Iran-linked hackers breach Minnesota water utilities, exposing nationwide cyber-security gaps
Iran-affiliated hackers targeted over 30 Minnesota community water systems in late July, exposing weak cybersecurity across U.S. water infrastructure.
In late July, Iranian-linked hackers launched a coordinated cyberattack against more than 30 community water systems in Minnesota, with related probes in several other states. Authorities say the breach relied on exposed internet-connected operational technology and basic security lapses, not advanced malware. A 2024 EPA Office of Inspector General review found critical or high-risk cyber weaknesses in 97 of 1,062 drinking-water systems, affecting roughly 26.6 million people, while 211 systems had publicly visible portals.
The Government Accountability Office notes that nearly 170,000 U.S. water and wastewater facilities often run outdated equipment and lack dedicated cyber staff. Although AI was not proven in this case, its ability to streamline vulnerability discovery and phishing heightens the threat. Experts recommend five fundamental actions: inventory assets, secure all access points, segment operational from business networks, keep software patched, and enforce application allowlisting. Implementing these measures could shift water utilities from reactive to preventive security postures.
Why it matters
A cyber breach of water utilities shows how easy flaws can threaten essential services for millions.
In this story