US Water Attacks Confirmed in Seven States — Michigan, Georgia, South Dakota Named; Trump Calls Minnesota Governor 'Grossly Incompetent'
The scope has names now. Water attacks span Minnesota plus at least six more states — Michigan, Georgia, and South Dakota confirmed — while Trump rejects the Iran assessment and calls Minnesota's governor 'grossly incompetent.' What's firm, what's political, and what operators should do.
The map of the water-sector campaign has names on it now. What started as a Minnesota story is, according to reporting published August 3, a multi-state one: attackers hit water and wastewater systems in Minnesota plus at least six other states, with Michigan, Georgia, and South Dakota specifically identified.
SecurityWeek reported that the intrusions extend well past the original 30-plus Minnesota utilities, and The Register tied the wider set to a crew that officials assess is likely linked to Iran. That reporting sharpens the picture we covered when the seven-state scope first surfaced: the count is holding at seven, three more states are now named, and the political fight over who's responsible has escalated to the President rejecting his own agencies' read. Here's what's firm, what's still contested, and what operators should do regardless of how the attribution argument lands.
What the Reports Actually Say
The confirmed baseline hasn't moved much. Check Point Research, in its August 3 threat-intelligence bulletin, cited Minnesota IT Services confirming coordinated cyberattacks affecting more than 30 community water utilities across the state, with incidents that briefly disrupted a treatment plant in Braham and touched industrial control systems.
What's new is the reach. SecurityWeek's account puts the footprint at Minnesota plus at least six additional states. The Register's reporting adds the names: Michigan, Georgia, and South Dakota join Minnesota as states whose water systems were targeted by the same likely-Iran-linked activity. That's four states identified out of a claimed seven. The other three aren't named in the reporting, and it isn't yet clear whether every one of the seven states' agencies has formally confirmed involvement — so the "seven" is a reported total, not seven separate on-the-record confirmations.
Keep the attribution language precise. Officials and reporting describe the activity as likely tied to Iran, not formally attributed. That distinction matters, because it's the exact gap the political dispute is now being fought in.
|
Confirmed Baseline
Minnesota IT Services confirms coordinated attacks on 30+ community water utilities statewide. A treatment plant in Braham was briefly disrupted; industrial control systems were affected. This is the part that's on the record.
|
|
Scope Now
Reporting puts the footprint at ≥7 states. Named so far: Michigan, Georgia, South Dakota (plus Minnesota). Activity is likely tied to Iran. The full roster of seven — and whether every state has formally confirmed — is still unnamed.
|
Sources: Minnesota IT Services via Check Point Research; SecurityWeek; The Register (Aug. 3, 2026). Three of seven states remain unnamed.
Braham: The One Confirmed Operational Hit
Amid a lot of "no impact to drinking water" statements, Braham is the concrete exception worth holding onto. Per the Minnesota IT Services account relayed by Check Point, the incident there briefly disrupted a treatment plant and reached industrial control systems — the operational-technology layer, not just back-office IT. Most of the 30-plus Minnesota utilities reported no operational effect, which is the reassuring half of the story. Braham is the reminder that this class of intrusion can cross from the network into the process, even if only for a moment.
That's consistent with what federal guidance has been warning about: the exposure lives in remote-monitoring links and the programmable logic controllers that run pumps, wells, lift stations, and towers. A short disruption at one plant is a small operational event and a large signal about where the soft spots are.
Trump Versus the Attribution
The politics have gotten louder. The Register reported that President Trump rejected the theory that Iran was behind the water-system attacks and instead blamed the "grossly incompetent" governor of Minnesota. That puts the President at odds with the preliminary read shared by U.S. and state officials, who describe the activity as likely Iran-linked — the same split we tracked when the administration and its own agencies diverged on this.
Two things can be reported at once here without picking a side. One: multiple agencies and outlets place this campaign in the likely-Iran column, and that read is what's driving the seven-state framing. Two: the President has publicly rejected that attribution and located the fault with state-level management in Minnesota. Both are on the record. This piece isn't going to adjudicate which is correct — the technical attribution isn't settled to a formal standard yet, and the political characterization is a separate claim from the forensic one.
My read: the attribution fight is real and worth watching, but it's a distraction from the only question a utility operator can act on this week. Whether the hand on the keyboard was in Tehran or somewhere else, the intrusion paths into a water plant are the same, and so are the fixes. Attribution changes the diplomacy. It doesn't change the checklist.
What Water Utilities Should Verify Now
None of this waits on a formal attribution finding. If you run or oversee a water or wastewater system, the practical list is short and it's the same list defenders have been handed after every OT-targeting campaign this year:
- Audit for internet-exposed PLCs and OT. Anything that answers from the public internet is a starting point for someone. Find it before they do.
- Disable or segment remote-management interfaces. If a control interface doesn't need to be reachable remotely, it shouldn't be. If it does, wall it off from the process network.
- Rotate credentials on internet-facing OT. Assume default and reused passwords are already known. Replace them, and kill shared logins where you can.
- Hunt undocumented cellular modems and links. Rogue or forgotten cellular connections are a favorite quiet door into remote sites. Inventory what's actually phoning home.
- Rehearse manual-operations fallback. The Braham disruption is the argument for this. Know that your operators can run the plant by hand if the automation is knocked out, and practice it.
For utilities working through this systematically, the federal water-sector advisories that circulated as the Minnesota incident unfolded point at the same failure modes. The value in acting now is that every item above is independent of who gets blamed.
Open Questions
A few things are genuinely unresolved, and it's worth naming them so the confidence flags stay honest:
- The full seven-state roster. Only four states are named — Minnesota, Michigan, Georgia, South Dakota. The remaining three haven't been identified in the reporting, and whether all seven states' agencies have formally confirmed is still open.
- Formal attribution. "Likely tied to Iran" is where this sits. It has not been elevated to a formal government attribution, and the President has publicly rejected it.
- The Minnesota governor's response. As of this reporting, whether Minnesota's governor has publicly answered the "grossly incompetent" charge isn't established in the source material here.
- Federal follow-through. It's unclear whether CISA will reissue or expand its earlier water-sector alert, and how the attribution split affects the federal response is unsettled.
The through-line is straightforward even with the gaps: the confirmed core is Minnesota's 30-plus utilities and a brief hit at Braham; the reported scope is seven states with four now named; the attribution is likely-Iran and politically contested; and the defensive work doesn't depend on any of that being finalized. We'll update as the remaining states and any federal response come into focus.