Iran Cyberattacks Against Minnesota Water Systems

Attribution is preliminary, and so far it seems no real damage.

And it seems like this is a campaign that has targeted at least seven states. And, because this is where the US is right now, Trump doesn’t believe it’s Iran and thinks Minnesota…I guess…hacked itself.

“I think I blame it on Minnesota because they’re grossly incompetent,” Trump said. “I would blame it on Minnesota and the governor, the corrupt governor of Minnesota. They like to say, ‘Oh, it’s Iran.’ Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota.”

No word on whether he believes the other six states have hacked themselves as well.

Slashdot thread.

Posted on August 4, 2026 at 3:00 PM21 Comments

Comments

DrinkingWaterAddict August 4, 2026 3:05 PM

I note that the US has been bombing municipal water systems in Iran. Otherwise they probably wouldn’t be doing this.

Clive Robinson August 4, 2026 6:27 PM

@ Bruce, all,

With regards,

“And it seems like this is a campaign that has targeted at least seven states.”

Actually we don’t know if it’s only “seven states” it’s actually probably more.

It is my understanding on information available that the attacks for various technical reasons are not really important or problematic, if those running the sites are following even minimal security practices.

But to run even minimal security practices requires “resources”…

The “water companies” in many places do not have anything close to the resources required for minimal security.

In fact it’s actually likely that successful breaches have occurred and not even be noticed by site operators in the “noise of everyday” other failures etc.

It is as I’ve noted since 9/11 a ” attack vector the US is almost uniquely vulnerable to.

The more “hi tec” an infrastructure is in the US the easier it apparently is to subvert and turn against society.

This is in reality an almost unique failing of the capitalism system in the US in effect owning the US Government at all levels and negating any sensible strategy to actually protect critical infrastructure against any kind of attack from furry varmints upwards.

And it’s not just “cyber-threats” where this happens. California and Texas are as many here have been witness to fairly replete with examples of incidents where US Capitalism has chosen not to service let alone do minimal required maintenance of service provision…

Anonymous August 5, 2026 8:01 AM

Almost like… He wants to be hated.

The old, larp as your enemy and throw yourself in the mud.

Classic

Anonymous August 5, 2026 10:08 AM

“Trump doesn’t believe it’s Iran”

This has nothing to do with what he believes. He explicitly tells us that he’s blaming, but that’s not the same as belief. He wants others to believe–or at least to pretend.

Rontea August 5, 2026 10:13 AM

The water of a people is its silent bloodstream, and now even that lifeblood is mocked by shadows behind screens. When barbarians of the old world came, they carried swords; today, they arrive through the ether, faceless and without honor, twisting the veins of civilization for sport or for war. A society that entrusts its wells to machines and then exposes those machines to the vast desert of the internet is like a shepherd who leaves his flock at the edge of the forest and falls asleep. Technology without spiritual vigilance is only a bridge for the enemy to cross. The fountain of life is not defended with firewalls alone, but with the consciousness that water is sacred, and sacred things demand guardians who do not slumber.

Bob August 5, 2026 2:51 PM

So not only will this regime attack us directly, but they’ll also provide cover for foreign adversaries to do so. Oh well. At least Iran isn’t sending thugs to execute us in the streets.

lurker August 5, 2026 10:46 PM

“… the attacks aligned with hacking activity being conducted by Iran-affiliated actors.”

Riiight, that narrows the field down a bit.

ResearcherZero August 6, 2026 12:08 AM

There are plenty of targets for “barbarians”, cyber criminals, nation states, AI platforms and any other entity or individual who feels like breaking into critical infrastructure, government networks and agencies, or businesses large and small.

The Trump administration and his circle of friends were hacked by Iran. … “because they’re grossly incompetent,” Trump said. “I would blame it on … and the …, the corrupt govern…. They like to say, ‘Oh, it’s Iran.’ Iran should be so lucky.”

