In late July, a cyberattack hit over 30 water systems in Minnesota, including the city of Plymouth. This attack disrupted operations in various treatment plants, pushing city officials in affected areas like Braham, Minnesota, to urge residents to conserve water. The outage in Braham was resolved in a few hours by manually controlling the pump. However, the issue signaled a larger coordinated cyberattack suspected to involve Iranian hackers targeting critical infrastructure.
Braham’s Mayor Nate George emphasized that the attack was not specifically aimed at his town, but at vulnerabilities inherent in internet-connected systems. The hackers did not compromise the water supply but raised alarms about the security of such systems. According to Rob Lee, CEO of Dragos, similar attacks affected other sectors reliant on the same industrial technology.
Between July 26 and 28, news spread of similar disruptions in Minnesota cities and towns like Maple Plain and Braham. These incidents prompted actions like boil water advisories in other states such as New Jersey and Michigan. The WaterISAC organization convened discussions on cybersecurity measures, while the EPA conducted webinars to alert the industry to emerging threats. The FBI’s investigation revealed similar attacks in at least seven states.
The U.S. has not named Iran officially in connection with these attacks, though it’s not the first time Iranian groups have targeted infrastructure. Past events include the defacement of systems in Aliquippa, Pennsylvania, by Iranian-linked hackers. Michael Crean from SonicWall reported an increase in cyber scanning for device vulnerabilities, a tactic preceding disruptions in American industries.
Jake Braun, formerly associated with the White House, suggests Iran’s motivations include demonstrating the ability to disrupt U.S. military bases, economic centers, and sowing doubt in government reliability. Efforts like Project Franklin aim to bolster cybersecurity in rural facilities through expert advice and updates.
Local operators already face challenges from technical failures to natural disasters, making cybersecurity another critical concern. Experts like Chris Hughes recognize the multifaceted threats posed by cyberattacks on regional water supplies. Operational technology remains vulnerable because it’s often outdated and connected to the internet for efficiency, creating potential security gaps.
Preventive measures include disconnecting systems from business networks, updating default credentials, and implementing robust security protocols. However, more sophisticated attacks could bypass these defenses. Cybersecurity within water systems faces hurdles due to outdated infrastructure, urging calls for federal funding and improved information sharing.
Concern over foreign cyber threats extends beyond the current attacks. Strategies outlined in Chinese military documents describe how infrastructure targeting can cause panic and distraction. Communities like Braham are increasingly aware of these global threats and seek strategic responses.
Efforts to mitigate threats highlight the need for more robust national leadership and funding to modernize and secure water infrastructure. Stakeholders like Kevin Morley of the AWWA emphasize information sharing but acknowledge the sector requires additional resources. The private and federal response has improved, but vulnerabilities remain significant, demanding proactive security measures and investments.
The Trump administration’s reduction of the federal cybersecurity workforce has added to the challenge. While states like California avoided immediate impact, they caution against complacency. Strategies for strengthening national cybersecurity frameworks, backed by potential federal funding, continue as critical discussions in safeguarding America’s essential services.

New Restrictions on U.S.-China Science Collaboration
Apple Watch Series 11 Discounted to Lowest Price
AI and Personal Finance: Balancing Automation and Human Insight
Army’s Artillery Project Stumbles Amid Costly Failures
The Misguided Move to Implement CT Scanners at Airports
Growing Concerns Over Data Centers in Kentucky