Federal agencies such as the FBI, CISA, and the EPA are investigating a cyberattack allegedly linked to Iran-affiliated threat actors. This attack targeted community water systems in Minnesota and at least six other states. The incident highlights the national security implications when local utility systems face cyber threats.
Most people do not consider the computer systems behind running water. However, this routine service felt uncertain in Minnesota and other affected states after a coordinated cyberattack on July 26 and July 27. The attack targeted the operational technology of over 30 community water systems.
Impact on Minnesota Water Systems
Minnesota IT Services (MNIT) activated the state’s cybersecurity response with federal agency assistance. Affected systems included a water plant that temporarily went offline. Other communities reported issues with automated controls and communications equipment, necessitating manual operations and backup procedures. Fortunately, state officials reported no need for residents to reduce or change their water usage.
The FBI confirmed that water or wastewater utility companies in seven states experienced some operational degradation. This prompted questions about the preparedness of other local utilities if hackers gain access.
Suspected Iranian Involvement
Though officials have not confirmed the perpetrators, a report from The New York Times cited preliminary suspicions of Iranian hackers responsible for the attack. Despite the initial suspicion, President Donald Trump rejected the idea that Iran was involved. Investigators are gathering technical evidence, some suggesting the activity might have been masked as Iranian. CISA had previously warned of Iranian-affiliated hackers targeting internet-exposed systems.
Risks of Water System Cyberattacks
The attack on Minnesota’s water systems underscores vulnerabilities that can affect systems nationwide. There are approximately 170,000 drinking water and wastewater systems in the U.S., with many using internet technology for remote monitoring. Smaller communities often struggle with cybersecurity due to limited budgets and older technology. Foreign entities have targeted these weaknesses.
Potential Consequences of a Cyberattack
Cyberattacks do not inherently mean water contamination, although there’s the potential for more severe impacts. A successful attack could disrupt treatment processes or damage equipment. During manual operations, staff must use established procedures to maintain safety. Facilities need to practice these protocols in preparation for emergencies.
CISA’s Recommendations for Strengthening Security
CISA issued new guidance titled “CI Fortify: Advice for Isolating Vital Systems” to help protect infrastructure. The document advises separating vital technology from less secure networks, offering better protection. Utilities should reduce unnecessary internet exposure and implement strong security controls.
- Change default passwords and use separate login credentials for staff.
- Comply with federal risk assessment and emergency response plans.
Steps for Residents During a Cyberattack
- Follow official local instructions for updates on water use.
- Do not assume water contamination without official notice.
- Enable emergency alerts on your devices.
- Keep a small emergency water supply in case of service interruptions.
- Watch out for fake messages from scammers during the incident.
The recent attack in Minnesota serves as a warning for governors and mayors nationwide. Communities should be aware of their internet-connected water control systems’ vulnerabilities. Smaller towns especially need support to enhance their cybersecurity defenses.