Email accounts belonging to White House chief of staff Susie Wiles and other top advisers were hacked. Kash Patel, Roger Stone and Trump’s lawyer Lindsey Halligan had their email hacked and stolen. 100GB of emails were reportedly stolen by the Iranian-backed group. The emails contain communications between members of the administration, advisers and lawyers.

‘https://www.foxnews.com/politics/iran-linked-hackers-threaten-release-new-trove-emails-stolen-from-trumps-inner-circle-after-strikes

There is no lack of targets for a determined adversary like Iran to exploit …

https://arstechnica.com/security/2026/08/thousands-of-servers-can-be-backdoored-by-exploiting-buggy-motherboard-controllers/

Clive Robinson August 6, 2026 4:01 AM

@ Bruce, ALL,

I noted above,

“Actually we don’t know if it’s only “seven states” it’s actually probably more.”

More information is slowly leaking out in the US Water industry about this.

Because it’s not really recorded unless it becomes a “public issue” of necessity (ie boil water orders etc). The number of incidents we get to hear about are just a tiny fraction of those that happen all the time.

When looked at on a map of the US it shows fairly uniform coverage across the nation. Almost like it’s “Graffiti” on walls…

Therefore it’s probably safe to say,

“Any State with one or more small water company outlets has been effected in the past year or so.”

Which suggests that “political nonsense” is in play from the executive, and should be treated as geriatric spoutings yet again.

ResearcherZero August 6, 2026 5:02 AM

IRGC Cyber Avengers (CyberAv3ngers) are attacking water entities of all sizes.
In 48 hours, the Iranian group launched cyber attacks on more than 36 water facilities.

(Rockwell MicroLogix 1400 and 1100 series PLCs are vulnerable to unauthenticated access.)

Clive Robinson August 6, 2026 6:23 AM

@ Rontea, ALL,

With regards,

“The water of a people is its silent bloodstream…”

And historically various type of “Water War” are the oldest type of attack on “the people”[1] by the “government or similar”. Which is where the original meaning of the term “terrorism” arose from and stayed untill comparatively very modern times.

[1] Other types of attack could be mostly defended against with planning, and many ancient farming communities did build “towns under the ground”. Which only left attacks such as burning the crops, which you can only do at certain points in time toward the end of the growing season in late summer or early autumn.

_ August 6, 2026 8:11 AM

re: “The Trump administration and his circle of friends were hacked by Iran. … “because they’re grossly incompetent,”

Right.

Same state administration that let billions in fraud occur in their state … no? TSA noted suitcases packed with cash being flown out; Not illegal if declared, but STILL, you know, shady.

PS. My last comment did not post … no reason given, and its now the next day …
PPS I bought your book, too, Bruce, back in 1994! I wanted a copy before they banned it. Cheers.

Jim August 6, 2026 8:17 AM

Comment from yesterday (I saved a copy, obviously) that didn’t post:

Look, it’s 2026, and I was using the ZoneAlarm brand firewall pre-year 2000 even while still running Win98SE.

A week or two back I visited the GRC (Gibson Research Corporation) website and tested (using their “ShieldsUP!” utility) my wireless connection (presently thru Verizon) and that test showed all ports blocked – JUST as if I was running ZoneAlarm back on that old internet dial-up connection in 1999 or later the ADSL (wired DSL) connection I had via AT&T.

Point being, we have, no, we’ve HAD the means to secure networks for MANY YEARS now (against direct ‘outside’ the network access), what happens though is, POOR IMPLEMENTATION of hardware and software solutions in these systems by green/sometimes newbie/or financially strained departments, or the result phishing attacks (for passwords and credentials), or insider ‘leaks’ (by the hiring of outside infiltrators) to the underworld of hackers and attackers.

One more note, if we think that the (Walz?) administration of Minnesota was allowing literally billions of dollars to be flown out of the country (TSA witnesses verify suitcases of cash LEFT the airport) don’t we think that cyber security might likewise have been low on the list of supervised items/things in the state?

The foregoing submitted for review here on schneier.com.

