Michigan Reports Cyberattacks on Nine Water Systems as Federal Investigation Targets Iranian Hacker Threat
Key Takeaways
- •Michigan confirmed that nine of its water systems were targeted by cyberattacks, and all affected systems continued operating safely without any public health risks.
- •Minnesota reported over 30 of its water systems were targeted, with the city of Braham experiencing a temporary plant shutdown and Plymouth facing disrupted infrastructure communications.
- •Federal agencies including the FBI and CISA issued an advisory warning that Iranian hackers have been targeting water and wastewater systems as well as other critical infrastructure sectors.
- •Iran has a documented history of targeting U.S. water infrastructure, including a 2016 attack on a dam near New York City and a 2023 compromise of a Pennsylvania water facility by a group linked to Iran's Islamic Revolutionary Guard Corps.
- •The majority of the approximately 50,000 community water systems in the United States serve fewer than 10,000 people and operate with limited staff and cybersecurity budgets, making them attractive targets for cyber intruders.

Michigan disclosed on Saturday that nine of its water systems were targeted by cyberattacks, making it the second U.S. state after Minnesota to report such incidents. State officials confirmed that all affected systems continued operating safely with no public health risks.
The announcement followed a federal cyber alert issued Tuesday warning of attempts to tamper with operational technology at water systems. The state subsequently received "a small number of reports from Michigan communities indicating activity consistent with what federal agencies described," according to Dale George, director of communications at the Michigan Department of Environment, Great Lakes, and Energy. George later confirmed that nine systems were impacted.
"All systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern," George said in a statement.
The FBI, which is leading the investigation, has not publicly identified a culprit. A bureau spokesperson declined to comment Thursday on who might be responsible. However, the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and other federal agencies issued an advisory last week warning that Iranian hackers have been targeting water and wastewater systems, along with operational controls across other critical infrastructure sectors.
"The FBI is aware of recent public reporting around Water and Wastewater (WWS) sectors," the agency said in a statement Saturday. "The FBI and our interagency partners are fully engaged to protect critical infrastructure and we remain well-equipped to protect against cyber threats of all varieties."
Minnesota authorities reported earlier in the week that more than 30 of the state's water systems had been targeted. Minnesota IT Services stated that as of Thursday, no communities had issued requests for residents to modify their drinking water usage. The agency noted that most confirmed attacks involved technology used to remotely monitor and control equipment. Being classified as "impacted" meant investigators confirmed malicious activity involving a system's technology, but did not necessarily mean every affected community experienced service disruptions.
In the city of Braham, population approximately 1,700 and located about 70 miles (113 kilometers) north of Minneapolis, residents were asked for several hours on Monday to minimize water use while officials investigated why the water plant was offline. The city said in a news release that the outage resulted from a cyberattack, though water quality was unaffected. According to the city, attackers disabled the operating controls that shut down the well and water treatment plant, temporarily leaving the city able to supply only the water held in its water tower.
In Plymouth, a city of roughly 80,000 outside Minneapolis, officials announced on social media that water infrastructure communications had been restored by Tuesday afternoon after being disrupted by a cyberattack.
Iran's interest in U.S. water system operations has persisted for years. In 2016, the Justice Department charged a group of Iranian hackers in connection with a cyberattack on a small dam near New York City. In November 2023, a group calling itself CyberAv3ngers, linked by U.S. authorities to Iran's Islamic Revolutionary Guard Corps, compromised a water facility in Aliquippa, Pennsylvania, by targeting programmable logic controllers manufactured by Israel-based Unitronics. That incident prompted a separate CISA advisory urging water utilities to change default passwords and restrict internet exposure of operational devices.
Digital warfare has become deeply embedded in modern military conflict, and local water utilities and healthcare facilities frequently lack the funding and technical expertise needed to deploy the latest software patches and security measures. The United States has roughly 50,000 community water systems, according to the Environmental Protection Agency, and the vast majority serve fewer than 10,000 people, meaning many operate with small staffs and limited cybersecurity budgets. This vulnerability has made such facilities attractive targets for cyber intruders, given both the relative ease of compromise and the potential for public alarm.
During a Cabinet meeting on Friday at the Camp David presidential retreat in Maryland, President Donald Trump claimed without evidence that recent cyberattacks in Minnesota were the fault of the state government, including Democratic Governor Tim Walz. Walz responded on social media, stating that Trump "knows exactly who is responsible for this attack, and knows that other states were hit too."