President Donald Trump said Friday that he does not believe Iran was responsible for the Trump Minnesota cyberattack, pushing back against growing speculation after coordinated cyberattacks disrupted operations at more than 30 Minnesota water systems. His comments came as the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and Minnesota officials continued investigating the incidents, while emphasizing that federal authorities have not formally attributed responsibility.
The attacks, which unfolded on July 26 and July 27, temporarily disrupted operational technology at multiple community water utilities. State officials said drinking water remained safe throughout the incident, but the attacks renewed concerns about the vulnerability of America’s critical infrastructure.
Timeline of the Minnesota Cyberattack
The investigation has developed rapidly over the past two weeks.
- July 22: Federal agencies issued a cybersecurity advisory warning that Iranian affiliated cyber actors were targeting programmable logic controllers (PLCs) used in critical infrastructure.
- July 26–27: Multiple Minnesota community water systems experienced coordinated cyber intrusions.
- July 28: Minnesota Information Technology Services confirmed more than 30 water systems had been affected.
- July 31: President Trump questioned whether Iran was responsible, while state and federal investigators continued examining the attacks.
Authorities stress that the investigation remains active and that no formal attribution has been announced.
Why Trump Says Iran Was Not Responsible
Speaking to reporters at Camp David on Friday, Trump rejected suggestions that Iran directed the cyber campaign targeting Minnesota’s water infrastructure.
“We heard in Minnesota there was a cyberattack, and they blame it on Iran. I don’t think so,” Trump said, according to Reuters.
The president also criticized Minnesota officials, saying he believed the state, rather than Iran, should bear responsibility for the security failures that allowed attackers to gain access.
“I blame it on Minnesota because they’re grossly incompetent,” Trump said.
Trump did not provide evidence supporting his assessment.
His remarks differ from recent federal cybersecurity warnings that identified tactics similar to those used in previous campaigns involving Iranian affiliated threat actors.
Federal officials have been careful to distinguish between identifying technical similarities and assigning responsibility.
Officials have not formally attributed responsibility for the Minnesota cyberattack.
Cybersecurity investigators say attribution requires forensic evidence, intelligence analysis, and corroborating technical data before responsibility can be assigned to a government or organized threat group.
That distinction remains central to the ongoing investigation.
What Happened During the Minnesota Cyberattack
Minnesota Information Technology Services said a coordinated cyberattack targeted more than 30 community water systems across the state between July 26 and July 27.
Investigators discovered unauthorized access to operational technology used to manage essential water infrastructure.
The attacks affected systems responsible for operating pumps, treatment equipment, valves, and other industrial controls.
Several utilities temporarily shifted from automated operations to manual control while engineers isolated affected equipment and restored normal service.
Officials said the response prevented more significant operational disruptions.
State authorities confirmed there was no evidence that drinking water quality had been compromised.
Residents were not advised to boil water, and public health officials said water remained safe throughout the incident.
The FBI later confirmed it had received reports of similar cyber incidents affecting water utilities in at least seven states.
Some of those attacks disrupted normal operations but did not result in confirmed contamination of public water supplies.
Cybersecurity specialists say the Minnesota incidents illustrate how attackers increasingly target operational technology rather than traditional office computer networks.
Operational technology, often called OT, controls the physical equipment that keeps water treatment facilities running.
Unlike standard IT systems, OT networks directly manage pumps, pressure systems, filtration equipment, and chemical treatment processes.
Although many facilities include safety mechanisms and manual overrides, unauthorized access can interrupt services and require operators to restore systems manually.
Federal Agencies Point to Iranian Linked Activity
Federal cybersecurity agencies have spent months warning utilities about increasing threats to America’s water infrastructure.
Earlier this month, the FBI, CISA, the Environmental Protection Agency, and the National Security Agency issued a joint advisory warning that Iranian affiliated cyber actors were actively targeting programmable logic controllers connected to critical infrastructure.
The advisory urged utilities to disconnect internet exposed industrial control devices, strengthen authentication, install software updates, and closely monitor remote access.
Following the Minnesota incidents, federal investigators said the attacks shared technical characteristics with previous campaigns associated with Iranian affiliated hacking groups.
Those similarities include attempts to gain unauthorized access to programmable logic controllers and industrial control systems used by water treatment facilities.
Cybersecurity officials caution that similar tactics do not automatically identify the attacker.
Threat actors frequently copy one another’s methods, making formal attribution a lengthy forensic process.
Investigators continue examining network logs, authentication records, compromised devices, and malware samples collected from affected utilities.
