Coordinated cyberattacks targeted water infrastructure in seven U.S. states this week, causing flooding and loss of water pressure at several facilities [3, 4].
These attacks highlight the vulnerability of municipal utility systems to foreign interference and the potential for digital breaches to cause immediate physical damage to critical infrastructure.
In Minnesota, more than 30 water systems were hit [2]. At least three cities in the state reported attacks on their water facilities [1]. The disruptions began on Monday and continued throughout the week [1, 4].
Some facilities reported flooding and a loss of water pressure as a direct result of the hacks [3]. These incidents occurred across a variety of municipal water treatment, and distribution systems [1].
Investigators said the attacks were likely orchestrated by Iranian-affiliated hackers [4]. This suspected link comes amid heightened tensions between the U.S. and Iran [4]. While some reports emphasize this attribution, other sources have not provided a specific nation or group responsible for the breaches [3].
Federal authorities, including the FBI, are investigating the scope of the attacks [3]. Michigan has also joined Minnesota in reporting similar cyberattacks on its water systems [3].
“More than 30 water systems in Minnesota were hit”
The targeting of water systems suggests a shift toward attacking 'soft' critical infrastructure where security may be less robust than at federal levels. By causing physical effects like flooding and pressure loss, the attackers demonstrated that cyber breaches can transition from data theft to operational sabotage, potentially threatening public health and safety.


