TL;DR · 30-second read
The Short Version
A coordinated cyberattack hit more than 30 local public water systems in Minnesota this week. Federal investigators are now involved.
The damage was small. One city’s well and treatment plant briefly shut down, and there are no signs the tap water became unsafe. Officials say early clues point to hackers linked to Iran, but that is not confirmed.
Why it matters beyond Minnesota: the giant computer buildings behind apps and artificial intelligence often cool their machines with water from these same local utilities. A hack at the water plant is a risk to them too.
A coordinated cyberattack affected more than 30 community water systems in Minnesota in the week of July 27, according to Minnesota IT Services, the state’s technology agency, Al Jazeera and Reuters reported on July 30. Local officials said the well and treatment plant in at least one city temporarily went offline, but the attack appears to have had minimal impact, and there are no indications the water supply became unsafe to drink. The FBI said on Wednesday that it was “actively engaged with victims.”
State officials said the incidents resemble activity attributed to hackers aligned with Iran’s government, and cautioned that the assessment is preliminary. The New York Times, citing unnamed state and federal officials, reported that Iranian hackers were the likely culprits, while noting that attribution is not definitive and that the attackers may have posed as Tehran-aligned actors. The attack comes amid renewed US–Iran hostilities after a June memorandum of understanding that paused the fighting broke down this month.
Executive Summary
More than 30 local water systems in a single US state were hit in what state officials called a “coordinated cyberattack.” The physical consequences were limited: one city’s well and treatment plant briefly went offline, and drinking water was not reported unsafe. But the breadth of the event and the FBI’s involvement put the security of utilities’ operational technology (OT) — the industrial control systems that run pumps, wells and treatment processes — back at the top of the critical-infrastructure agenda.
For the data center industry, the relevance is indirect but concrete. Many facilities that use evaporative cooling draw their water from municipal systems like these. The Minnesota incident is a reminder that a data center’s cooling supply depends not only on its own cybersecurity but on the cybersecurity of utilities it neither owns nor controls, and whose security resources are set by local public budgets rather than by the data center.
No data center has been reported as affected, and attribution of the attack remains preliminary. The episode’s value for operators is as a live test of a common assumption: that water outages are local, physical events rather than coordinated ones spanning many utilities at once.
The Cooling Risk Sits Outside the Fence
Data centers that use cooling towers or other evaporative systems reject heat by evaporating water, which has to be continuously replaced — industry shorthand calls this “makeup water.” Where a campus draws that water from a municipal utility, the utility’s wells, pumps and treatment plant become part of the data center’s cooling chain. Those assets are run by OT: programmable controllers and supervisory software that start pumps, open valves and dose chemicals. An intrusion that reaches them is, for every large water customer downstream, a cooling-supply risk.
Minnesota shows what that looks like in practice. More than 30 community water systems were affected in a single coordinated event, and in at least one city the well and treatment plant went temporarily offline — precisely the kind of interruption that stops water flowing to a large commercial customer. Water resilience planning has traditionally centered on familiar, local failures: a main break, a drought restriction, a fault at one plant. A coordinated intrusion is different in kind, because it can reach many independent systems at once, which may also affect neighboring utilities or backup supplies an operator expected to lean on.
The exposure is not uniform. AI training and inference hardware concentrates far more heat per rack than conventional servers, pushing operators toward liquid cooling and larger heat-rejection systems. Closed-loop liquid cooling and air-cooled chillers consume little water; evaporative designs trade lower electricity use for continuous water dependence. The operators most exposed to an event like Minnesota’s are water-reliant sites on a single municipal feed with limited on-site storage. Nothing reported so far indicates that any data center served by the affected systems saw an interruption, and the outage that did occur was brief.
Minimal Impact Is the Good News, Not the Whole Story
The most important outcome is that drinking water was not reported unsafe and service disruption appears to have been limited. That is a credit to the utilities and responders involved, and it should temper any alarm.
But officials’ own description points to a campaign rather than a one-off. Minnesota IT Services spokesperson Emily Zimmer said “the timing, methods of access, and targeted infrastructure share characteristics with other coordinated cyber incidents our federal partners have observed involving critical infrastructure.” Community water systems often run lean, with limited dedicated security staff, which makes a campaign that sweeps many of them at once hard to defend against one utility at a time.
The number that matters for infrastructure planners is therefore the 30-plus, not the single outage. Breadth indicates that access was obtainable across many separate operators simultaneously. A contained result this time says more about where the attackers stopped than about how far they could have gone.
Attribution Is Unsettled; the Threat Picture Is Not
State officials said the incidents resemble those attributed to Iran-aligned hackers but called that assessment preliminary. Officials cited by The New York Times said Iranian hackers were the likely culprits, while acknowledging the conclusion could change and that the attackers may have impersonated Tehran-aligned groups to raise tensions. Former intelligence officials told the paper a false-flag operation was less likely. The fair reading is that the available indications point one way but are not conclusive, and no technical evidence has yet been published that would let outside analysts test either view.
For defenders, final attribution matters less than the context. Water infrastructure has become a target across the current conflict: reported US strikes have hit Iranian water plants, and Iran has targeted desalination plants in neighboring Gulf states. Whoever is ultimately responsible for Minnesota, that backdrop raises the baseline risk to water-sector OT, and to every large customer that depends on it.
What Operators Can Ask Their Water Utility
Data center operators cannot secure a municipal utility’s control systems, but they can reduce how much a compromise of them would cost. Practical steps include confirming how and how quickly the utility will notify large customers of a cyber incident, knowing how many hours of cooling the site’s on-site water storage actually covers, qualifying alternative supplies such as reclaimed water or trucked delivery, and weighing low-water cooling designs for new builds.
The relationship can run both ways. Large water customers have a direct stake in their utility’s security posture, and utilities facing coordinated campaigns have an interest in knowing which customers carry the highest consequences from an outage. Minnesota makes that conversation easier to start.
Background
Water utilities are among the more exposed parts of US critical infrastructure: many are small, locally run and operate industrial control systems designed for reliability rather than security. US agencies have previously linked attacks on water-sector equipment to Iran: in late 2023, intrusions into industrial controllers at several US water utilities, including the Municipal Water Authority of Aliquippa in Pennsylvania, were attributed to a group affiliated with Iran’s Islamic Revolutionary Guard Corps.
Data centers become significant water users when they rely on evaporative cooling, which trades lower electricity use for continuous water consumption. As AI workloads raise heat density, cooling design, and the water supply behind it, has become a central siting and permitting question. The Minnesota incident arrives amid renewed US–Iran hostilities: the US joined Israel in a war against Iran on February 28, and a June memorandum of understanding that paused the fighting broke down in July. Source: US authorities probe cyberattack on water systems in Minnesota – Al Jazeera — Al Jazeera and Reuters on a coordinated cyberattack affecting more than 30 Minnesota community water systems and the federal response.Sources

