More than 30 Minnesota communities saw their water and wastewater utilities disrupted by a coordinated cyberattack on Sunday and Monday, the state’s technology bureau announced Tuesday. Among those was the City of Braham, a community of 1,700 people that brands itself the “Homemade Pie Capital of Minnesota.”
Braham officials on Monday morning announced on the city website that its water plant was “offline for an unknown reason” and asked its residents to minimize water use because the city water tower held only a “limited quantity.” A second notice later that day noted that the plant was back online, explaining that the outage had been the result of “a malicious cyber-attack of computerized operating systems by unknown actors.”
Response Efforts
A spokesperson from Plymouth, a Minneapolis suburb of about 80,000 people, explained in an email that the city’s IT division “disconnected the affected equipment from the network to stop the cyberattack and avoid any potential retargeting while the equipment is reconfigured.” In Plymouth’s case, the attack was limited to “equipment connected via cellular communications” at two city water towers and “multiple” lift stations.
Minnesota Information Technology Services, the state technology agency, said its response efforts have included “sharing threat intelligence, providing guidance on response efforts and best practices, and helping affected utilities contain, investigate, and remediate damages from the attack.” The agency said it’s working with numerous other agencies, including its own public safety and health departments, and a state fusion center, along with federal agencies such as the Cybersecurity and Infrastructure Security Agency, the Environmental Protection Agency, and FBI.
Possible Attribution
John Israel, Minnesota’s chief information security officer, is quoted in a press release as saying that the “whole-of-government response” worked as intended, helping “prevent more serious impacts to critical services.” The Minnesota state government and several local governments contacted for this story declined to comment on who attacked the state’s water utilities, though Iran is a reasonable guess.
CISA and a cohort of other federal agencies last week updated an advisory “urgently” warning the nation of ongoing attempts by Iranian hacking groups, such as CyberAv3ngers, to target internet-connected operational technology devices, including programmable logic controllers.
Expert Analysis
Joshua Corman, an executive in residence at the Institute for Security and Technology, a nonprofit think tank focused on issues of national security and global stability, said the warning “should give everyone nightmare fuel.” There were also the U.S. strikes this month along Iran’s southern coast, near the Strait of Hormuz, that destroyed a water facility and cut off water access to more than 20,000 people as temperatures rose above 100 degrees Fahrenheit.
TJ Sayers, senior director of threat intelligence at the nonprofit Center for Internet Security, affirmed that the Minnesota attacks have not yet been attributed to any particular party, and that “it is unclear” whether the attacks involved the programmable logic controllers CISA warned about.
Vulnerabilities in Water Utilities
U.S. water utilities are a highly distributed network of some 150,000 to 170,000 systems, many of them small, rural, and with few resources to defend themselves against cyberattacks or other disruptions. The EPA in 2024 warned that more than 70% of water systems were failing to comply with a provision of a 2018 law requiring them to develop or update risk assessments and emergency response plans, and to certify them with the environmental agency.
An audit of 1,000 water systems serving 193 million people found 97 systems with critical- or high-risk vulnerabilities. The national cyber drill, an annual event hosted by the EPA’s Office of Water Emergency Response and Cybersecurity, which is designed to boost emergency readiness, this month saw “a really tiny participation rate,” said Corman.
Source: CyberScoop