Clive Robinson August 8, 2026 3:35 PM

Split into parts due to auto-mod.

Part 1,

@ Bruce, ALL,

In my above I noted that,

“Actually we don’t know if it’s only “seven states” it’s actually probably more.”

And that more information was slowly leaking out in the US Water industry about this, being more of a US Wide problem.

Well more on this from a. X-NSA leader,

Water system controllers don’t belong on the internet, says ex-NSA chief after suspected Iran attacks

With at least 12 US states’ water systems having been hacked – most likely by Iran – we have to get better at cyber defense, according to retired General and Ex-NSA chief Paul Nakasone, who was speaking to reporters at DEF CON.

“We have to have higher standards,” Nakasone said. “These PLCs should not be connected to the internet.”

In late July, the FBI said it was investigating attacks conducted by “malicious cyber actors” targeting operational technology devices, including programmable logic controllers (PLCs). Iran-linked crews have targeted these devices, which monitor sensor data like tank levels, and can turn pumps on and off, for years.

https://www.theregister.com/security/2026/08/07/water-system-controllers-dont-belong-on-the-internet-says-ex-nsa-chief-after-suspected-iran-attacks/5285070

Clive Robinson August 8, 2026 3:38 PM

Part 2,

Note “for years” now.

I was talking about the risk of SCADA Systems using open communications networks on this blog, long before our host and long before most even understood what SCADA stood for and how the systems worked with RTUs, attached PLCs, and the like to control plant equipment and what later became known as ICS.

With engineers and designers favouring “plaintext protocols” on the equivalent of “Serial Lines” going across Private Radio Networks often working in the VHF or UHF PMR bands using simple modems across “walkie-talkies” with hi-gain Yagi or similar antennas often up high radio masts.

These systems were not in the slightest bit secure back in the 1980’s and were very expensive to build and operate.

In the 1990’s the use of dial up telephone networks started to be used as this enabled “man power costs” to be significantly reduced.

Again not the slightest bit secure but rarely if never attacked simply because there was nobody interested in doing so that knew sufficient detail as to how to attack them.

Truly “Security by Obscurity”, and it kind of just stayed that way as mostly nobody wanted to “waste money” or “make maintenance hard”.

Clive Robinson August 8, 2026 3:40 PM

Part 3,

I could see the migration to the nascent Internet happening driven as I said back then “by the bean counters”.

In the UK the privatisation of much National Infrastructure in the 1980’s had led to sell off after sell off and round to the likes of Venture Capitalists.

They wanted quick returns so no money on maintaining the infrastructure let alone making it secure…

What caused a change believe it or not was Three Mile island. Somebody realised that in theory you could “Dial in and Meltdown” a nuclear reactor and that they were “Potential PIRA terrorist targets”. So none of this “Fly in a 747” that had been considered what might be a credible threat and reactor buildings had been designed to withstand.

But we are stuck especially in the US with tiny operators “stripped to below the bone” by “investors” with little or no “essential maintenance” carried out and certainly no money for even basic ICTsec activity.

Clive Robinson August 8, 2026 3:42 PM

Part 4,

This has been going on for getting on for half a century and most if not all US States have very insecure very vulnerable water infrastructure due to “US Capitalism” ethos. And finally some Old General from the NSA finally says,

“These PLCs should not be connected to the internet.”

Well old geezer “welcome to the party” you are already a working life time to late …

ResearcherZero August 9, 2026 6:55 AM

@Clive Robinson

You are indeed correct. Attacks have taken place in more than seven states. There will likely be more attacks discovered in other states and against other asset types. Some of these attempts may have so far gone unnoticed (or unreported) and will likely continue.

Local utilities may not realise that dashboards and controllers are connected to public facing internet, or that these assets even exist. These systems are often outdated and do not support modern security features. Local governments and states require additional funding and professional assistance to properly secure critical devices.

