Trump blames Minnesota for water systems cyber attack, but experts say it’s too soon to dismiss Iran – PolitiFact - GoGoSpoiler

Trump blames Minnesota for water systems cyber attack, but experts say it’s too soon to dismiss Iran – PolitiFact


President Donald Trump has pointed the finger at Minnesota and its Democratic leader, Gov. Tim Walz, following a wave of cyberattacks on water facilities across the state. In doing so, he dismissed recent warnings from federal cybersecurity officials pointing toward potential Iranian involvement.

Speaking on July 31 at a Cabinet gathering held at Camp David, Trump asserted, “I think that Minnesota is behind it. You know who is behind it? Minnesota, because they are grossly incompetent. I think the governor is behind it. I don’t think there was an Iranian cyberattack. I think that Minnesota needs to get its act together.”

Contradicting that narrative, the Cybersecurity and Infrastructure Security Agency (CISA) issued an alert on July 22 concerning “ongoing Iranian-affiliated cyber targeting” directed at critical infrastructure devices. A prior 2024 advisory from the same agency highlighted similar Iranian threats specifically targeting water and wastewater management networks.

When Minnesota authorities originally reported the security breach, state officials noted that the compromised systems primarily utilized programmable logic controllers—the exact vulnerabilities flagged by federal cybersecurity experts. Furthermore, the FBI reported that at least six other states experienced simultaneous attacks, raising questions about why Minnesota would be held uniquely accountable for incidents occurring nationwide. (The bureau did not disclose which other states were affected.) 

When asked to provide proof that Minnesota acted alone, a White House spokesperson simply redirected inquiries back to the president’s prior statements. 

Industry experts emphasize that dismissing potential foreign actors like Iran in favor of placing total blame on a single state is premature.

“Cyberattack attribution is typically very difficult and inherently uncertain,” explained Vassil Roussev, director of the Cyber Center at Louisiana State University New Orleans. “There are usually clues based on known methods, code and other attributes, but these could be imitated by a third party as well. This is similar to intelligence assessment — there is rarely complete certainty, only degrees of confidence.”

FBI Receives Incident Reports from Seven States Throughout July 

Minnesota IT Services announced that operational technology across more than 30 community water systems was hit by a coordinated digital intrusion on July 26 and 27. The state department stated it was actively collaborating with federal investigators to examine the breaches. 

On July 30, a joint bulletin from the FBI and the Environmental Protection Agency revealed that malicious hackers had targeted water and wastewater facilities in “at least seven states,” noting that certain operations experienced degraded functionality as a result.

According to the FBI, the intruders gained remote entry to internet-connected devices, altering IP addresses and login credentials to sever monitoring and control capabilities. Resulting physical issues included pressure drops and localized flooding. However, The Minnesota Star Tribune reported that local officials confirmed drinking water safety and quality remained uncompromised.

“Minnesota state officials have been briefed that Iran was likely responsible for the attack,” The Minnesota Star Tribune noted. Similarly, The New York Times cited multiple government sources indicating early evidence pointed toward Iranian hackers.

In response, Gov. Walz wrote in an online post that “Trump knows exactly who is responsible for this attack, and knows that other states were hit too. This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran.” 

Meanwhile, CISA urged organizations to heighten defenses, emphasizing that these hostile entities are pursuing water facilities of every scale.

Walz also criticized the current administration for weakening national cyber defenses, stating via social media that a federal spending reduction initiative known as DOGE had “took an axe to CISA and left the U.S. exposed to cyber attacks.”

Public records indicate the Trump administration has indeed downsized personnel and resources at CISA, which oversees critical infrastructure and electoral security. Historically, Trump dismissed CISA director Chris Krebs after the agency vouched for the security of the 2020 presidential election.

Roussev stressed that digital threats facing critical infrastructure like municipal water systems remain a serious, ongoing danger.

Many of these operational frameworks “rely on old automation technologies that were never designed with security in mind and are, by default, very vulnerable,” he observed. Protecting them “requires systematic planning, investments and constant vigilance. Any lapses are potentially exploitable by adversaries with the potential for mass effects in the physical world.”



Reference

Leave a Comment