Trump Blames Minnesota for the Iran-Linked Water Hack. The Flaw Has No Patch.

Open control cabinet of programmable logic controllers with lit status lights inside a small water treatment plant, a dark control screen and a paper log sheet on the desk, and a town water tower against a dusk sky outside

In Braham, Minnesota, a city of roughly 1,700 people, the cyberattack that hit the week of July 26 disabled the computerized controls at the municipal well and treatment plant, and what kept water in the taps was a filled tower and operators willing to run the system by hand.

President Donald Trump’s account of that, delivered Friday at a Cabinet meeting at Camp David, was that the state is “grossly incompetent” and that he doubts Iran was involved at all, a claim that falls apart the moment you look at the specific vulnerability the attackers used.

What Was Actually Broken

More than 30 Minnesota water and wastewater systems saw operational disruption across July 26 and 27, according to a Tenable breakdown of the incident, with Braham, Plymouth, South St. Paul and Maple Plain disclosing publicly. The Minnesota Department of Health found no effect on drinking water quality and issued no boil-water advisories anywhere in the state. That is the good news, and it is worth sitting with the reason for it: the failure mode was contained by physical redundancy and human operators, not by any digital defense.

The FBI said on July 30 that utilities in at least seven states had been hit, and CBS News reported that federal investigators were examining whether Iran or Iran-linked actors were responsible. By the following day, CNN was describing a sweeping campaign against US water systems that had officials on edge. Minnesota officials had already been briefed that Iranian actors were the likely source.

A Cryptographic Key That Cannot Be Changed

Here is the part almost nobody covering the political fight has bothered to explain. Most of the confirmed intrusions involved programmable logic controllers, the small industrial computers that open valves, run pumps and trip alarms. The specific weakness in play, CVE-2021-22681, is an authentication bypass in Rockwell Automation Logix controllers rated 9.8 on a 10-point severity scale. It exists because a cryptographic key used to verify communication between the engineering software and the controller is insufficiently protected.

Rockwell has said there is no software fix, and none is coming. The key is baked into the architecture. A vendor cannot patch it out without rebuilding how the product authenticates, so the guidance to customers is defense in depth instead: segment IT from OT networks, isolate engineering workstations, turn on CIP Security, and physically set the controller mode switch to Run.

Read that list again as a budget document. Every item is a project. Network segmentation in a plant built in 1974 means new hardware, a new architecture and someone qualified to design it. Braham has about 1,700 residents. Maple Plain has fewer than 2,000. These are cities whose entire public works staff can fit in one pickup truck, being told that the only remedy for a nine-point-eight vulnerability with no vendor patch is an infrastructure program they were never funded to run.

Calling that incompetence is like blaming a homeowner for a lock the manufacturer admits cannot be re-keyed.

The Warning Went Out Four Days Before

The federal government knew. CISA, the FBI, the NSA and the Department of Energy published an advisory on July 23 warning that Iranian state-backed hackers were targeting industrial control systems at American water and energy providers, naming Rockwell, Schneider Electric and Siemens equipment. The update to CISA advisory AA26-097A landed on July 22. The Minnesota attacks began on July 26.

The advisory also described what makes this campaign different from ordinary ransomware. The attackers were not encrypting files for money. They were reprogramming controllers to disable the processes that handle emergency shutdowns and alarms, so a system could drift into an unsafe state without ever telling an operator. That is not theft. That is an attempt to make the machine lie to the person watching it.

Groups tied to Iran’s Islamic Revolutionary Guard Corps have run this playbook against US water utilities before, most visibly in 2023, and the domestic threat picture has been sharpening all year, including an FBI warning to California in March about a possible Iranian drone attack launched from an offshore vessel. None of this was a surprise to anyone holding a clearance.

Why the Blame Landed on a Governor

So why point at Governor Tim Walz? Because the alternative sentence is politically expensive. If Iran did this, then the war the administration has been prosecuting since February has arrived inside the United States, at the level of small-town utility closets, and it has arrived in a form the federal government has publicly admitted it cannot patch.

Walz said as much in his response, that Trump knows who is responsible and knows other states were hit, and that this is what modern warfare looks like. The line landed because it points at the thing the blame-shift is designed to obscure: there is still no articulated theory of how this war ends, a gap the Senate has spent the past week failing to close as binding war powers votes went down again.

There is also a resourcing problem that a governor cannot solve. CISA, the agency whose advisory sits at the center of this story, has shed roughly a third of its workforce this year, down toward the 2,200 to 2,600 range from about 3,700 at the start of 2026, with a proposed FY2026 budget that would cut hundreds more positions and specifically thin the teams that coordinate support to infrastructure operators. The EPA’s ask for a competitive water cybersecurity grant program for all fifty states was $10 million. For scale, the Pentagon’s supplemental request for the Iran war has been measured in tens of billions.

You cannot spend a hundred dollars on the war and a dime on the counterpunch landing in Braham, and then call the town incompetent when it lands.

What Attribution Actually Requires

To be fair to the uncertainty, formal attribution is genuinely hard and genuinely slow. Security researcher Vassil Roussev told PolitiFact that cyberattack attribution is inherently uncertain, and as of the end of July no US agency had formally named a specific group for the Minnesota intrusions, though researchers have pointed at CyberAv3ngers, the IRGC-linked outfit the Treasury sanctioned in February 2024.

That caution cuts in exactly one direction, though, and it is not the direction the President took. “We do not know yet” is a defensible position. “I think Minnesota is behind it” is not the same sentence, and it was offered with no evidence at a moment when the FBI had already counted seven states.

The tell is the arithmetic. Whatever hit Braham also hit utilities outside Minnesota’s borders, and a governor’s alleged incompetence does not travel across state lines through a Rockwell controller.

The Next One Will Not Have a Water Tower

The thing worth watching is not the blame fight. It is the ratio in Braham: an unpatchable flaw on one side, a full water tower and a couple of operators on the other. That held, this time, in a town small enough for manual operation to be realistic.

Run the same intrusion against a system serving 400,000 people with no manual fallback, and the tower does not save you. The federal advisory describing exactly that scenario has been public since July 22. The question is whether the next several weeks produce funded segmentation projects at a few thousand small utilities, or another Cabinet meeting.