City of Gresham Wastewater Treatment Plant in Oregon

Cyberattack Targets Water Utilities in Seven States as FBI Probes Possible Iran Link

Federal authorities are investigating a coordinated cyberattack that disrupted technology used by water utilities in at least seven states this week, with officials examining whether hackers linked to Iran were responsible for the incidents.

The FBI, the Cybersecurity and Infrastructure Security Agency (CISA) and the Environmental Protection Agency confirmed Thursday that malicious cyber activity targeted internet-connected industrial control systems used by water and wastewater facilities, forcing some utilities to temporarily switch to manual operations.

Investigators have not publicly attributed the attacks to a specific actor, but U.S. officials familiar with the investigation said authorities are exploring whether Iran-based hackers carried out the operation. Officials cautioned that attribution remains preliminary and noted investigators are also considering whether another group deliberately attempted to make the attack appear to originate from Iran.

Minnesota among hardest-hit states

The FBI said incidents occurred in at least seven states but did not identify them.

CBS News is reporting that more than 30 community water systems in Minnesota alone were affected.

According to Minnesota IT Services, most of the incidents involved programmable logic controllers (PLCs), devices commonly used to remotely monitor and control pumps, water towers and other utility infrastructure.

State officials emphasized that no drinking water supplies have been contaminated or compromised.

Mike Ernster, a spokesperson for the Minnesota Department of Public Safety, said the state’s Bureau of Criminal Apprehension and Minnesota Fusion Center are coordinating with local governments and federal agencies to investigate the incidents.

Authorities have identified similarities in the timing and technology involved but have not confirmed whether every incident was conducted by the same threat actor.

Utilities shift to manual operations

Several Minnesota communities reported successfully maintaining water service despite the cyber disruptions.

In South St. Paul, officials detected the intrusion early Monday and immediately activated contingency procedures, transitioning employees to manual operation of water and wastewater systems.

City officials said drinking water quality, pressure and delivery were never affected, and investigators found no evidence that resident or customer data had been accessed.

In Braham, city workers discovered Monday that the well supplying the municipal water tower had stopped functioning. Crews isolated the affected equipment, activated backup systems and restored operations within approximately 90 minutes.

Mayor Nate George said residents experienced no interruption in water service.

Plymouth officials reported communications outages Sunday evening affecting programmable controllers connected to two water towers and 14 sewer lift stations. Operators disconnected the affected devices from cellular networks and temporarily managed operations manually until communications were restored Tuesday.

“I think you never expect it to happen to you,” Plymouth Public Works Director Michael Thompson told CBS News Minnesota.

Federal agencies warn of growing threat

CISA said it is observing “a significant increase” in cyber threat actors targeting programmable logic controllers used by water utilities of all sizes.

The agency urged operators to immediately remove publicly exposed industrial control systems and other operational technology from the internet whenever possible.

“Even water organizations with mature cybersecurity processes should validate their external connections,” CISA said, warning that some vulnerable cellular modems installed by contractors or vendors may not appear in routine cybersecurity scans.

Federal officials reported that some attacks temporarily disrupted monitoring and control functions at critical infrastructure sites, leading to pressure loss and localized flooding in certain cases.

Similar tactics used in earlier attacks

Federal investigators noted the latest incidents resemble tactics previously employed by Iran-linked hackers.

In 2023, agencies confirmed that cyber actors affiliated with Iran’s Islamic Revolutionary Guard Corps targeted U.S. water and wastewater facilities by exploiting internet-connected industrial controllers that still used factory-default passwords.

Officials said the current investigation remains ongoing, and no final determination has been made regarding responsibility for this week’s attacks.

About J. Williams

Check Also

President Trump

Trump Announces Gaza Disarmament Deal as Hamas Agrees to Surrender Weapons

President Donald Trump announced Thursday that negotiators have reached an agreement aimed at ending the …

Leave a Reply