Key Takeaways
Malicious cyber activity hit technology at more than 30 community water systems in Minnesota, and reporting now puts the intrusions in at least seven states including Michigan.
CISA issued a July 30 advisory on rising attacks against programmable logic controllers at water utilities and urged operators to remove exposed equipment from the public internet.
US officials say Iran is the leading suspect but stress there is no definitive forensic proof yet, and no drinking water supply has been reported compromised.
Malicious cyber activity hit technology at more than 30 community water systems across Minnesota in late July, CBS News reported, and by the weekend the intrusions had been reported in at least seven states, including Michigan, according to UPI and the New York Times.
Most confirmed cases involved programmable logic controllers, the small computers utilities use to remotely monitor and control pumps, wells and treatment equipment. In South St. Paul, public works crews switched to manual operations and kept water and wastewater service running without interruption. In Braham, a small city north of Minneapolis, workers spotted a malfunctioning well, isolated the system and restored a backup in about 90 minutes. No drinking water supply has been reported compromised in any affected state.
The Cybersecurity and Infrastructure Security Administration issued an advisory on July 30 reporting "a significant increase in cyber threat actors" targeting these controllers at water entities of all sizes, and urged utilities to pull exposed operational technology off the public internet as soon as possible.
Attribution is the open question. US officials told CBS News that Iran is the most likely perpetrator, but they caution the assessment could change, and investigators are also checking whether the attacker deliberately tried to appear Iran based. Hackers affiliated with Iran's Islamic Revolutionary Guard Corps breached multiple US water facilities in 2023 through internet connected controllers that still used default passwords.
The pattern here is hard to ignore. Six months into the Iran war, the pressure keeps landing on civilian money and infrastructure, from the bitcoin ship insurance scheme the Treasury sanctioned in the Strait of Hormuz to the AI models that breached real companies during security testing. Water utilities are the newest front, and the first fix CISA is asking for costs almost nothing, unplug the controllers from the public internet.
People Also Ask
Are Iran linked hackers behind the US water system cyberattacks?
Investigators consider Iran the leading suspect but have not definitively attributed the attacks, and they are also examining whether the actor tried to look Iran based on purpose.
Is US drinking water safe after the cyberattacks?
Yes so far. No water supply has been reported compromised, and affected utilities kept service running by switching to manual operations.
What is a programmable logic controller in a water system?
It is a small industrial computer that remotely monitors and controls equipment like pumps, wells and treatment systems, and it is the technology these attacks targeted.
What does CISA say water utilities should do now?
Remove publicly exposed controllers and other operational technology from the internet immediately, and validate external connections including undocumented cellular modems.
