Critical Infrastructure Under Fire
Michigan reported Saturday that nine of its water systems were impacted by cyberattacks, joining Minnesota, where authorities confirmed earlier this week that hackers had targeted more than 30 water systems across the state. All nine Michigan systems continued to operate safely, according to Dale George, director of communications at the state's Department of Environment, Great Lakes, and Energy.
'All systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern,' George said in a statement.
The Michigan reports surfaced after the state received a federal cyber alert Tuesday about attempts to tamper with operational technology at water systems.
FBI and CISA Move In
The FBI is now investigating. The bureau has not publicly identified a culprit, and a spokesperson declined Thursday to name who the bureau believed was responsible. However, the FBI, the Cybersecurity and Infrastructure Security Agency, and other federal agencies issued an advisory last week warning that Iranian hackers have been targeting water and wastewater systems and the operational controls of other critical infrastructure sectors.
'The FBI and our interagency partners are fully engaged to protect critical infrastructure and we remain well-equipped to protect against cyber threats of all varieties,' the FBI said in a statement Saturday.
Iran's interest in U.S. water infrastructure is not new. In 2016, the Justice Department charged a group of Iranian hackers in connection with a cyberattack targeting a small dam near New York City.
On the Ground: Braham and Plymouth
In Braham, Minnesota — a city of about 1,700 located roughly 70 miles north of Minneapolis — attackers shut down the operating controls of the well and water treatment plant on Monday, leaving the city temporarily reliant on water held in its tower. Residents were asked to minimize usage for a few hours. The city confirmed the outage was due to a cyberattack but said it caused no issue with water quality.
In Plymouth, a Minneapolis suburb of about 80,000 residents, officials said water infrastructure communications had been restored by Tuesday afternoon following a separate cyberattack.
Minnesota IT Services confirmed that most of the verified attacks involved technology water systems use to remotely monitor and control equipment. Being 'impacted,' the agency clarified, meant investigators confirmed malicious activity — not necessarily a disruption to water service.
The Systemic Vulnerability
The numbers come first, and here they are stark: dozens of municipal water systems across two states hit within days, with federal agencies already on record warning of Iranian targeting of critical infrastructure. The deeper problem is structural. As the reporting makes clear, local water plants and healthcare facilities routinely lack the funds and technical expertise to install current software patches or implement basic security protocols — making them soft targets for state-sponsored actors who understand that disruption breeds panic.
This is what happens when critical infrastructure is chronically underfunded at the operational level while Washington debates broader cybersecurity frameworks. Free enterprise depends on reliable public utilities; capital does not flow to communities where the tap may go dry because a foreign government can exploit an unpatched control system. The FBI's engagement is necessary — but the more durable answer is hardening these systems before the next advisory, not after.



