Trump Blames Minnesota and Gov. Tim Walz for Water Utility Cyberattack/ TezzBuzz/ WASHINGTON/ J. Mansour/ President Donald Trump dismissed reports linking Iran to a cyberattack on more than 30 Minnesota water systems and blamed state officials and Gov. Tim Walz. Minnesota authorities said they had not identified a specific attacker, although federal and state officials reportedly consider Iranian hackers the likely perpetrators. The attack disrupted automated equipment in several communities, but officials reported no known threat to drinking water.

Quick Look
- More than 30 Minnesota community water systems were targeted.
- The coordinated attacks occurred Sunday and Monday.
- Operational technology used by the utilities was affected.
- Trump rejected speculation about Iranian involvement.
- He blamed Minnesota and Gov. Tim Walz.
- Walz accused Trump of knowing Iran was responsible.
- Minnesota IT Services has not formally attributed the attack.
- The investigation remains active.
- Automated operations were disrupted in several communities.
- Malicious software temporarily disabled controls in Braham.
- Plymouth and South St. Paul shifted some functions to manual operation.
- No known drinking-water contamination was reported.
- Federal agencies recently warned about Iranian-affiliated hackers.
- Similar hackers targeted American water infrastructure in 2023.
- Earlier breaches exploited default or missing passwords.
- An Iranian hacker was charged over a 2013 intrusion at a New York dam.

Deep Look
Trump dismisses suspected Iran connection
CAMP DAVID, Md. — President Donald Trump rejected reports suggesting that Iranian hackers were responsible for a coordinated cyberattack targeting more than 30 community water systems in Minnesota.
Trump discussed the incident Friday at the beginning of a Cabinet meeting at Camp David.
Rather than blame Iran, the president accused Minnesota officials and Democratic Gov. Tim Walz of incompetence.
His comments conflict with a preliminary assessment reportedly shared by American and state officials, although Minnesota’s investigation has not formally identified the attacker.
Trump blames Minnesota leadership
Trump said he had heard reports that Iran was being blamed for the incident.
“I just want to mention that we heard in Minnesota there was a cyberattack, and they blame it on Iran,” he said at the start of a Cabinet meeting Friday at Camp David, Maryland.
The president said he did not accept that attribution.
“I don’t think so. I think I blame it on Minnesota because they’re grossly incompetent,” Trump said. “There was a cyberattack of 30 water plants, and I would blame it on Minnesota and the governor, the corrupt governor of Minnesota. They like to say, oh, is Iran? Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota.”
Trump offered no technical evidence supporting his rejection of possible Iranian involvement.
Weak security and foreign attack can coexist
Poor cybersecurity and foreign responsibility are not mutually exclusive explanations.
An Iranian-linked group could exploit vulnerabilities created by weak passwords, unprotected internet connections or outdated equipment.
Determining responsibility requires investigators to examine malicious software, server records, infrastructure and techniques used during the intrusion.
Separately, reviewing the affected utilities’ security practices can establish why the attacker succeeded.
Trump’s comments focused on state competence rather than the technical evidence used to attribute cyberattacks.
Walz responds to Trump
Walz challenged the president’s account in a post on X.
“Trump knows exactly who is responsible for this attack, and knows that other states were hit too. This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran.”
Walz’s statement directly blamed the conflict with Iran for the cyberattack.
He did not provide public evidence supporting his claim in the supplied report.
His reference to other states suggests the activity may have extended beyond Minnesota, although those additional incidents were not described.
Political hostility shapes response
Trump has repeatedly attacked Walz, the Democratic vice presidential nominee in 2024.
The president has focused particularly on fraud involving social-service programs administered by Minnesota.
Walz abandoned his campaign for a third gubernatorial term in January as scrutiny of his administration’s handling of those schemes increased.
He has not been accused of personally participating in the fraud.
The history of political conflict between the two men shaped Trump’s public response to the cyberattack.
More than 30 water systems targeted
Minnesota IT Services said the attack affected operational technology at more than 30 community water systems.
The incidents occurred Sunday and Monday.
Operational technology includes hardware and software that monitors or controls physical equipment such as pumps, wells, treatment systems and valves.
Interference can disrupt service even without compromising business networks or customer information.
A coordinated attack against numerous utilities suggests that the perpetrator searched for similar equipment or vulnerabilities across multiple communities.
State says investigation remains active
Minnesota IT Services has not determined whether a “specific actor” was responsible for the attack and the probe remains active.
That means the state has not issued a final public attribution to Iran or another group.
Cybersecurity investigations can take time because attackers frequently conceal their identities, use compromised servers and imitate other groups’ methods.
Initial assessments may change as investigators obtain additional evidence.
The absence of formal attribution does not mean that officials lack preliminary suspicions.
