Multiple Minnesota water systems experienced cyberattacks targeting their operational technology, impacting more than 30 community water providers across the state. While no water safety issues arose and service largely continued without interruption, investigators are examining whether Iran may be behind the intrusion.

The attacks occurred over Sunday and Monday, according to state officials, who confirmed that no ransom demands were made and that affected localities swiftly activated backup systems to maintain service. Some cities, including Plymouth, Braham, Maple Plain, and South St. Paul, publicly acknowledged disruptions, although state law limits disclosure of all impacted sites.

The New York Times reported that federal and state sources indicated the cyberattacks were "probably" executed by Iranian hackers, escalating concerns amid ongoing tensions between the U.S. and Iran. However, Minnesota IT Services (MNIT) has refrained from attributing the attacks to a specific actor and emphasized that federal agencies are best placed to analyze the incident amid broader intelligence assessments.

The investigation remains active, with cooperation among multiple entities including the Minnesota Bureau of Criminal Apprehension, the FBI, tribal authorities, and federal partners. MNIT’s assistant commissioner highlighted the need for a coordinated government response to cyber threats targeting critical infrastructure and affirmed ongoing efforts to assist affected communities and strengthen defenses.

This cyber incident reflects the broader context of increasing cyberattacks on essential services, raising the stakes as international relations remain strained. Authorities continue to gather intelligence and will provide updates as the inquiry unfolds.