The FBI, CISA, Minnesota Information Technology Services, and other federal partners are working together to determine whether the attacks form part of a broader campaign targeting critical infrastructure across the United States.
Until that investigation concludes, officials continue emphasizing one point: while investigators have identified Iranian linked tactics, they have not formally attributed responsibility for the Minnesota cyberattack.
Governor Tim Walz Responds
Governor Tim Walz strongly disagreed with Trump’s assessment, arguing that the investigation should remain focused on the available evidence rather than political debate.
Responding to the president’s remarks, Walz said Trump “knows exactly who is responsible for this attack, and knows that other states were hit too,” according to Reuters.
Walz also criticized recent federal staffing changes affecting cybersecurity programs, saying cuts had weakened the nation’s ability to defend critical infrastructure against increasingly sophisticated cyber threats.
Minnesota officials praised state cybersecurity specialists, local utility operators, and federal agencies for identifying the intrusions quickly and preventing more serious disruptions.
The governor’s office said affected communities restored normal operations through coordinated emergency response plans and close cooperation with federal investigators.
Minnesota Information Technology Services continues working with the FBI, CISA, the Minnesota Fusion Center, and local utilities as the investigation remains active.
State officials have not publicly identified the attackers and continue to defer formal attribution to federal investigators.
How the Cyberattack Affected Minnesota Water Systems
The attacks primarily targeted operational technology rather than traditional business networks.
Operational technology, often called OT, controls the equipment responsible for producing and distributing drinking water. That includes pumps, valves, pressure systems, filtration equipment, and chemical treatment processes.
Investigators said unauthorized users gained access to industrial control environments used by multiple community water systems.
Several utilities temporarily switched to manual operation while technicians isolated affected devices, reset equipment, and verified that treatment systems continued functioning safely.
Officials said those manual procedures helped maintain water service while engineers completed forensic reviews.
Authorities repeatedly stressed that there is no evidence the attacks contaminated drinking water or created an immediate public health threat.
Instead, the incidents disrupted normal operations and required extensive technical response from utility operators and cybersecurity teams.
The FBI has also reported similar incidents affecting water utilities in at least seven states, suggesting investigators are examining whether the attacks form part of a broader campaign against U.S. critical infrastructure.
Why Water Infrastructure Remains a Growing Cyber Target
Cybersecurity experts have warned for years that water and wastewater facilities remain attractive targets because many rely on aging industrial control systems connected to modern networks.
Many small and medium-sized utilities operate with limited cybersecurity budgets and lean technical staff, making it difficult to modernize aging infrastructure.
A key concern involves programmable logic controllers, or PLCs.
PLCs automate essential functions such as regulating water pressure, controlling pumps, managing filtration equipment, and monitoring chemical treatment.
If attackers gain unauthorized access, they may alter operating settings, interrupt automated processes, or force utilities to switch to manual control.
Modern treatment facilities include multiple safety layers designed to prevent catastrophic failures, but even temporary operational disruptions can strain local resources and reduce public confidence.
Recent federal advisories encourage utilities to disconnect unnecessary internet-facing industrial devices, require multifactor authentication for remote access, monitor unusual network activity, and separate operational technology from standard information technology networks.
Cybersecurity specialists say those measures significantly reduce the likelihood of successful attacks against critical infrastructure.
What Investigators Are Looking At Next
Federal investigators continue collecting digital evidence from affected utilities to determine how the attackers entered the systems and whether the incidents share a common origin.
The FBI, CISA, the Department of Homeland Security, and Minnesota authorities are reviewing authentication records, network logs, industrial control devices, and forensic artifacts recovered during the investigation.
Officials are also examining whether vulnerabilities identified in Minnesota exist in similar water systems across the country.
That work may lead to additional federal guidance for utilities using comparable industrial control technologies.
One question remains central to the investigation: who carried out the attacks?
Federal officials have emphasized that investigators have identified tactics consistent with previous Iranian-linked cyber campaigns. However, they also continue to caution that technical similarities alone are not enough to establish responsibility.
Officials have not formally attributed responsibility.
Cyber attribution typically combines forensic evidence, intelligence reporting, infrastructure analysis, and other classified information before agencies publicly identify a responsible actor.
Until that process is complete, investigators say the Minnesota cyberattack should be viewed as an active national security investigation rather than a concluded case.
The incident has renewed attention on the cybersecurity of America’s water infrastructure, with federal agencies urging utilities nationwide to strengthen defenses, review remote access policies, and report suspicious activity immediately.
Read More: Xbox Outage Today Leaves Thousands Locked Out of Games as Microsoft Works to Restore Services

