Menu

Minnesota Water Systems Hit by Cyberattack Linked to PLC Vulnerabilities

3 days ago 0

More than 30 community water systems across Minnesota faced a cyberattack affecting technology, prompting some utilities to shift to manual operations. Investigators, including state and federal authorities, are examining whether Iranian hackers are responsible, though no specific actor has been officially named. The assessment is ongoing as additional technical evidence is gathered. The possibility of misdirection by attackers posing as Iran-based is also under consideration.

Most affected cases involved technology that remotely monitors and controls water system equipment, particularly programmable logic controllers (PLCs). However, no compromise of Minnesota’s water supply has been reported. Mike Ernster, from the Minnesota Department of Public Safety, confirmed this and stated that the Minnesota Fusion Center is collaborating with municipalities and federal bodies to address the issue.

Nick Anderson, acting director of the Cybersecurity and Infrastructure Security Administration (CISA), highlighted a significant rise in cyber threats targeting PLCs at water facilities. CISA urges removing publicly exposed PLCs from the internet promptly. Minnesota investigators noted similarities in the incidents but haven’t confirmed a common perpetrator.

In South St. Paul, officials identified issues early and switched to manual operations, ensuring continued water services. The city reported that the cyberattack affected only technology related to parts of the water utility; essential services like water treatment and delivery remained unaffected. There was no indication of data breaches involving resident or customer information.

Braham, another affected area, detected problems when the city’s water tower well malfunctioned. The issue was resolved swiftly within 90 minutes, with no interruption to water services noted. The city ensured systems were disconnected from public internet networks and is coordinating with its technology provider for further action.

The FBI is aware of the incident and is in contact with affected entities, though specific details remain undisclosed. CISA reiterated the surge of threats targeting water utilities of various sizes, advising infrastructure owners and operators to scrutinize external connections, including undocumented cellular modems used by operators or integrators.

Iran-linked hackers have historically targeted U.S. water utilities. In 2023, actors associated with Iran’s Islamic Revolutionary Guard Corps used similar tactics, accessing facilities through internet-connected controllers with default passwords.

Leave a Reply

Leave a Reply

Your email address will not be published. Required fields are marked *