Key facts
- A coordinated cyberattack affected over 30 community water systems in Minnesota on July 26 and 27.
- Minnesota IT Services confirmed unauthorized access with malicious intent.
- The attacks bear similarities to previous incidents attributed to Iranian-linked hackers.
- The targeting involves internet-facing programmable logic controllers.
Minnesota IT Services announced that a "coordinated cyberattack" impacted more than 30 community water systems in the U.S. state on July 26 and July 27. The agency stated it was not aware of any immediate requests for residents to alter their drinking water usage.
The attacks bear similarities to previous cyber intrusions against U.S. water infrastructure, which officials have previously attributed to Iranian-affiliated hackers. Emily Zimmer, a spokesperson for Minnesota IT Services, noted that the timing, methods of access, and targeted infrastructure align with other coordinated cyber incidents observed by federal partners involving critical infrastructure.
While formal attribution is pending, Zimmer explained the use of the term "attack" due to the identification of unauthorized access with malicious intent. The FBI and the Cybersecurity and Infrastructure Security Agency (CISA) have not yet responded to requests for comment. Past advisories from CISA have warned of Iranian-linked hackers targeting internet-facing programmable logic controllers (PLCs) manufactured by companies including Rockwell Automation, Schneider Electric, and Siemens. Cybersecurity experts have expressed concern over the expansion of this targeting, which could enable physical impact scenarios.