US Water Supply Cyberattacks Spread to 6 Additional States Beyond Minnesota
US water and wastewater sector faces cyberattacks expanding to six additional states beyond Minnesota, with suspected Iranian involvement and vulnerabilities in operational technology systems.
Initial Impact in Minnesota
A cyber campaign targeting operational technology (OT) systems at over 30 water and wastewater facilities in Minnesota between July 26 and 27 caused no disruption to water supply or wastewater management. One municipality temporarily shut down its water plant as a precaution, while others confirmed systems remained functional and safe.
Response from Affected States
Michigan acknowledged a “small number” of communities experiencing cyber intrusions, with critical systems operating without compromising public health. South Dakota’s City of Rapid City confirmed a cybersecurity incident involving a lift station within its wastewater system, though no threats to water supply were detected. Media outlets reported Georgia as an affected state, though the full list remains undisclosed.
Suspected Iranian Involvement
The U.S. government has not publicly attributed the attacks to any specific actor, but multiple sources suggest Iran’s involvement. Federal investigators are examining evidence linking the campaign to hacking groups associated with Iran, which has a history of targeting industrial control systems (ICS) and OT environments.
Technical Analysis and Vulnerabilities
Technical analysis revealed the breach targeted equipment connected via cellular networks, a vulnerability exploited in prior incidents. Industry experts highlight that OT devices using cellular communication channels represent a significant risk, as demonstrated by earlier attacks on Israeli water facilities. Infracritical, a cybersecurity research group, has compiled ongoing updates on the campaign, including mitigation strategies.
CISA and Industry Warnings
The Cybersecurity and Infrastructure Security Agency (CISA) has urged water sector organizations to reinforce protections for OT systems, particularly programmable logic controllers (PLCs). This follows a recent advisory warning of Iranian threats against ICS devices manufactured by Siemens, Schneider Electric, and Rockwell Automation.
Exposure of Vulnerable Systems
A separate analysis by security firm Censys found approximately 10,000 PLCs from these vendors exposed to the internet, though the exact number of vulnerable systems remains unclear. No public statements have been released by affected municipalities regarding the specific tactics used in the attacks.
Broader Implications for Critical Infrastructure
The incident underscores ongoing concerns about the security of OT environments and the need for continuous monitoring of industrial systems connected to external networks. The pattern of intrusion aligns with known methods employed by state-sponsored actors targeting critical infrastructure.
A report from WaterISAC, an organization focused on water sector information sharing, indicated that Minnesota’s Fusion Center identified patterns consistent with previous Iranian-linked cyber operations. The document, marked as TLP:Amber, was not intended for public distribution.
According to a separate analysis by security firm Censys, approximately 10,000 PLCs from Siemens, Schneider Electric, and Rockwell Automation were exposed to the internet, though the exact number of vulnerable systems remains unclear.
