
Iranian hackers likely breached dozens of municipal water systems in Minnesota this week, according to U.S. and state officials cited by The New York Times, temporarily knocking at least one city’s well and treatment plant offline and forcing other municipalities into manual workarounds to fend off attempted intrusions into automated operations. No water was rendered unsafe to drink.
But the incident lands at a precarious moment — direct fighting between the U.S. and Iran has resumed in the Middle East — and it should focus attention on a warning this industry has heard for years and, arguably, hasn’t fully absorbed: mobile networks sit on the same target list as water and power, and the infrastructure securing them is just as unevenly hardened.
What happened in Minnesota
John Israel, the state’s chief information security officer, said hackers targeted roughly 36 municipal water systems as part of a breach first detected Sunday, going after infrastructure used to remotely manage and monitor water towers. Minnesota’s early detection let officials warn other municipalities with similar vulnerabilities before the intrusion spread further, though Israel said the same threat activity has likely been occurring in other states nationally.
Three state officials briefed on the investigation, speaking anonymously to The New York Times because it remains an active criminal matter, said the tradecraft used and the absence of a ransom demand pointed analysts toward Iranian involvement rather than a financially motivated criminal group — though officials cautioned that attribution isn’t final and warned the hackers could be attempting to impersonate Iranian actors to inflame tensions, a scenario former intelligence officials called unlikely. Cynthia Kaiser, a former senior FBI official who oversaw foreign-government cyberattack investigations, noted Tehran has demonstrated a recent, specific interest in targeting U.S. water systems, alongside a disruption-focused rather than profit-focused pattern in this attack.
This isn’t Iran’s first swing at the water sector. CISA, alongside the FBI, NSA, DOE, EPA, and U.S. Cyber Command, has been warning about it directly since at least November 2023, when the IRGC-affiliated group CyberAv3ngers exploited exposed programmable logic controllers at water utilities, and again in an April 7, 2026 advisory covering the same target set following the U.S. bombing of Iranian nuclear sites in June 2025. The pattern those advisories describe — poorly secured networks, unpatched software, internet-exposed operational technology, default passwords — is not unique to water utilities. It’s a description of thousands of small telecom operators, tower owners, and rural carriers too.
The mobile network warning has been sitting in plain sight
The U.S. doesn’t need to imagine what a nation-state actor targeting communications infrastructure looks like — it’s watched one unfold in real time. Salt Typhoon, the Chinese state-sponsored group, spent much of 2024 and 2025 burrowing into U.S. telecom networks, at one point exploiting unpatched Cisco IOS XE devices to compromise more than 1,000 network devices worldwide, over half of them in the U.S., South America, and India, according to researchers at Recorded Future’s Insikt Group.
AT&T and Verizon both eventually confirmed their systems were touched. Separately, backbone technology provider Ribbon Communications disclosed a nation-state intrusion last October with an attack profile pointing to China.
CISA’s own threat advisories name telecommunications explicitly, alongside energy, water, and transportation, as a priority sector for Iranian-linked targeting. And this industry’s own regulator has already said the quiet part out loud: FCC Commissioner Olivia Trusty warned in June that attacks on communications infrastructure — then framed around physical copper theft and vandalism — have crossed the line from regional nuisance into national security emergency, and flagged that AI tools are already being used to mine public FCC filings to identify infrastructure targets. That warning was about physical attacks. The cyber exposure sitting underneath the same networks is arguably less visible and no less real.
Why the network needs to be secured quickly, not eventually
The water sector and the mobile network sector share the exact vulnerability CISA keeps describing: highly fragmented systems, operated at enormous scale by thousands of separate local entities and small and mid-sized carriers, many running legacy hardware and remote-management tools never designed with this threat model in mind. A ransomware or disruption campaign doesn’t need to hit a Tier 1 carrier to matter — a regional carrier, a rural tower owner, or a subcontracted network operations center with exposed remote access credentials is exactly the kind of “target of opportunity” CISA’s advisories describe Iranian actors preferring.
That fragmentation isn’t only a cyber problem. Homeland Security, the U.S. Department of Labor’s Office of Immigration Policy, the Small Business Administration, the FCC, and members of congressional committees with oversight over telecom are all known to be looking into a related vulnerability from the physical side of the buildout. According to sources knowledgeable of the matter, these agencies are equally concerned about illegitimate Eastern Bloc 1099 crews operating across the industry, and are treating it as a potential threat to the integrity of the nation’s communications infrastructure buildout and security, rather than a routine labor dispute — particularly since FirstNet, the public safety network built to serve first responders, could easily be affected by rogue crews with no accountability, no vetting, and no traceable chain of responsibility.
Both threads point to the same conclusion: America’s communications infrastructure is being built and maintained by a patchwork of operators of wildly uneven security posture, oversight, and accountability, and the agencies now circling the problem are starting to treat it that way. Minnesota’s water systems got lucky this week: early detection, no contamination, no sustained outage. Whether that same margin exists the next time an adversary — Iranian, Chinese, or an unvetted crew with unsupervised access to a FirstNet site — turns a similar vulnerability toward America’s wireless backbone is the question these agencies, and this industry, need to answer before it happens rather than after.
