Minnesota’s Water Systems Were Probed. Our Election Systems Are Next in the Window.

Minnesotans,

Last weekend, roughly 36 municipal water systems across our state were targeted in a coordinated cyber campaign. Automated controls at water towers, wells, and lift stations were hit through cellular and wireless links. Operators had to switch to manual operation. One plant in Braham was knocked offline for under two hours. Water stayed safe. Service continued. But the doors were tested.

This was not random. It came four days after federal agencies updated a formal warning that Iranian-linked actors were actively exploiting internet- and cellular-connected industrial controls in water systems and local government facilities.

U.S. investigators now assess Iranian-linked actors as the likely source. That assessment is preliminary. The pattern is not.

The Same Class of Exposure Exists in Election Equipment

Just days earlier, during required public accuracy testing in Rice County, the following was documented in real time:

• Only 3 of 35 DS200 precinct tabulators were tested

• A single DS450 central-count machine handled the entire county’s absentee and mail ballots

• Live wireless networks were active in the testing room (including Pollpad WiFi Secure–Mobile and multiple county networks)

• Machine interfaces displayed signal strength and a “Begin Modem Process” option

• Requests for serial numbers and current firmware versions were refused on site

Cellular and wireless connectivity is not theoretical. It is present. When the same type of links can reach water-tower telemetry across dozens of cities in a single weekend, the residual risk to the machines that will count our votes cannot be waved away as “overstated.”

Why This Matters Right Now

The August 11 primary recreates the exact conditions that expand the attack surface: equipment powered on, temporary network configurations activated, testing and results transmission under time pressure, and staff focused on process rather than adversarial monitoring.

Actors who successfully mapped and briefly disrupted cellular-linked municipal systems do not need permanent, undetected access on day one. They need residual pathways and the continued belief that “it can’t happen here.”

What You Can Demand

• Expanded public accuracy testing beyond the statutory minimum

• Full disclosure of modem, cellular, and wireless configurations on election equipment

• Serial numbers and current firmware versions made available

• Independent audits of third-party remote-access tools before the primary

• Transparent reporting when municipal operational technology is targeted

Paper ballots are a strength. Connectivity that is left unexamined is not.

This is not about fear. It is about refusing to accept residual remote-access risk as normal in the systems that deliver our water and count our votes.

Read it. Share it. Ask your local election officials the hard questions. Document what you see. The window is open until August 11.

The pattern is visible. The primary is twelve days away. Close the doors.

— Phillip C. Parrish

Operation Shadow Hunt

30 July 2026

###