clear drinking glass with clear liquid
Photo by Engin Akyurt on Pexels.com
/

Cyberattack hits 30-plus Minnesota water systems as officials probe possible Iran link

A coordinated cyberattack disrupted operational technology at more than 30 community water systems across Minnesota on July 26 and 27, prompting a statewide response as state and federal investigators work to determine whether Iran-linked hackers were responsible.

2 mins read
Start

More than 30 community water systems across Minnesota were targeted in a coordinated cyberattack Sunday and Monday, according to Minnesota IT Services, the state agency confirmed Tuesday. The attack disrupted operational technology, the systems utilities use to remotely monitor and control physical equipment such as water towers, pumps and lift stations, though officials say no water supply was compromised.

The disruption has drawn national attention because it followed closely on the heels of a federal warning about Iranian hackers targeting critical infrastructure, and because it lands amid an active U.S.-Iran military conflict. Investigators have not publicly attributed the attack to any actor, and multiple officials cautioned that whoever carried it out could have deliberately mimicked Iranian tactics to inflame tensions between the two countries.

Four Minnesota cities have publicly acknowledged being affected: Plymouth, South St. Paul, Maple Plain and Braham. In Braham, unknown malware knocked out operating controls at the city’s water plant, leaving a water tower unable to be filled for more than an hour. The city temporarily asked residents to minimize water use while the issue was resolved.

In Plymouth, a Twin Cities suburb of about 79,000 people, remote communications between two water towers and multiple wastewater lift stations went offline starting late Sunday, Public Works Director Michael Thompson said. The city switched to manual operations while crews worked to restore the system. South St. Paul reported a similar disruption to automated controls but said staff were able to maintain normal water and wastewater operations throughout. In Maple Plain, Mayor Julie Maas-Kusske declared a local state of emergency to help coordinate resources and speed the city’s response.

“Cyberattacks against critical infrastructure require a coordinated, whole-of-government response,” John Israel, MNIT assistant commissioner and Minnesota’s chief information security officer, said. Israel said the agency is working alongside the Minnesota Department of Health, the Department of Public Safety, the FBI, the Environmental Protection Agency and the Cybersecurity and Infrastructure Security Agency (CISA) to contain the incident, investigate its source and help affected utilities recover.

The Minnesota Bureau of Criminal Apprehension declined to comment on the specifics of an active investigation but reiterated that no water supplies in the state have been compromised. As of Thursday, MNIT said, no Minnesota community had asked residents to change how they use tap water, and no ransom demand was detected in connection with the intrusion, a detail analysts say points toward disruption rather than financial motive.

The timing has fueled the suspicion of an Iran connection. CISA updated an advisory on July 22, four days before the Minnesota attacks began, warning that Iran-linked hackers were targeting programmable logic controllers, the internet-connected devices utilities use to manage water infrastructure remotely. Nick Anderson, CISA’s acting director, said the agency is “currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLC) at water utilities” and urged operators to remove exposed devices from the internet.

Multiple news organizations, citing U.S. officials and people familiar with the investigation, have reported that Iran is considered a likely or suspected source. The Washington Post reported that U.S. intelligence agencies have assessed Iran was likely behind the attack, while NBC News, citing a senior law enforcement official, reported the intrusion “bears the hallmarks” of Iran-backed hackers. CBS News reported that investigators are also examining the possibility that the actor tried to appear Iranian in order to stir tensions between Washington and Tehran. Neither Minnesota nor federal officials have made a public attribution.

Braham Mayor Nate George told KSTP that early conversations with state and federal investigators pointed toward a possible culprit. “We had our inclinations initially just in our initial conversations with the state and FBI officials,” George said.

Iran’s suspected interest in U.S. water infrastructure isn’t new. In 2016, the Justice Department charged a group of Iranian hackers in connection with a cyberattack on a small dam near New York City. Security researchers at Tenable have also pointed to CyberAv3ngers, an Iran-linked group that claimed a 2023 attack on a Pennsylvania water authority, as consistent with the pattern seen in Minnesota, though that assessment has not been confirmed by state or federal officials.

The investigation remains active, and MNIT said it will share additional information as it becomes available.

Daily Planet

Stories published by the Daily Planet are either guest pieces, press releases, articles from outside news sources and/or content that was sent to us.

Leave a Reply

Your email address will not be published.

Previous Story

Man dies in downtown Saint Paul shooting that also wounded second victim

0 £0.00