Key takeaways:
- More than 30 Minnesota community water systems were affected by malicious cyber activity involving technology used to monitor and control water equipment.
- Officials said no Minnesota water supply was reported compromised, and affected communities maintained service through manual operations or backups.
- U.S. investigators are examining whether Iranian-linked hackers were involved, but state and federal officials have not publicly attributed the attack.
More than 30 community water systems across Minnesota were hit by malicious cyber activity this week, forcing some utilities to shift to manual operations while state and federal investigators examine whether hackers linked to Iran were involved.
Minnesota IT Services described the incident as a “coordinated cyberattack” affecting technology at water facilities around the state. Most confirmed cases involved systems used to remotely monitor and control equipment, including programmable logic controllers, or PLCs, the agency said.
No Minnesota water supply has been reported compromised, Mike Ernster, a public information officer for the Minnesota Department of Public Safety, told CBS News. Officials said water service continued in affected communities, and there were no indications that drinking water was unsafe.
U.S. officials and people familiar with the incident told CBS News that investigators are looking into whether Iranian hackers were behind the activity. They cautioned that the attack has not been definitively attributed and that the assessment could change as more technical evidence is collected. Investigators also are examining whether the actor may have tried to appear Iran-based to inflame tensions amid the ongoing U.S. conflict with Iran, CBS News reported.
Minnesota and federal officials have not publicly blamed any specific actor.
“The timing, methods of access, and targeted infrastructure share characteristics with other coordinated cyber incidents our federal partners have observed involving critical infrastructure,” Emily Zimmer, a spokesperson for Minnesota IT Services, told Reuters, according to Al Jazeera.
Nick Anderson, acting director of the federal Cybersecurity and Infrastructure Security Administration, said the agency “is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLC) at water utilities.”
“We urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible,” Anderson said.
CISA issued a similar advisory Thursday, saying cyber threat actors are targeting “water entities of all sizes” in the Water and Wastewater Systems sector. The agency warned that even organizations with mature cybersecurity programs should verify external connections, including cellular modems installed by operators, vendors or integrators that may not be documented or included in routine scans.
Local officials reported limited operational disruptions. In South St. Paul, a city spokesperson told CBS News that officials identified an issue early Monday and immediately implemented contingency procedures. Public works employees switched to manual operations, allowing water and wastewater services to continue without interruption. The city said the incident was limited to technology supporting parts of its water utility and did not affect drinking water treatment, quality, pressure or delivery. Officials found no indication that resident or customer data was accessed.
In Braham, north of Minneapolis, public works employees discovered a problem Monday after noticing that the well supplying the city’s water tower was malfunctioning. Mayor Nate George told CBS News that workers isolated the affected system, restored a backup and restarted the plant in about 90 minutes. Residents did not lose water service, and the city has since ensured the system is not connected to public-facing internet networks, George said.
The FBI said it was aware of the incident and in contact with victims. In a social media post cited by Al Jazeera, the agency said it was “actively engaged with victims” and emphasized its “joint commitment to support critical infrastructure entities against malicious cyber actors attempting to harm the United States.”
Iran-linked hackers have previously targeted U.S. water utilities. Federal agencies have said actors affiliated with Iran’s Islamic Revolutionary Guard Corps accessed multiple water and wastewater facilities in 2023 by exploiting internet-connected controllers that still used default passwords.












Be First to Comment