Summary
- President Trump publicly blamed Minnesota for cyberattacks on its own water systems, contradicting assessments from CISA, the FBI, and his own intelligence services attributing the attacks to Iran.
- CISA recently updated an advisory specifically warning that Iranian-affiliated actors are exploiting programmable logic controllers across US water and critical infrastructure sectors.
- WaterISAC, Halcyon, Scythe, and IANS faculty members all expressed confidence in the Iran attribution, describing the attacks as opportunistic exploitation rather than targeted political acts.
- CISA has been significantly reduced in size under the current administration, with states increasingly left to manage critical infrastructure defence without prior levels of federal support.
- Minnesota IT Services declined to address the political remarks and stated it remains focused on containment, coordination with local partners, and supporting affected communities.
What happened
Cyberattacks struck water systems across multiple US states in recent days, with federal investigators attributing the activity to Iran. CISA updated an advisory last week — jointly issued with the FBI — warning that Iranian-affiliated actors are actively exploiting programmable logic controllers (PLCs) used in the water sector and other critical infrastructure. WaterISAC, the water industry’s information sharing and analysis centre, said it is confident the confirmed activity aligns with that advisory.
The political dimension
Speaking to reporters, President Trump departed from the official attribution, stating: “I think that Minnesota is behind it. Because they’re grossly incompetent. I don’t think there was an Iranian cyberattack.” The White House, when asked to clarify who the President believed was responsible for similar attacks in other states, did not respond. Trump has previously downplayed Iranian attacks during the military campaign he launched against Iran alongside Israel beginning in February, and has a pattern of questioning his own government’s cyber attribution findings — he similarly cast doubt on Russian responsibility for the SolarWinds breach.
The expert response
Security professionals pushed back promptly. Jake Williams of IANS faculty noted plainly that Trump’s “own intelligence services are attributing this to Iran.” Cynthia Kaiser, former senior FBI cyber official and now at Halcyon, described Iran as ticking every box the bureau uses for attribution: technical indicators, historical capability, prior similar attacks, and logical motive. “My view is, if it walks like a duck, if it talks like a duck, I strongly suspect it’s a duck,” she told CyberScoop. Bryson Bort of Scythe described the attacks as a target of opportunity — hackers finding exploitable internet-facing assets — rather than anything Minnesota did to specifically provoke Iranian action.
The victim-blaming problem
Andy Jabbour, founder and CEO of Gate 15, which provides cybersecurity support to the water sector, said he could not determine what the President was actually suggesting Minnesota had done or failed to do. He characterised public, unsubstantiated allegations directed at a political opponent — in the context of an active CISA and FBI advisory and an ongoing conflict with Iran — as “reckless” and “a disservice to the American people.” Minnesota IT Services declined to engage with the political remarks, with spokesperson Emily Zimmer stating the agency would “not comment on political statements or speculate about attribution” and remains focused on containment and coordination.
The structural concern
Governor Tim Walz pointed to reductions at CISA under the current administration as a contributing factor to the exposure. CISA has contracted considerably in size, and the administration has increasingly shifted responsibility for critical infrastructure defence to the states themselves. Tom Dobbins, executive director of WaterISAC, called on Congress to provide dedicated funding for the ISAC, noting the water sector’s persistent vulnerability and Iran’s demonstrated history of targeting it even before the current conflict.
Why it matters
For CISOs in critical infrastructure — and particularly in the water, energy, and industrial sectors — this episode carries several layers of risk. First, the technical threat is real and active: Iranian-affiliated actors are exploiting internet-exposed PLCs, and CISA and the FBI have documented the activity. Second, the political noise around attribution creates genuine operational risk: organisations that look to government signals for threat intelligence will find those signals contradictory. Third, the scaling back of CISA means less federal support for detection, response, and information sharing — a gap that sector ISACs and state agencies cannot fully absorb. If your organisation operates OT or ICS environments, the advisory referenced in this reporting (AA26-097A) warrants direct attention regardless of the political environment surrounding it.
What to do now
- Review the CISA and FBI joint advisory AA26-097A on Iranian exploitation of programmable logic controllers and assess whether any internet-facing PLCs or OT assets in your environment match the described attack surface.
- Audit internet exposure of industrial control systems and programmable logic controllers; remove or restrict remote access where it is not operationally essential.
- Engage directly with your sector ISAC — WaterISAC explicitly confirmed confidence in the federal attribution and is coordinating threat intelligence for the water sector.
- Do not allow political ambiguity around attribution to delay or deprioritise incident response or patching cycles; base decisions on the technical advisory, not public commentary.
- Review your organisation’s reliance on federal support structures given reported reductions to CISA capacity, and assess whether existing state and sector partnerships need to be strengthened to compensate.
