MEFILES · Edition No. 17Today's edition · Archive · RSS
Seven files · One region · Zero illusions
Digital Front Monitor The full edition of July 31, 2026 →
Attribution Without a Name

Five American Outlets Put Iran Behind the Minnesota Water Hack, and No Official Signed It

The preliminary US assessment reported Thursday rests on anonymous officials, the absence of a ransom demand and a reading of tradecraft. Minnesota’s own IT agency has attributed nothing.

The intrusion into operational technology at Minnesota water and wastewater utilities ran overnight from 26 into 27 July. Minnesota IT Services puts the number of affected systems above 30; Valley News Live, citing the New York Times, puts it near 36. Four municipalities have disclosed publicly — Braham, which reported limited reserves and banned lawn watering, Maple Plain, which declared a state of emergency, Plymouth and South St. Paul, whose public works staff told CBS News they moved to manual operation with no effect on treatment, quality, pressure or delivery and no customer data accessed. On Thursday the New York Times, reported by Dustin Volz and Ernesto Londoño, said the preliminary US assessment holds Iranian hackers “probably” responsible. The Washington Post, NBC, CBS and ABC followed within hours. The FBI, EPA and CISA issued a fresh warning to wastewater operators the same day, with CISA saying actors are changing passwords on programmable logic controllers “to lock out operators.”

Every attribution word in print on Thursday came from an unnamed source. NBC’s version rests on a single senior law enforcement official; ABC’s on multiple US officials, all describing the assessment as preliminary and awaiting deeper forensic detail. The two reasons officials gave the Times for leaning Iranian were the tradecraft and the fact that nobody has demanded money. The Times carried its own caveat that hackers could be posing as Iran-based to inflate US–Iran tension, while noting former intelligence officials consider that unlikely. Tenable Research Special Operations pointed at CyberAv3ngers on Wednesday, but that is a vendor inference from operational pattern and timing, not an attribution. MNIT has made none. John Israel, the state’s chief information security officer, said Minnesota has handed material to Washington, “which is evaluating this activity in the broader national context.” Senator Amy Klobuchar requested a briefing Thursday.

Assessment: MNIT did the most useful thing in the file and almost nobody quoted it: the agency told ABC that “impacted” means confirmed malicious activity on a system’s technology, not that any community lost water. That definitional line is a state pre-empting the misreading of its own headline number, and it is the discipline the national coverage abandoned within a day. The event to wait for is a named FBI or ODNI statement; another anonymous briefing is not one. Two things cut against the current read: the forensics are not in, and CyberAv3ngers claim their work. Four days of silence after an operation this size is a data point. Watch instead for a second state — Israel says the activity has likely occurred elsewhere.