A hacking campaign that began in Minnesota's water systems is now known to stretch across at least seven states, with federal officials increasingly pointing to Iran as the likely source. The intrusions have hit internet-connected control systems that regulate treatment chemicals and water pressure; in some cases, utilities were pushed into manual operations and issued boil-water notices. Authorities said there's no evidence that drinking water has been contaminated, the New York Times reports, but warn the scope could be wider as more systems check their networks.
The FBI and EPA said some attacks have disrupted operations, and Michigan has confirmed nine municipal systems experienced suspicious activity but remained safe. Cybersecurity experts describe the incidents as a notable escalation by Iran-linked hackers, who have been more active since the war with the US began five months ago. President Trump has publicly dismissed the likelihood of Iranian involvement, instead suggesting Minnesota was to blame—an assertion the Gov. Tim Walz rejected. Behind the scenes, federal officials and industry memos are treating Tehran as the leading suspect, per the Times, while small cities grapple with how to pay for security upgrades for aging infrastructure.
CBS News counts more than 30 community water systems affected in Minnesota. Digital warfare has become ingrained in military conflict, the AP points out, and local water plants or health care facilities often lack the money and know-how to install the latest software patches or take other security steps. That has made them a favorite target, partly because of the panic such disruptions can cause.