News

Coordinated Cyberattack Targets Minnesota Water Supply Systems

A coordinated cyberattack targeted more than 30 community water supply systems in Minnesota on July 26 and 27, according to a statement from the state’s IT department.

Minnesota IT Services stated that there are no active requests from cities urging residents to change their drinking water consumption. This statement follows reports from local media indicating that four Minnesota cities issued alerts regarding cyberattacks on their networks.

The attacks resemble a series of cyber intrusions previously directed at the water supply infrastructure across the United States, which have been attributed to hackers affiliated with Iran. Such incidents have raised alarms about the vulnerability of local public services that provide water to millions.

Emily Zimmer, a spokesperson for the agency, told Reuters that while the investigation is ongoing, “the timing of the attacks, access methods, and targeted infrastructure share similarities with other coordinated cyber incidents observed by our federal partners involving critical infrastructure.”

Suspicion of Iranian Involvement in New Cyberattack

Zimmer indicated that the agency cannot discuss the official attribution of responsibility or specific details of the incidents at this time. She explained that the agency used the term “attack” to describe the situation because investigators identified unauthorized access with malicious intent aimed at these systems.

The FBI has acknowledged the incident and is in contact with affected parties “to resolve the situation.” The Cybersecurity and Infrastructure Security Agency (CISA) did not respond to Reuters’ request for comments.

While it remains unclear who is behind the attacks, Iranian-affiliated hackers have targeted U.S. water supply systems in the past, with varying degrees of success.

Concerns Over Vulnerabilities in U.S. Critical Infrastructure

A warning issued by CISA on April 7 indicated that Iranian-affiliated hackers were attacking internet-connected programmable logic controllers (PLCs)—devices used to manage machinery and other critical infrastructure networks—manufactured by Rockwell Automation.

On July 22, an update to the warning expanded the list of targeted devices to include equipment produced by Schneider Electric, Siemens, and possibly other manufacturers.

Joe Slowik, a director of threat research and cybersecurity engineering at Dataminr, warned in a blog post on July 27 that “CISA’s updated reporting indicates a concerning expansion of targeting critical infrastructure in the United States by Iranian-affiliated actors.”

Slowik emphasized that while the initial warning was already alarming, “the expansion of these activities to include additional lines of equipment and their association with process manipulation and safety mechanism degradation makes the situation even more concerning, as it creates the potential for various scenarios with physical impact.”

Ashley Davis

I’m Ashley Davis as an editor, I’m committed to upholding the highest standards of integrity and accuracy in every piece we publish. My work is driven by curiosity, a passion for truth, and a belief that journalism plays a crucial role in shaping public discourse. I strive to tell stories that not only inform but also inspire action and conversation.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button