Federal agencies issued an urgent joint warning after cyberattacks struck municipal water systems across at least seven states in a single week, and officials still have not publicly identified who is behind them.
The FBI and the Environmental Protection Agency released a joint public service announcement telling water and wastewater utilities nationwide that malicious cyber actors are actively trying to disrupt critical water infrastructure. Hackers targeted certain brands of control systems used by municipal utilities, and some of the attacks degraded water operations, Breitbart News reported, citing NBC News. The advisory focused on the tactics used in the attacks rather than attribution, meaning the federal government has declined, at least publicly, to name a responsible party.
Minnesota bore the most visible damage. More than 30 municipal water facilities in the state were targeted in a single coordinated breach. The Cybersecurity and Infrastructure Security Agency issued a separate alert noting that some of the larger attacks across the country had forced boil-water notices and pushed utilities into sustained manual operations. CISA did not disclose which locations were affected.
Wisconsin's Department of Natural Resources sent a bulletin to water contacts statewide earlier in the week, warning that intelligence officials believed Wisconsin systems might be vulnerable to the same hackers. The bulletin went further, stating that Minnesota had reported hackers managed to reduce system pressures, and that in several incidents, the pressure drops triggered alarms and prompted law enforcement responses.
Minnesota pushed back hard on that characterization. Emily Zimmer, a spokesperson for Minnesota's information technology services agency, spoke Thursday and said there was no indication the breaches had contaminated any municipal water supplies. She directly contradicted Wisconsin's account:
"Minnesota has not reported that threat actors lowered pressure across multiple water systems or that pressure changes prompted a law enforcement response."
That leaves a notable gap between what one state said happened and what the other denies reporting. Neither federal officials nor Minnesota's own agencies have reconciled the discrepancy publicly. The FBI and EPA did not identify who was responsible for the breaches in the six states beyond Minnesota, and those states have not been named.
President Trump addressed the attacks Friday in remarks to reporters at Camp David. He did not attribute the breach to a foreign adversary. Instead, he placed blame squarely on state leadership:
"I think I blame it on Minnesota because they're grossly incompetent. I would blame it on Minnesota and the governor, the corrupt governor of Minnesota. They like to say, 'Oh, it's Iran.' Iran should be so lucky. Iran's got bigger problems than worrying about Minnesota."
Gov. Tim Walz, the 2024 Democratic vice presidential nominee, fired back with a statement that implicitly attributed the attacks to Iran and accused the president of deflecting:
"Trump knows exactly who is responsible for this attack, and knows that other states were hit too. This is what modern warfare looks like, and it further illustrates there's no plan to win a war with Iran."
Neither Walz nor any federal official has released evidence supporting Iranian attribution. The federal advisory itself avoided naming any nation-state or group. So Walz's claim that the president "knows exactly who is responsible" remains an assertion without public documentation behind it.
Wisconsin's warning carried an unmistakable sense of urgency. The Department of Natural Resources told utilities the cyber threat was ongoing and demanded immediate action:
"This leads us to believe that the cyber threat is ongoing in Wisconsin and requires immediate action to prevent potentially serious impacts to our systems."
No confirmed compromise of Wisconsin systems has been reported. But the bulletin made clear that intelligence officials considered the state's infrastructure vulnerable to the same actors who struck elsewhere. Federal officials urged operators of all water systems, regardless of brand or location, to take security precautions.
The scope of the attacks raises questions that remain unanswered. Which six states beyond Minnesota were hit? Which specific control systems did the hackers exploit? Were any arrests made or suspects identified? What is the current operational status of the 30-plus Minnesota facilities that were breached? And why, more than a week into a coordinated campaign against basic public infrastructure, has no one in the federal government publicly named a responsible party?
Municipal water systems are among the most essential, and most exposed, pieces of American infrastructure. Many rely on internet-connected programmable controllers that were never designed with sophisticated cyberdefense in mind. A successful attack does not need to poison a water supply to cause serious harm. Forcing utilities into manual operations, triggering boil-water notices, and degrading pressure across dozens of facilities all disrupt daily life for the communities that depend on clean, reliable water.
The political blame game between Washington and the states may generate headlines. But the residents of Minnesota, Wisconsin, and at least five other states are left with a more basic concern: whether the water coming out of their taps is safe, and whether anyone in charge has a plan to keep it that way.
When hackers can reach into more than 30 water systems in a single state and the government cannot even agree on what happened, let alone who did it, the failure is not partisan. It is structural. And the people who pay the price are the ones who turn on the faucet every morning and have no choice but to trust the system.