Trump Blames Minnesota, His Agencies Blame Iran: The Water-Sector Attribution Split
The President and his own intelligence agencies now publicly disagree on who hit Minnesota's water systems. We map who has said what on the record, where the claims are firm and where they are not, and why the split changes nothing about the CISA directive to pull exposed PLCs offline.
The United States now has two official-sounding answers to the same question — who attacked Minnesota's water systems — and they come from the same government. At a Cabinet meeting at Camp David on Friday, President Trump said he did not believe Iran was responsible for the intrusions that have disrupted more than 30 Minnesota community water systems since late July. "I think that Minnesota is behind it," he told reporters. "Because they're grossly incompetent. I don't think there was an Iranian cyberattack." Separately he said, "Iran's got bigger problems than worrying about Minnesota." That position runs against the preliminary conclusion of his own intelligence agencies, which — per reporting from CyberScoop and The Washington Post — have assessed Iran as the likely actor.
Disagreements over attribution are routine in cybersecurity; a disagreement this public, between a sitting president and the agencies that report to him, during an active critical-infrastructure incident, is not. For water-sector defenders the split produces an awkward operating condition: the officials who set national policy are not speaking with one voice about the threat. What follows maps exactly who has said what, marks where the claims are firm and where they are not, and explains why — for anyone actually running a treatment plant — the disagreement should change nothing about the next 72 hours.
What Each Side Has Actually Said
Strip away the politics and a large amount of this is not in dispute. Minnesota IT Services has stated that more than 30 community water systems were hit by a coordinated cyberattack beginning July 26. In its July 30 public alert, CISA described a "significant increase" in malicious activity against water utilities and said intruders "have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses," producing boil-water notices and sustained manual operations. The FBI has said utilities in at least seven states have reported incidents involving programmable logic controllers. Those are the confirmed, on-the-record facts of the incident itself.
The divergence begins at attribution — the question of who. On one side sit a set of assessments pointing to Iran. A leaked WaterISAC memo, first reported by Wired, tied the activity to Iran, and WaterISAC executive director Tom Dobbins told CyberScoop the group is "confident in our government partners' assessment that the confirmed activity is aligned with" CISA's joint advisory AA26-097A on Iranian-affiliated actors exploiting PLCs. Independent practitioners quoted by CyberScoop reached the same read: Scythe founder Bryson Bort called it "a target of opportunity" consistent with Iranian activity, and former FBI cyber official Cynthia Kaiser said, "if it walks like a duck… I strongly suspect it's a duck. I'd be shocked if we found out it wasn't Iran." IANS faculty member Jake Williams put the internal contradiction plainly: "His own intelligence services are attributing this to Iran."
On the other side is the President, who rejected the Iran assessment without naming an alternative perpetrator and instead faulted the state of Minnesota and its Democratic governor. Governor Tim Walz pushed back, saying Trump "knows exactly who is responsible for this attack, and knows that other states were hit too." Minnesota IT Services, for its part, declined to engage the politics: a spokesperson said the agency "will not comment on political statements or speculate about attribution" while the investigation continues.
One detail is easy to miss and worth holding onto: CISA's own Thursday alert — the operational one telling utilities what to do — does not name Iran at all. The public alert and the intelligence assessment are two different documents with two different evidentiary bars.
● ATTRIBUTION SCORECARD: WHO SAID WHAT | |
WaterISAC (leaked memo) | Ties the activity to Iran; “confident” it aligns with CISA advisory AA26-097A on Iranian-affiliated actors. |
CISA public alert (Jul 30) | Reports a spike in attacks on water systems; urges removing publicly exposed PLCs and OT from the internet. Does not name Iran. |
Cyber experts (via CyberScoop) | Iran is the likely actor — a “target of opportunity” (Bort); “I’d be shocked if it wasn’t Iran” (Kaiser). |
President Trump | Blames the state of Minnesota (“grossly incompetent”), not Iran; names no alternative perpetrator. |
Positions mapped, not adjudicated. Sources: WaterISAC via Wired; CISA alert via The Record; remarks via CyberScoop. | |
Why an Open Split Is Unusual — and What It Doesn't Tell Us
It helps to separate two things that are easy to conflate. An intelligence assessment ("we assess with some confidence that Iran is the likely actor") is not the same as a formal, public government attribution ("we attribute this to Iran"). The first is an analytic judgment; the second is a policy act that typically clears a higher evidentiary bar and often carries diplomatic consequences. That gap is a plausible reason CISA's operational alert stayed silent on Iran even as the underlying assessment pointed there — a distinction worth keeping in mind before reading the President's comments as a straightforward factual correction. That reading is my assessment, not an established fact.
What the split does not tell us is who actually did it. A president publicly doubting an assessment does not disprove it, and expert consensus around Iran — however well-reasoned — is still an assessment, not a confirmed, evidence-published attribution. Both remain, in confidence terms, reported and assessed rather than confirmed. The honest state of play is that the technical facts of the incident are firm, the identity of the attacker is probable-but-contested, and the loudest disagreement is happening between people who are not the ones defending the pumps.
What an Unresolved Attribution Split Means for Water Operators
Here is the part that matters if you run or defend a water system, and it is genuinely simple: none of your defensive priorities depend on the flag on the attacker. The CISA directive to remove publicly exposed PLCs and other OT from the internet "as soon as possible" stands regardless of whether the answer is eventually Tehran, some other actor, or a mix. Attribution is a policy and intelligence problem. Exposure is yours, and it is fixable today.
Concretely, the incident's own mechanics dictate the checklist. Because the intruders reportedly changed passwords to lock out operators, credential rotation and out-of-band recovery access are urgent — assume standing credentials on any internet-facing OT may already be compromised. Because they disconnected controllers by changing IP addresses, monitoring for unexpected PLC configuration and addressing changes is a high-value detection. Because the campaign has forced plants into manual operation, rehearsing and staffing manual-operations fallback is now an operational readiness item, not a tabletop hypothetical. And because CISA specifically flagged cellular modems installed by operators, vendors, or integrators that "may not be documented or included in routine attack surface scans," an external-connection inventory should explicitly hunt for undocumented links, not just the ones you already know about.
The strategic takeaway for defenders is to decouple response from attribution entirely. If your remediation plan has a step that waits on a definitive public naming of the attacker, that step is a liability — the naming may never come cleanly, and this week is a live demonstration of how contested it can be. Pull exposed controllers offline, rotate credentials, and validate your external connections now; let the intelligence community and the politicians sort out the who on their own timeline.
Open Questions
Several threads remain genuinely unresolved as of this writing. The five other affected states beyond Minnesota and Wisconsin have not been publicly named. No agency has issued a formal, evidence-backed public attribution, so the Iran assessment stays at the "reported/assessed" tier. It is unclear whether the administration will reconcile the President's comments with the working intelligence assessment, or simply let the two stand in parallel. And it is not yet known whether the campaign is opportunistic exploitation of exposed devices — as Bort suggested — or something more targeted. We will update this analysis as attribution firms up or additional states are confirmed.
Primary Documents
- CyberScoop — Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world
- The Record — CISA warns of spike in attacks on water systems as Minnesota incidents probed
- The Washington Post — U.S. spy agencies suspect Iran launched cyberattack on Minnesota water facilities
- Wired — A leaked memo ties cyberattacks on Minnesota water utilities to Iran
- The CyberSignal — CISA's water-sector OT / PLC guidance for Minnesota