‘https://theconversation.com/how-hackers-attack-municipal-water-systems-and-why-the-utilities-are-so-vulnerable-288864

North Carolina ports disrupted by cyber attack, following attacks on critical water infrastructure in 12 states. Three ports were impacted by attacks on their systems.

https://cyberscoop.com/north-carolina-ports-cyberattack-coast-guard/

ResearcherZero August 9, 2026 7:07 AM

@Clive Robinson

Given the backdrop of global affairs and the current conflict, Trump is really asking for trouble in cutting funding to states and cyber defenses, as the impacts have already been seen in Ukraine of what damage a determined adversary can inflict on public utilities.

Iran has already made it known it will attack facilities in the Middle East. Ignoring the vulnerabilities within American systems, spread across many states is rather foolish. The full range of vulnerable targets extends globally, due to the nature of supply chains.

Putin may test NATO if he cannot find an off-ramp for Ukraine.

https://edition.cnn.com/2026/08/07/politics/us-intelligence-russia-putin-nato-attack

Disruptions to the supply of components threatens defense production.
https://www.iiss.org/online-analysis/military-balance/2026/05/defence-supply-chains-beyond-crms-dependencies-and-bottlenecks/

Houthis learned from Iran’s success in forcing the United States to negotiate.
https://edition.cnn.com/2026/08/07/middleeast/yemen-iran-war-explainer-intl

Multiple disruptions to shipping choke-points could severely impact supply chains.
Cost estimates for disruptions to the Bab al-Mandeb Strait are in the billions.

Reduced refining capacity had already placed pressure on fuel supplies due to the war in Ukraine. Further disruptions are now causing shipping firms to prioritize cost over security. If Red Sea shipping routes are no longer viable, firms would need to re-direct vessels to navigate around Africa’s coast, at substantial cost.

https://orfme.org/expert-speak/double-chokepoint-impact-of-a-hormuz-and-bab-al-mandeb-closure/

Clive Robinson August 10, 2026 2:49 AM

@ ResearcherZero, ALL,

You make two very salient points with,

“Putin may test NATO if he cannot find an off-ramp for Ukraine.”

“Houthis learned from Iran’s success in forcing the United States to negotiate.”

So why is there the assumption,

“It must be the Iranian’s”

Yes the Iranian’s have performed cyber attacks across the Internet but so has every First World and I suspect every Second World country along with a few Third World countries.

It’s not as though the “on ramp” to such behaviour is even noticeable these days. Just about anyone who can read and learn and has a small amount of connected technology available to them can do it. Worse there are plenty who will do it for others for just “Sh1ts and G1ggles” or a fist full of cash.

Ask yourself a question,

“How much would a North Korean do it for?”

Or,

“An Israeli or Italian startup with US Venture Fund Capitalist backing?”

It’s not as though there is any shortage of “talent” available with Russian and other East European cyber-crooks doing ransomware and the like.

I and others have pointed out here that there are a lot of advantages in “False Flag Cyber Operations” long before the CIA false flag kit of tools got outed. Kind of proving a point.

I and others have also repeatedly pointed out the idiocy of US Cyber Security investigators and their short list of “the four horsemen” of “China, Iran, North Korea, Russia” that US Politicians wanted a finger pointing at “for public consumption”…

More importantly I’ve pointed out repeatedly that the Nations most vulnerable to such False Flag, and other, Cyber and technology Failing, Attacks are those who use technology for convenience without responsibility. As the convenience is what gets turned against them.

It’s therefore not exactly difficult to see why the US would be up the top of any such list of nations by quite a long way.

Which brings us to another salient point you make,

“Trump is really asking for trouble in cutting funding to states and cyber defenses”

Yes “Defence Spending” is always a vexed question due to the conundrum of,

“You never know when you’ve spent to much on defence, only when you’ve spent to little and been attacked for the lack of it.”

But add in the over reliance in the US on highly fragile and vulnerable technology to run supply chains with woefully less than the necessary resilience then the most likely outcomes can not be only visible to you or I… So why?…

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.