Officials reportedly suspect Iranian hackers
U.S. and Minnesota officials and other people familiar with the incident told The New York Times that Iranian hackers were likely responsible.
The supplied report did not identify those officials or describe the intelligence supporting their assessment.
Their conclusion remains preliminary unless the federal or state government issues a formal statement.
The timing of the attack is significant because it occurred during an escalating military conflict between the United States and Iran.
Cyber operations can provide governments with a way to retaliate without launching conventional attacks directly on American territory.
Braham controls temporarily shut down
Malicious software temporarily disabled controls for a well and water-treatment plant in Braham.
The supplied report did not specify how long the controls were unavailable or whether operators immediately switched to manual procedures.
Losing automated controls can disrupt pumping, chemical treatment, pressure management and other essential functions.
Utilities generally maintain manual alternatives for emergencies, but operating without automation may require additional personnel and monitoring.
Officials reported no known contamination of Braham’s drinking water.
Cities move to manual operations
Plymouth and South St. Paul shifted some operations to manual control.
The decision allowed local employees to maintain services while isolating or investigating potentially compromised digital systems.
Manual operation can prevent malicious software from sending dangerous commands to pumps and treatment equipment.
It may also limit efficiency and increase the workload for plant employees.
The report did not identify other communities where automated systems were disrupted.
No known threat to drinking water
Minnesota health officials said they were unaware of any active requests for residents to change their water use.
Minnesota IT Services said the “coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems” Sunday and Monday, but the Minnesota Department of Health is “not aware of any active requests from Minnesota cities to have their residents modify their drinking water usage.”
Officials reported no known threat to drinking-water safety.
Residents were not instructed to stop drinking tap water, boil it or reduce consumption.
Federal agencies issued advance warning
Federal agencies warned shortly before the Minnesota attacks that Iranian-affiliated hackers were targeting industrial control systems.
Those systems are used by water utilities, power facilities and local governments.
The warning said the hacking campaign had already disrupted operations at some facilities and caused financial losses.
Investigators believed the hackers intended to create disruption inside the United States.
The Minnesota incident involved the same general type of operational equipment identified in the warning.
Water systems attractive cyber targets
Community water utilities can be vulnerable because they often operate with limited budgets and small technical staffs.
Some facilities use aging industrial equipment that was not designed for internet connectivity or modern cybersecurity threats.
Remote access can help operators maintain systems efficiently but also creates entry points for hackers.
An attack does not necessarily require advanced techniques if equipment remains exposed online with weak credentials.
Smaller utilities may lack the monitoring systems needed to detect intrusions promptly.
Iran linked to previous water attacks
Iranian-affiliated hackers have previously targeted American water and wastewater facilities.
In 2023, hackers connected to Iran’s Islamic Revolutionary Guard Corps breached programmable logic controllers at several U.S. utilities, according to the Cybersecurity and Infrastructure Security Agency.
Programmable controllers operate physical processes such as pumps, valves and treatment equipment.
Access to those systems can allow an attacker to change operations or force utilities to shut down automation.
The earlier incidents provide context for the preliminary suspicion surrounding Minnesota.
Default passwords enabled earlier breaches
The 2023 attackers generally exploited equipment connected directly to the internet.
Many systems continued using default passwords or had no effective passwords.
Those weaknesses allowed hackers to gain access without developing sophisticated new tools.
Affected utilities moved some operations offline while investigating and securing their systems.
No drinking water was compromised.
The incidents demonstrated that basic security failures can expose critical infrastructure to foreign attackers.
New York dam targeted in 2013
An earlier Iranian cyber case involved a small dam in Rye, New York.
The Justice Department charged an Iranian hacker with repeatedly accessing its control system in 2013.
Prosecutors said the intrusion could have allowed the hacker to operate the dam’s sluice gate remotely.
The gate had been disconnected manually for maintenance at the time, preventing the attacker from moving it.
The case became an early warning about foreign efforts to access American infrastructure.
Cyberattacks complicate Iran conflict
The Minnesota incident occurred while the United States and Iran were exchanging military strikes.
Cyber operations can broaden a conflict beyond conventional battlefields and affect civilian infrastructure far from the Middle East.
Water systems, power grids and local governments may become targets because disruption can create public fear and economic costs.
Such attacks are also difficult to attribute quickly and confidently.
That uncertainty allows political leaders to offer competing explanations before technical investigations are complete.
Formal attribution remains unresolved
The current evidence presents two different levels of conclusion.
Anonymous officials reportedly assess that Iranian hackers were likely responsible.
Minnesota IT Services says it has not identified a specific actor and is continuing its investigation.
Trump rejects the Iran theory, while Walz publicly asserts that the president knows who carried out the attack.
Until authorities release technical findings, responsibility remains officially unresolved.
More on US News