Key Takeaways
- President Donald Trump blamed Minnesota Gov. Tim Walz for a cyberattack on the state’s water systems, dismissing possible Iranian involvement and citing “gross incompetence.”
- Gov. Walz rebutted, asserting that federal cybersecurity cuts by the Department of Government Efficiency (DOGE) weakened CISA and that Minnesota’s experts quickly identified and mitigated the threat.
- More than 30 Minnesota water systems were targeted, with attackers focusing on programmable logic controllers (PLCs) used for remote monitoring and control of pumps, valves, and treatment processes.
- CISA issued an alert warning that threat actors modify PLC passwords to lock out operators; Minnesota officials report no disruption to water service and are working with federal investigators.
- Senator Amy Klobuchar said the National Cyber Director confirmed no service impacts and noted nationwide FBI and EPA warnings about similar PLC‑targeted attacks.
Trump’s Accusation Against Governor Walz
At a Cabinet meeting at Camp David on July 31, 2026, former President Donald Trump directly blamed Minnesota Governor Tim Walz for a recent cyberattack on the state’s water systems, insisting that the incident stemmed from “gross incompetence” rather than any foreign actor. Trump dismissed reports that U.S. officials were probing whether Iran or Iran‑linked hackers were responsible, stating, “I don’t think so. I think, I blame it on Minnesota because they’re grossly incompetent.” His remarks came amid a broader discussion of national security priorities and reflected his tendency to attribute cyber incidents to state‑level shortcomings. The comment sparked immediate pushback from Walz and other state leaders, who argued that the attack was part of a coordinated campaign targeting critical infrastructure across the country.
Governor Walz’s Counter‑Argument and Critique of Federal Cuts
In a series of social‑media posts Friday, Governor Walz rebutted Trump’s accusation, asserting that the former president “knows exactly who is responsible for this attack” and that other states had been hit as well. Walz characterized the incident as an illustration of modern warfare and warned that there is “no plan to win a war with Iran.” He also highlighted that recent federal cuts made by the Department of Government Efficiency (DOGE) had weakened the Cybersecurity and Infrastructure Security Agency (CISA), leaving the United States exposed. Walz praised Minnesota’s IT experts for quickly identifying the vulnerability and collaborating with local communities to mitigate the threat, arguing that strong state‑level readiness can compensate for federal shortcomings.
Scope and Nature of the Cyberattack on Minnesota Water Systems
According to Minnesota IT Services (MNIT), more than 30 water systems across the state were targeted in the cyberattack that unfolded over Sunday and Monday, February 2‑3, 2026. The attackers focused on gaining remote access to systems that monitor and control essential equipment, particularly programmable logic controllers (PLCs) that regulate pumps, valves, and treatment processes. MNIT emphasized that the intrusion was detected early, allowing officials to isolate affected components and prevent manipulation of water flow or quality. Although the agency has not released a definitive list of the compromised utilities, it confirmed that the scope was significant enough to warrant a coordinated response with federal partners and local operators.
Technical Details: PLC Targeting and CISA Alert
The Cybersecurity and Infrastructure Security Agency (CISA) issued an alert on Thursday noting that cyber threat actors are increasingly targeting PLCs in U.S. water systems, often modifying passwords to “lock out operators” and hinder manual intervention. In Minnesota’s case, investigators observed that the malicious actors attempted to change credentials on the PLCs, which could have prevented local technicians from overriding automated controls. CISA’s warning stressed that such tactics are part of a broader campaign to disrupt critical water infrastructure by impairing operational technology (OT) environments. Despite the attempted credential changes, MNIT reported that its teams were able to restore access and maintain system integrity before any service disruption occurred.
Current Impact Assessment and Ongoing Investigation
MNIT stated that, as of the latest update, there are no active requests from Minnesota localities for residents to alter their water use, indicating that water delivery and safety have not been compromised. The agency is working closely with federal investigators, including the FBI and CISA, to determine the origin of the attack, but has not yet attributed responsibility to any specific group or nation‑state. Officials continue to monitor network traffic for signs of lingering persistence or additional intrusion attempts, and they have advised utilities to implement recommended hardening measures such as multi‑factor authentication and network segmentation for OT environments.
Senator Klobuchar’s Remarks and Federal Guidance
Senator Amy Klobuchar (D‑MN) released a statement Friday confirming that she had spoken with U.S. National Cyber Director Sean Cairncross about the Minnesota incident. Director Cairncross informed her that, at present, there are no measurable effects on water service resulting from the cyberattack. Klobuchar noted that the conversation also covered the broader challenge of limited cybersecurity resources for many communities, not only in Minnesota but nationwide. She added that the FBI and the Environmental Protection Agency (EPA) have issued advisories to water utilities across the country, warning them of heightened risks to PLCs and urging prompt adoption of CISA’s best‑practice guidelines to strengthen defenses against similar intrusions.
Broader Implications for U.S. Water Infrastructure Cybersecurity
The Minnesota episode underscores the growing vulnerability of water sector operational technology to cyber threats, particularly as attackers increasingly focus on PLCs that control essential physical processes. Federal budget cuts to agencies like CISA, highlighted by both Walz and Klobuchar, have raised concerns about the nation’s ability to detect, respond to, and recover from such incidents at scale. Experts argue that sustained investment in OT security, regular staff training, and robust public‑private partnerships are essential to protect critical infrastructure. The incident also serves as a reminder that attribution in cyber operations can be complex; while state‑linked actors such as Iran remain a concern, domestic preparedness gaps can be equally consequential in enabling successful attacks.

