Trump publicly parts with US intelligence on Minnesota cyber attribution, blames Walz and state 'incompetence'
The US president publicly rejected the preliminary intelligence-community assessment that Iran was behind coordinated cyberattacks on more than 30 Minnesota water systems, instead blaming governor Tim Walz and the state's 'gross incompetence.'

On 31 July 2026, at 20:22 UTC, Polymarket's account on X relayed a fresh headline from the US presidency: Donald Trump was rejecting the preliminary intelligence assessment that Iran was behind coordinated cyberattacks on more than 30 Minnesota water systems, and was instead blaming Tim Walz and the state's "gross incompetence." Reuters confirmed the posture independently at 23:40 UTC, reporting that Trump had said Iran was not to blame for the Minnesota cyberattack. The gap between the president's public position and his own agencies' assessment is now the story.
Monexus analysis: this is a public, on-the-record rejection of a formal intelligence-community attribution by the same official who, in the same news cycle, was also publicly describing himself as "losing faith" in Iran. The split is not stylistic. It changes what the rest of the US government has to say out loud about an active cyber incident.
What the intelligence community actually said
The attribution itself is the cleanest part of the record. According to Polymarket's reporting at 15:21 UTC on 31 July, US intelligence agencies had assessed that Iran was likely behind coordinated cyberattacks targeting more than 30 Minnesota water systems. The phrasing in the public summary is "likely" rather than confirmed, and the underlying assessment is described as preliminary, which is the standard caveat intelligence agencies use when they want to telegraph that evidence exists without yet publishing the indicators of compromise. The targets named in that Polymarket item are Minnesota water utilities; the available source items do not specify whether the same campaign extended to other states or sectors, and this article has not independently established that question.
The scale, more than 30 systems, attacked in a coordinated wave, is large enough to be qualitatively different from a probing campaign. It implies either a deliberate signalling operation, or an opportunistic one that got out of hand, or both. The available source items do not specify the operational impact: whether treatment was disrupted, whether billing or SCADA systems were merely probed, whether any facility was taken offline.
The president's counter-attribution
Trump's own framing, as carried by Reuters and Polymarket, does not engage with the Iranian attribution on the merits. He offers, in its place, an explanation rooted in domestic politics: Tim Walz, the governor of Minnesota, and what the president characterised as the state's "gross incompetence." Polymarket's 20:22 UTC item is the cleanest summary on the record. Reuters, writing at 23:40 UTC, frames the president's posture as a flat exoneration of Iran. The available source items do not specify whether Trump characterised the underlying intelligence assessment as politically motivated, and this article does not establish that he did.
This is a notable move on at least three counts. First, it contradicts a formal intelligence-community assessment publicly. Second, it does so in a way that hands the governor of a US state the role of preferred culprit. Third, it lands on the same day that the president, according to Polymarket's 19:46 UTC item, was publicly describing himself as "losing faith" in Iran, a posture that, on its face, would normally harden, not soften, attribution for hostile action. Whether the two statements are in tension is a matter of interpretation; the wire evidence records both, and the reader can decide how to read them.
The parallel thread: military pressure on Tehran
The cyber story does not sit alone. According to an item carried by the Telegram channel OSINT Live at 22:17 UTC on 31 July, citing a Wall Street Journal tweet relayed via Disclose.tv, Trump had ordered a new attack on Iran. The available source items do not specify the target, the instrument, or the authority under which the strike was ordered; the claim arrives through a relay (Telegram carrying a WSJ tweet via Disclose.tv) and the primary WSJ story itself is not in the record. Read with that caveat, the juxtaposition is hard to miss: the same afternoon, the president publicly exonerates Iran of a cyber operation against US critical infrastructure while reportedly authorising kinetic action against the same country.
Monexus assessment: the most natural reading is that the public posture on Minnesota is shaped by domestic political incentives rather than by the underlying intelligence, while the classified posture toward Tehran has continued to harden. Those two tracks can coexist inside one administration. They cannot coexist inside one press conference, which is why this afternoon's split is the part that will travel.
Stakes, and what to watch next
The stakes are concrete on three clocks. In the short term, Minnesota's water utilities, and the federal responders now coordinating with them, need an authoritative attribution to scope remediation. If the White House position sticks, federal help gets reframed as disaster relief for an incompetent state rather than a response to a foreign intrusion, which changes the funding politics and the tempo of disclosure. Over a slightly longer horizon, US adversaries are now reading an open signal that the American president can publicly disclaim an intelligence-community attribution when it is domestically inconvenient; that is a foreign-policy cost the cyber defenders did not choose. Over the longest horizon, the credibility of the formal US attribution process itself is what gets eroded, because the gap between a classified PDB line and a presidential tweet is now visible to every operator watching.
Two things to watch in the next 48 to 72 hours. First, whether CISA, the FBI, or the Director of National Intelligence publish a public statement that narrows, restates, or doubles down on the Iran-likely framing; the available source items do not specify whether any such statement has been issued. Second, whether the WSJ story behind the Disclose.tv relay surfaces with operational detail on the new attack order, which would let a reader judge whether the kinetic track and the rhetorical track are pointed at the same target or at different ones. A counter-reading worth holding in mind: the public exoneration could be a negotiating posture, a domestic-political move, or a genuine reassessment of the underlying forensics. The wire evidence on the record does not let us choose between them.
Desk note: Monexus led on the contradiction between the public attribution and the public exoneration, carried the Wall Street Journal strike-order claim with explicit relay caveats, declined to characterise the cyber campaign's geographic scope beyond what the cited items specify, and declined to paraphrase Trump's language as 'politically motivated' because the source items do not contain that characterisation.
Wire provenance
This editorial synthesis draws on the following public wire/social posts:
- https://x.com/Reuters/status/2083336939529236501
- https://x.com/Polymarket/status/2083287080369570132
- https://x.com/Polymarket/status/2083278170107625657
- https://x.com/Polymarket/status/2083211571803615578
- https://t.me/osintlive/560966