U.S. Investigates Potential Iranian Involvement in Cyberattack on Minnesota Water Systems
Translated from English, summarized and contextualized by DistantNews.
At a glance
- U.S. authorities are investigating a cyberattack that disrupted over 30 water systems in Minnesota.
- Investigators are examining whether Iranian hackers were behind the attack, though attribution is not yet definitive.
- The attack targeted technology used for remote monitoring and control, but no water supply has been reported compromised.
Federal and state authorities are investigating a significant cyberattack that impacted technology at more than 30 community water systems across Minnesota this week. The malicious activity forced some utilities to switch to manual operations as investigators work to identify the perpetrators.
U.S. officials and sources familiar with the incident revealed that investigators are probing the possibility of Iranian hackers being responsible. However, these sources cautioned that the assessment could change as more technical evidence is gathered. There is also an ongoing investigation into whether the actor might have attempted to impersonate an Iran-based entity to exacerbate existing tensions amid the U.S. conflict with Iran.
is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLC) at water utilities.
Minnesota IT Services reported that the confirmed cases primarily involved technology used for remotely monitoring and controlling water system equipment, specifically devices known as programmable logic controllers (PLCs). Despite the disruption to control systems, officials have confirmed that no Minnesota water supply has been compromised. Mike Ernster, a public information officer for the Minnesota Department of Public Safety, stated that the Minnesota Fusion Center is collaborating with local municipalities and state and federal partners to address the issue.
Nick Anderson, acting director of the federal Cybersecurity and Infrastructure Security Administration (CISA), confirmed an "increase in cyber threat actors targeting programmable logic controllers (PLC) at water utilities." CISA has urged critical infrastructure operators to remove internet-exposed PLCs and operational technology from the internet promptly. While investigators noted similarities in the timing and technology affected across incidents, they have not yet definitively confirmed a single actor behind all of them. In affected areas like South St. Paul and Braham, public works employees successfully transitioned to manual operations, ensuring uninterrupted water and wastewater services without impacting water quality or delivery.
We urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible.
Originally published by CBS News in English. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.