Cyber Attack Targets 30 Minnesota Water Systems, Suspected Link to Iran
Malicious cyber activity has been reported to have paralysed technology in more than 30 community water systems across Minnesota this week. The incident has forced several utilities to switch to manual operations while state and federal authorities investigate the perpetrators behind the attack.
Investigators are currently looking into whether the attack was the work of Iranian hackers. However, US officials and sources familiar with the incident have warned that attribution is not yet final and could change as additional technical evidence is gathered. There is also the possibility that the cyber actors intentionally mimicked the methods of Iranian hackers to incite tension amidst the ongoing US-Iran conflict.
The FBI, the Environmental Protection Agency (EPA), and the Cybersecurity and Infrastructure Security Agency (CISA) have issued warnings that attackers are targeting internet-connected industrial controllers known as Programmable Logic Controllers (PLC). These devices are widely used by water and wastewater utilities.
In several cases, federal authorities reported a loss of monitoring and control functions at critical infrastructure sites, leading to issues ranging from decreased water pressure to flooding. These problems have been reported not only in Minnesota but also across at least seven other states.
Mike Ernster, a public information official from the Minnesota Department of Public Safety, stated that there have been no reports of compromised water supplies so far. “Minnesota Fusion Centre is working with municipal governments as well as state and federal partners to address this issue,” he said.
Some regions in Minnesota have reported varying levels of disruption due to the attack. The Plymouth Public Works Director, Michael Thompson, acknowledged the urgency of the situation, stating, “You never expect this to happen to you,” while adding that water quality and delivery remained maintained during the incident.
CISA is urging owners and operators of critical infrastructure to immediately remove PLCs and other operational technology (OT) that are directly exposed to the internet. “We are observing a significant increase in cyber threat actors targeting PLCs in the water and wastewater sector,” said Nick Anderson, Acting Director of CISA. Authorities noted that hackers affiliated with the Iranian Islamic Revolutionary Guard Corps used similar methods in 2023, exploiting internet-connected controllers that were still using default passwords.