Michigan reported cyberattacks across nine water systems on Saturday, following similar breaches affecting more than 30 sites in Minnesota. The FBI is actively investigating the incidents as federal authorities warn that foreign hackers are targeting operational controls across critical water infrastructure sectors nationwide.
Digital intrusions targeting critical public utilities have expanded beyond Minnesota, drawing an immediate federal response. The Federal Bureau of Investigation confirmed on Saturday that it is investigating cyberattacks in both Michigan and Minnesota, marking a widening pattern of digital tampering against municipal water and wastewater networks.
Michigan Water Systems Targeted After Federal Security Warning
The disclosures in Michigan surfaced after state environmental officials received a federal security alert warning of malicious attempts to interfere with operational technology inside municipal water plants. Following that advisory, Michigan reported cyberattacks on nine of its water systems, according to state communications director Dale George. State officials emphasized that local operators stepped in to address the issues quickly.
Dale George, director of communications for Michigan’s Department of Environment, Great Lakes and Energy, stated that all systems continued to operate safely, that issues were addressed by local operators, and that there are no known impacts that posed a public health concern.
The state-level breaches follow an earlier wave of digital intrusions in Minnesota, where authorities reported cyberattacks targeting over 30 water systems. Most of the confirmed activity involved technology that local facilities use to monitor and control equipment from a distance. While several communities experienced operational hurdles—such as Braham, where a plant went offline for hours and required temporary water conservation measures—state technology officials confirmed that an impacted system did not automatically mean disrupted water service or compromised drinking water quality.
Federal Warnings Highlight Vulnerabilities in Municipal Utilities
Before the incidents in Michigan and Minnesota came to light, federal authorities issued a joint advisory pointing to Iranian hackers targeting water and wastewater systems alongside other critical infrastructure. Local water plants frequently operate with outdated cybersecurity measures and lack the funding needed to install timely software patches, leaving them exposed to actors seeking to cause public panic or disrupt vital services.
The intersection of geopolitics and municipal infrastructure security is far from new. The U.S. Department of Justice indicted a group of Iranian hackers for a 2016 cyberattack targeting a small dam near New York City. Yet identifying culprits in real time remains a complex hurdle for law enforcement. The FBI has not publicly named a suspect in the ongoing investigations.
The bureau added in its statement that the FBI and our interagency partners are fully engaged to protect critical infrastructure, maintaining that federal teams remain equipped to address diverse cyber threats.
Political Clashes Erupt Over Attributing the Breaches
While federal security agencies point toward foreign actors, political figures have traded sharp disagreements over who bears responsibility for the security failures. Speaking at a cabinet meeting at Camp David, President Donald Trump rejected the assessment that Tehran orchestrated the Minnesota attacks, instead placing blame on local leadership.
I think Minnesota is behind it. I don’t think there was an Iranian cyberattack. President Donald Trump
Trump further asserted during the meeting that I think I blame it on Minnesota because they’re grossly incompetent, singling out Minnesota Governor Tim Walz. The White House press office declined to clarify the president’s remarks regarding state culpability.
Governor Walz fired back on social media, countering that Trump knows exactly who is responsible for this attack, and knows that other states were hit too. Walz argued that prior reductions in federal personnel left domestic infrastructure increasingly exposed to digital intrusions.
What Lies Ahead for Municipal Cybersecurity Defenses
As investigators continue combing through digital logs in Michigan and Minnesota, the immediate threat to public health appears contained. State agencies in Minnesota reported no active requests for residents to alter water consumption as of late last week, and Michigan officials confirmed their nine affected sites are running safely. However, the incidents underscore a persistent security gap: local utility boards managing vital resources frequently lack the financial resources required to withstand coordinated state-backed cyber campaigns. With federal authorities continuing their interagency review, municipal operators across the country face heightened pressure to audit their remote monitoring systems before the next security alert arrives.
