More Than 30 Minnesota Water Systems Hit by Cyberattacks

More than 30 Minnesota water systems were targeted by cyberattacks Sunday and Monday; state and federal agencies are investigating amid warnings of Iranian-linked activity.

State and federal investigators are probing cyberattacks that targeted more than 30 water systems in Minnesota on Sunday and Monday, officials said. The incidents affected technology used to remotely monitor and control equipment and have not been publicly linked to a single culprit. Authorities reported no widespread water-quality problems.

Minnesota IT Services said investigators found similarities in the timing of the intrusions and the types of systems affected, but have not concluded whether the same actor carried out each incident. The FBI is leading a federal investigation and declined to identify a suspect. The Cybersecurity and Infrastructure Security Agency and other federal partners issued an advisory last week noting that Iranian-linked actors have focused on operational technology that runs critical infrastructure, including water and wastewater systems.

Some communities reported short disruptions. In Braham, a town of about 1,700 north of Minneapolis, operators lost control of the well and treatment plant and relied briefly on water stored in the town tower while staff worked to restore controls; officials asked residents to limit water use for a few hours and reported no water-quality issues. In Plymouth, a suburb of roughly 80,000, officials said system communications were restored by Tuesday afternoon and crews continued operating the network without any reported impact on water levels or quality.

State officials said an “impacted” designation reflects confirmed malicious activity involving a system’s technology and does not necessarily mean customers experienced service loss or safety issues. By Thursday, Minnesota IT Services said no communities had active requests for residents to change drinking-water usage.

Cynthia Kaiser, the former deputy assistant director of the FBI’s cyber division who now leads ransomware research at Halcyon, said: “I think most credible researchers and responders would be right to treat it like it’s Iran until proven otherwise.” The Justice Department previously charged Iranian hackers in connection with a 2016 cyberattack that targeted control systems at a small dam near New York City.

Federal agencies are working with state and local partners to share threat intelligence, investigate how access was gained and whether the same vulnerabilities were exploited across systems, and help restore affected networks. Officials did not provide a full list of communities affected beyond saying the number exceeded 30 as investigators continue their work.

Articles by this author