Reading: Iran And The United States probe cyberactivity at Minnesota water systems

Iran And The United States probe cyberactivity at Minnesota water systems

Published
3 min read
Advertisement

Malicious cyber activity disrupted technology at more than 30 community water systems across Minnesota this week, pushing some utilities into manual operations while investigators try to figure out who was behind it. U.S. officials are looking at whether the activity was the work of Iranian hackers, but Minnesota and the federal government have not publicly blamed any actor.

The concern is showing up now because the issue is not confined to one city or one utility. Federal authorities warned Thursday that attackers are targeting internet-exposed industrial controllers used by water and wastewater systems, and they said similar incidents have been reported in at least seven states. In Minnesota, most confirmed cases involved technology used to remotely monitor and control water system equipment, including programmable logic controllers.

Mike Ernster said none of Minnesota's water supply has been reported compromised, even as the Bureau of Criminal Apprehension's Minnesota Fusion Center works with municipalities and state and federal partners. That distinction matters: the cyber activity hit the technology that helps utilities run their systems, but officials have not said it reached the water itself. The FBI, Environmental Protection Agency and Cybersecurity and Infrastructure Security Agency also said some incidents have caused a loss of monitoring and control functionality at critical infrastructure sites.

- Advertisement -

State officials said investigators found similarities in the timing of the recent incidents and in the types of technology affected, but Minnesota had not yet confirmed that every case was carried out by the same actor. That leaves open the question that has sharpened the response in both Minnesota and Washington: whether this was one coordinated campaign, or several incidents that only looked alike because they struck the same vulnerable equipment.

Specific problems were reported in South St. Paul and Braham. A South St. Paul spokesperson said the city identified an issue early Monday and immediately put contingency procedures in place, with public works employees shifting to manual operations while water and wastewater service continued without interruption. Officials there said the incident was limited to technology supporting portions of its water utility and that drinking water treatment, quality, pressure and delivery were not affected. They also found no sign that resident or customer data was accessed. In Braham, public works personnel discovered a malfunctioning well supplying the city's water tower on Monday and isolated the affected system.

Nick Anderson said the Cybersecurity and Infrastructure Security Administration is seeing a sharp increase in cyber threat actors targeting programmable logic controllers at water utilities, and urged owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible. For Minnesota utilities, the immediate threat appears to be disruption rather than contamination, but the unanswered attribution question means the next phase of the investigation is likely to focus less on what broke and more on who was probing the systems in the first place.

Advertisement
Share This Article