accessing multiple water and wastewater facilities in 2023 by exploiting internet-connected controllers that retained their default passwords.

Officials warned of water systems being targeted

The FBI, Environmental Protection Agency and CISA all warned on July 30 that attackers are targeting internet-exposed industrial controllers used by water and wastewater utilities. 

In at least some cases, federal authorities reported loss of monitoring and control functionality at critical infrastructure sites, leading to pressure loss and flooding.

Most confirmed cases in the Minnesota cyberattack involved technology used to remotely monitor and control water system equipment, including devices called programmable logic controllers, according to Minnesota IT Services.

None of Minnesota’s water supply has been reported compromised as a result of the attack, Mike Ernster, a public information officer for the Minnesota Department of Public Safety, told CBS News. The Bureau of Criminal Apprehension’s Minnesota Fusion Center was working with municipalities, as well as state and federal partners, to address the issue, he added.

US Water Systems Cyberattack Minnesota
A water tower is seen in Plymouth, Minnesota, on July 30, 2026. A cyberattack targeted the operating technology at over 30 water systems in the state, including Plymouth’s, earlier this week, state officials said. 

AP Photo/Ellen Schmidt

Nick Anderson, acting director of CISA, confirmed that the agency “is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLC) at water utilities.” 

“We urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible,” he added.

Minnesota said investigators identified some similarities in the timing of the recent incidents, in addition to the types of technology impacted, but had not yet confirmed that every incident was carried out by the same actor.

A spokesperson for the city of South St. Paul told CBS News it identified an issue early Monday, July 27, and immediately implemented contingency procedures. Public works employees transitioned to manual operations, allowing water and wastewater services to continue without any interruption to service. The city added that the incident was limited to technology supporting portions of its water utility, while drinking water treatment, quality, pressure and delivery were not impacted. 

Officials in South St. Paul found no indication that resident or customer data was accessed.

In Braham, located in a more rural area north of Minneapolis, public works personnel also discovered the problem on July 27 after noticing the well supplying the city’s water tower was malfunctioning. Workers isolated the affected system, restored a backup and restarted the plant in about 90 minutes, Mayor Nate George confirmed to CBS News. 

Residents experienced no loss of water service, George added. The city’s water tower typically holds enough drinking water to last about two days, and operators discovered the problem before receiving an automated alert, leading the city to believe the pump had been offline for only a brief period. The city has since ensured the system is not connected to any public-facing internet networks and is meeting with its technology provider about remediation.

In suburban Plymouth, Minnesota, officials detected an outage the evening of Sunday, July 26, after noticing compromised PLCs at two water towers and 14 sewer lift stations, then disconnecting them from the cellular network. 

A city official in Plymouth told CBS News that operators moved into a manual operation mode temporarily until the systems were brought back online, with normal communications restored by the afternoon of Tuesday, July 28. Still, officials say water quality, treatment and pressures were never affected, with delivery remaining undisrupted throughout.

Michael Thompson, the Plymouth Director of Public Works, told CBS News Minnesota his team first noticed there was a problem when communication between devices started to become interrupted on Sunday evening. By just after midnight, Thompson said it was an all-hands-on-deck situation.

“I think you never expect it to happen to you,” Thompson said.

CISA said Thursday, July 30, that was “currently observing a significant increase in cyber threat actors” that are targeting PLCs in the Water and Wastewater Systems sector, noting those actors are targeting “water entities of all sizes.”

“CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible,” said CISA, which is part of the Department of Homeland Security. 

“Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans,” CISA added in its advisory.

South Carolina to hold first 2028 Democratic presidential primary

▶ Watch Video: Democrats expected to approve South Carolina as first primary in 2028, but other states pushing back Democrats on Saturday approved a new presidential nominating calendar for 2028, cementing South Carolina's place as the first official Democratic primary state, as the party looks to elevate states that better reflect its diverse coalition of voters.The vote came during the Democratic National Committee's summer meeting in Austin, where members signed off on a schedule that begins with South Carolina on Jan. 22, followed by Nevada on Feb. 1. New Hampshire, New Mexico, Michigan and Virginia round out the early-state lineup throughout February, all voting before Super Tuesday.The new calendar goes into effect amid a tug-of-war within the progressive and establishment wings of the party. It also continues a shift away from a tradition that for half a century gave states that are predominantly composed of White voters — Iowa and New Hampshire — outsized influence at the start of the nominating process. Strategists say the new calendar gives greater influence to Black and Latino voters, who make up key parts of the Democratic coalition. "If you're not strong with Latino voters or if you're not strong with Black voters, you know you can only get so far in this calendar," CBS News contributor and Democratic strategist Chuck Rocha said, adding that the schedule shows Black voters "the respect that they're due."Not everyone in the party is on board. Democratic leaders in Iowa and New Hampshire — previously the first and second states to hold primary contests, respectively — excoriated the new map as soon as the DNC's Rules and Bylaws Committee recommended it, arguing that it diminishes the role of states that have long taken on the responsibility of shaping the presidential nomination battlefield. "New Hampshire's First in the Nation primary is a tested proving ground in a closely contested swing state that forges better candidates and better presidents — and despite what DNC insiders say, that hasn't changed," New Hampshire's U.S. congressional delegation said in a statement. "As a state with highly engaged voters, we put candidates through their paces and thoroughly vet them. And our small size means that actually meeting and talking to voters takes precedence over super PACs or mega-donor-fueled campaigns."Momentum for South Carolina's ascension in the calendar traces back to 2020, when a victory there shifted momentum in the presidential primary that year to Joe Biden after he performed poorly in Iowa, New Hampshire and, to a lesser extent, Nevada. Under pressure from Biden and his allies, the DNC moved South Carolina's primary to first for the 2024 calendar. That cycle, New Hampshire defied the DNC's revised schedule and held its primary before South Carolina, citing a state law that mandates it hold the first primary. In response, the party stripped the contest of its sanctioned status. DNC Chair Ken Martin has signaled that if New Hampshire jumps ahead again in 2028, punishment will be more severe. "This is a calendar this party is actually going to protect," Martin told reporters after the DNC's Rules and Bylaws Committee met last month to propose a new schedule. The new calendar could impact the ideological battle within the Democratic Party between establishment moderates and more progressive candidates, including far-left democratic socialists. With no obvious 2028 front-runner, the newly approved schedule gives South Carolina, Nevada and the other four early states disproportionate influence over which faction can build early momentum in the 2028 presidential primaries. Among the states granted early slots, only Nevada and New Mexico offer clear advantages to progressives. Michigan has shown openness this cycle to progressives, with the primary victory of Abdul El-Sayed in the Senate race, but historically has elected more moderate candidates. New Hampshire voters have over time shown an openness to outsiders, but they typically have a more independent streak rather than a steep ideological lean. Progressives face an uphill battle in South Carolina, which has fewer of the White voters with college degrees who tend to support further-left candidates, and Virginia, which has long favored more moderate candidates. The decision to elevate states with large Black and Hispanic populations also comes as Democrats fight to stop the GOP from gaining ground with those two groups in general elections. President Trump won 48% of the Hispanic vote in 2024, up 12 points from four years earlier, and he won 15% of Black voters, almost double his share in 2020, according to the Pew Research Center. His share of non-Hispanic White voters remained stable, at 55%.
Read Next Story