Iranian Hackers Target US Water Systems, But Iowa Among States That Fought Biden-Era Cybersecurity Rules
Federal cybersecurity officials are investigating a wave of cyberattacks on U.S. water systems, with Iran emerging as a prime suspect. While President Donald Trump has publicly blamed Minnesota's state government for a recent attack in that state, intelligence agencies have not yet definitively concluded Tehran was responsible for disruptions in Minnesota and elsewhere. The attacks highlight a long-standing vulnerability in the nation's water infrastructure, a weakness that Iowa and other states have helped preserve by suing to block stricter federal cybersecurity rules.
What happened in the water system attacks?
Hackers have been targeting internet-connected programmable logic controllers (PLCs) at water, wastewater, and energy facilities across the country. These devices, often made by Rockwell Automation/Allen-Bradley, are widely used in critical infrastructure. In some cases, attackers used low-sophistication tactics to exploit weak or nonexistent passwords, locking out operators and forcing utilities into manual operations. This has led to boil water notices and temporary plant shutdowns.
Beyond Minnesota, Michigan and South Dakota have also reported attacks. Experts say it is likely many more states are affected, given the widespread use of the targeted equipment. Joshua Corman, a public safety expert at the Institute for Security and Technology, noted,
We only have one internet and it's the same equipment for all these victims. Theoretically, you should see these vulnerabilities in all 50 states.
Why is U.S. water infrastructure so vulnerable?
Experts widely agree that America's water infrastructure has been uniquely vulnerable for more than a decade. Of the roughly 151,000 water plants in the U.S., only about one-third service residential communities year-round. Yet only about 420 water plants participate in WaterISAC, a group that works to improve cybersecurity across the water sector. Corman put it bluntly:
We have under 0.5% paying attention to cybersecurity. Water is incredibly prone. We've been prey, we just didn't have predators with an appetite for water, but that's over.
Another major issue: many small to medium-sized utilities rely on third-party contractors who configure security settings using default credentials and weak passwords. The water industry has also resisted federal cybersecurity regulation.
How did Iowa fight Biden-era cybersecurity rules?
In 2023, the Biden administration tried to impose cybersecurity audits on water utilities. But water industry groups and three states — Missouri, Arkansas, and Iowa — sued to block the rule. The lawsuit succeeded, forcing the Environmental Protection Agency to roll back its standards. This means Iowa water utilities remain largely unregulated on cybersecurity, a fact that critics say leaves them exposed.
Nate George, the mayor of Braham, Minnesota — which experienced a hack that briefly knocked its plant offline — told the Washington Post that cities like his need more resources to comply with mandates to keep infrastructure safe. The tension between federal oversight and local control remains a key issue.
What did Trump say about the attacks?
President Trump, at a Camp David meeting with Cabinet officials, dismissed the idea that Iran was behind the Minnesota attack. Instead, he blamed state officials, a frequent political target.
I blame it on Minnesota because they're grossly incompetent. I would blame it on Minnesota and the governor, the corrupt governor of Minnesota. Iran's got bigger problems than worrying about Minnesota,Trump said.
Governor Tim Walz, a Democrat, fired back, pointing the finger at both Iran and Trump.
Trump knows exactly who is responsible for this attack, and knows that other states were hit too. This is what modern warfare looks like, and it further illustrates there's no plan to win a war with Iran,Walz said.
What does this mean for Iowa?
Iowa's decision to join the lawsuit against Biden-era cybersecurity rules means the state's water utilities remain outside federal oversight. While this aligns with conservative principles of limited government and local control, it also leaves the door open for similar attacks. Experts warn that the threat is only expanding. As Alec Davison, an analyst with WaterISAC, explained,
This has led to boil water notices and forced utilities into sustained manual operations.
For Iowa communities, the question is whether local utilities have the resources and expertise to secure their systems without federal mandates. The answer may determine whether the state becomes a target in the next wave of cyberattacks.
FAQ: What you need to know about the water system hacks
Who is behind the attacks on U.S. water systems?
Intelligence agencies suspect Iran, but have not definitively concluded Tehran is responsible. Federal cybersecurity officials have warned for months that Iranian hackers are targeting vulnerable PLCs in the U.S.
Are Iowa water utilities at risk?
Yes. The targeted equipment is widely used nationwide, and Iowa's water utilities are not subject to federal cybersecurity audits due to the state's successful lawsuit against Biden-era rules.
What can local utilities do to protect themselves?
Experts recommend using strong, unique passwords, avoiding default credentials, and participating in information-sharing groups like WaterISAC to stay ahead of threats.
Is the federal government helping?
The FBI and other agencies say they are fully engaged to protect critical infrastructure. However, the Trump administration has focused blame on state officials rather than foreign actors, and the rollback of federal oversight means less direct federal involvement in water utility security.