The Federal Bureau of Investigation opened inquiries into cyberattacks reported by water systems in Michigan and Minnesota, as federal agencies assessed a broader series of incidents affecting critical infrastructure. Michigan identified activity at nine water systems, while Minnesota had previously reported attacks involving 30 sites.
No attacker had been identified as of August 1. The incidents followed a warning from the FBI, the Cybersecurity and Infrastructure Security Agency and partner agencies that Iranian hackers were targeting water and wastewater facilities and the operational controls used in other essential sectors. That alert made Iran one line of inquiry, not a confirmed source of the breaches.
Michigan received a federal notification about attempts to interfere with operational technology on the Tuesday before the FBI statement. State environment-department spokesperson Dale George said a small number of communities then reported activity resembling the pattern described by federal authorities. He said all affected systems continued to operate safely.
In Minnesota, most confirmed incidents involved tools that plants use to monitor and control equipment remotely. State information-technology officials stressed that a compromised system did not automatically mean water service had been interrupted. By the Thursday before the announcement, residents were not under active requests to change consumption, although some modifications had been requested earlier.
The FBI said it and other agencies were engaged in protecting water infrastructure and investigating the public reports. Its wider advisory referred to incidents in at least seven states, but only Michigan and Minnesota had been publicly named in the supplied coverage. The identities and circumstances of the other states remained undisclosed.
Local water plants can be vulnerable because they may operate older control systems and have fewer cybersecurity resources than larger utilities. Remote-access technology can improve efficiency, but poorly secured connections create a route for intruders to manipulate settings or disrupt operators. Federal prosecutors had previously charged Iranian hackers in cases involving attacks on water infrastructure.
Political reactions moved ahead of the evidence. Minnesota Governor Tim Walz said he believed Iran was responsible and argued that reductions in federal staffing had weakened cyber defence. President Donald Trump rejected that view and suggested Minnesota itself was responsible, without presenting supporting details. Neither statement amounted to an investigative finding.
The most important operational fact was that officials reported safe water service despite the intrusions. The unresolved questions concerned who accessed the systems, whether the incidents were coordinated, and what changes utilities needed to prevent recurrence. The FBI investigation was intended to distinguish those technical facts from competing political claims.



