Key facts
- The U.S. government's civilian cyber defense agency warned of a significant increase in hackers targeting water and wastewater systems.
- Operators of these systems are advised to remove them from the internet as soon as possible.
- Over 30 community water systems in Minnesota were targeted in a coordinated cyberattack.
- Water and wastewater utility companies in at least seven states have reported incidents to the FBI.
- Iranian-linked hackers are suspected to be behind the recent attacks.
- Some attacks have resulted in "boil water notices" and "sustained manual operations."
The U.S. government's civilian cyber defense agency issued a warning on Thursday about a significant increase in cyberattacks targeting technology used in water and wastewater systems. The Cybersecurity and Infrastructure Security Agency (CISA) advised operators to disconnect these systems from the internet as quickly as possible.
This alert follows a report from Minnesota's state IT agency that over 30 community water systems in the state were targeted in a coordinated cyberattack on July 26 and 27. The FBI confirmed that water and wastewater utility companies in at least seven states have reported incidents, with some attacks degrading operations.
U.S. officials and investigators are likely attributing the Minnesota attacks to Iranian-linked hackers, according to The New York Times. This activity occurs amid heightened tensions and exchanges of attacks between the U.S. and Iran. While Iranian-linked hacking targeting U.S. water facilities predates the current conflict, various groups have conducted notable cyberattacks on U.S. organizations.
State and local officials have stated that the Minnesota attacks did not compromise water safety but did necessitate manual resets for some systems taken offline. CISA's alert detailed that hackers have, in some instances, altered passwords to lock out operators and disconnect devices, leading to "boil water notices and sustained manual operations." The FBI has received reports of "operational effects" including loss of pressure and flooding.
Minnesota's chief information security officer, John Israel, confirmed that the state has shared information with the federal government for broader evaluation. Cynthia Kaiser, a former FBI cybersecurity official, noted that the recent campaigns are likely a continuation of prior Iranian-affiliated targeting of critical infrastructure technology, as highlighted in previous federal advisories. Chris Day, a cybersecurity executive, described the temporary system outages as an "interesting escalation" compared to prior events.
