CISA urges water utilities to take exposed systems down after Minnesota hacks

Robert Alexander/Getty Images
A memo distributed to water industry members and obtained by Nextgov/FCW makes mention of Iran but does not directly present evidence attributing the latest Minnesota incident to the country.
Following coordinated cyberattacks on Minnesota water systems that officials suspect may be linked to Iran, the Cybersecurity and Infrastructure Security Agency on Thursday warned utilities nationwide to remove exposed industrial-control equipment from the internet, citing a surge in activity that has locked operators out, disrupted facilities and triggered boil-water notices.
The Minnesota hacks targeted technology used by more than 30 community water systems on Sunday and Monday, state officials said. Some utilities were forced to operate equipment manually, while an intrusion in Braham briefly knocked out controls for the city’s well and water treatment plant. Officials said they had found no evidence that drinking water quality was affected.
Some officials believe an Iran-aligned cyber group is the culprit behind the attacks, two people familiar with the matter said, though one noted that investigations remain ongoing. Both were granted anonymity because the situation is sensitive.
A recent memo distributed to water industry members and obtained by Nextgov/FCW makes mention of Iran and says several public water utilities reported suspicious cyber activity between July 26 and 27.
The notice, addressed to members of the Water Information-Sharing Analysis Center, cites findings from the Minnesota Fusion Center, which say the water attacks are “aligned” with characteristics of a cyber campaign described by CISA in April that involved Iran-linked hackers, though it does not present direct evidence attributing the latest Minnesota incident to Iran. CISA’s April advisory was notably updated last week on July 22.
The contents of the WaterISAC memo were first reported by Wired. Investigators’ suspicion of Iranian involvement was first reported by the New York Times.
Water and wastewater systems are designated as critical infrastructure under federal policy. Major sabotage could disrupt access to safe drinking water or, in severe cases, damage physical equipment and threaten public health. In the early months of the Israel-Hamas war, a pro-Iran group accessed and defaced interfaces embedded onto U.S. water systems in Aliquippa, Pennsylvania.
If tied to Tehran, the Minnesota attacks would represent the latest escalation in a cyber campaign that U.S. officials and security researchers anticipated from the earliest days of the war against Iran.
After U.S. and Israeli strikes began in late February, suspected Iran-linked actors have since disrupted medical technology giant Stryker, targeted FBI Director Kash Patel’s personal email and breached industrial-control equipment across several U.S. sectors.
U.S. officials expected that activity to continue even after a preliminary agreement with Tehran was reached last month because cyberattacks are widely accepted as standard procedure even in peacetime conditions.
“There is no ceasefire in cyber,” Israel’s top cyberdefense official told Nextgov/FCW in May.
CISA’s alert issued Thursday says unnamed hackers are increasingly targeting internet-connected programmable logic controllers, the devices used to automate pumps, valves and other water-system equipment. The agency urged utilities of all sizes to disconnect exposed equipment, replace default passwords and limit remote access to trusted devices.
One person who works in the water sector expressed frustration that providers continue to leave these devices and other operational technology exposed to the open web.
“If utilities are exposing programmable logic controllers to the public internet, and if the U.S. was a serious country, we’d shut down their operator and sell the utility operations to a competent entity,” said this person, who spoke on the condition of anonymity to be candid about their discontent. “It’s more proof of how unserious the U.S. is about public health in the water sector.”
Water infrastructure is particularly challenging to defend, in part because utilities often manage a patchwork of aging equipment and work with components maintained by multiple contractors over decades, said Aurigo Software CISO Manish Sharma.
“Cybersecurity has to account for that complexity. It must be treated as an infrastructure requirement throughout the asset lifecycle, from planning and design through construction, commissioning, operation, modernization and replacement,” he said.
The Minnesota attacks come as the five-month war with Iran has again escalated after a brief pause in U.S. airstrikes. American forces struck dozens of Iranian Revolutionary Guard targets Wednesday after Tehran fired missiles toward U.S. positions, while Iran launched additional attacks toward Jordan and Kuwait on Thursday. The Strait of Hormuz remains the central obstacle to a peace agreement, with traffic through the major oil and gas route near a standstill.




