**
Federal and state authorities in the United States are currently probing a series of cyberattacks on water and wastewater facilities across at least seven states, with early reports suggesting a potential connection to Iranian cyber actors. The Federal Bureau of Investigation (FBI) disclosed on Thursday that these incursions have disrupted water operations, prompting some communities to issue boil water advisories and revert to manual procedures. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recommended that water facilities sever any vulnerable internet connections, particularly those linked to programmable logic controllers (PLCs), to mitigate the risk of further assaults.
Nature of the Cyber Threats
The recent cyberattacks come closely on the heels of a warning from CISA that Iranian-affiliated cyber actors were exploiting PLCs within critical U.S. infrastructure sectors, including water systems. This advisory was part of a broader warning issued after hostilities escalated between the U.S., Israel, and Iran, beginning in late February.
While officials have not yet publicly confirmed a specific group as the perpetrator of the recent attacks, they have noted a concerning trend in the targeting of water facilities. CISA stated, “These threat actors are targeting water entities of all sizes,” emphasising the need for even those with robust cybersecurity measures to assess their external connections.
Understanding Programmable Logic Controllers
PLCs are essential components in modern industrial operations, enabling remote monitoring and control of systems across various sectors, including water management. These devices allow for the efficient management of infrastructure such as dams, pumping stations, and treatment facilities from a centralised location, which is particularly advantageous for urban areas.
However, the integration of internet-connected assets increases vulnerability. A report from the Canadian Centre for Cyber Security highlighted that “the more internet-connected assets an organization has, the larger the threat surface” for cybercriminals. CISA’s advisories indicate that Iranian-linked actors have been utilising third-party programming software to gain unauthorised access to PLCs, allowing them to manipulate operational parameters and create unsafe conditions without alerting system operators.
Timeline of Recent Attacks
The cyberattacks reportedly began in Minnesota on Sunday and Monday, prompting a statement from the state’s IT services department (MNIT) on Tuesday. By Thursday, it was revealed that over 30 community water systems in Minnesota had been compromised, although no immediate alterations to drinking water use were requested from the affected communities.
Investigators clarified that “impacted” does not equate to a complete disruption of water services, but rather indicates confirmed malicious activity involving specific technologies. Reports from Wisconsin also indicated malicious cyber activity detected at state water facilities on Monday, although the FBI has not disclosed the names of all seven states experiencing these attacks.
The nature of these attacks involved altering IP addresses and passwords for PLCs, leading to a loss of monitoring and control capabilities. The FBI’s advisory noted operational implications, including loss of pressure and flooding, with the potential for untreated groundwater to infiltrate pipes, creating serious health risks.
Accountability and Responses
In light of the ongoing investigation, there has been speculation regarding Iranian involvement. Various media outlets, including the New York Times and CNN, have reported that intelligence sources believe Iranian actors may be behind the attacks. A leaked memo from the Water Information Sharing and Analysis Center (WaterISAC) suggested that the Minnesota attacks exhibited characteristics associated with Iranian-affiliated hackers.
Despite these claims, U.S. President Trump dismissed the notion of Iranian involvement during a cabinet meeting, instead attributing blame to Minnesota’s government. “You know who’s behind it? Minnesota, because they’re grossly incompetent,” Trump stated, further alleging that the state’s leadership had failed to adequately respond to the situation.
Minnesota Governor Tim Walz countered these assertions on social media, affirming that Trump is aware of the true nature of the attacks and highlighting the broader implications of such cyber threats. He remarked, “This is what modern warfare looks like,” underscoring concerns about the lack of a cohesive national strategy to counteract cyber warfare.
Preventative Measures and Recommendations
In response to these alarming incidents, both the FBI and CISA are urging organisations that utilise PLCs to take immediate action. Recommendations include disconnecting PLCs from public-facing internet connections and ensuring that remote modems are securely configured. Strengthening passwords and implementing additional access controls, such as firewalls, are also advised.
Furthermore, facilities are encouraged to maintain and regularly practice manual override procedures to ensure operational continuity in the event of a cyber incident. The Canadian Cyber Centre has outlined further mitigation strategies to enhance the security of PLC systems, urging organisations to remain vigilant against evolving cyber threats.
Why it Matters
The significance of these cyberattacks extends beyond immediate operational disruptions; they underscore the vulnerabilities inherent in critical infrastructure systems. As cyber threats continue to evolve, the need for robust cybersecurity measures in essential services like water management becomes paramount. This situation highlights the interconnectedness of global security and the necessity for coordinated responses to safeguard public health and safety in an increasingly digital world. With the potential for severe consequences stemming from cyber vulnerabilities, the imperative for proactive measures has never been more urgent.