Water systems hacked in 7 US states. Is Iran to blame? – Firstpost | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


A wave of coordinated cyberattacks targeting water infrastructure across the United States has agencies looking at Iranian-linked hacking groups.

While investigators have not formally identified those responsible, US federal and state authorities are examining whether the attacks
bear similarities to previous cyber campaigns attributed to Iran-affiliated actors.

The cyber intrusions, which affected dozens of community water systems and wastewater facilities across multiple states, forced several utilities to shift to manual operations as investigators worked to contain the incidents.

STORY CONTINUES BELOW THIS AD

Although the attacks disrupted automated systems, officials have said there has been no evidence of drinking water contamination or interruptions to public water supplies.

Coordinated attacks hit water systems across multiple states

The first signs of the cyber campaign emerged in Minnesota, where more than 30 community water systems were targeted over July 26 and July 27.

According to Minnesota IT Services, investigators identified “unauthorized access with malicious intent” directed at water infrastructure, prompting officials to classify the incidents as coordinated cyberattacks.

Emily Zimmer, spokesperson for Minnesota IT Services, said the investigation remains ongoing.

“The timing, methods of access, and targeted infrastructure share characteristics with other coordinated cyber incidents our federal partners have observed involving critical infrastructure.”

However, she stressed that authorities were not yet prepared to formally attribute responsibility or disclose further technical details. The attacks soon appeared to extend beyond Minnesota.

According to US officials and sources familiar with the investigation, malicious cyber activity has now affected water or wastewater facilities in at least seven states, with roughly six states reporting related incidents within a week.

The Federal Bureau of Investigation (FBI) confirmed it was aware of the attacks and said it was working directly with affected organisations “to resolve the matter.”

The US Cybersecurity and Infrastructure Security Agency (CISA), the Environmental Protection Agency (EPA), state authorities and federal investigators have been coordinating efforts to secure vulnerable facilities and ensure that public drinking water remains safe.

STORY CONTINUES BELOW THIS AD

Minnesota officials have also stated that they are “not aware of any active requests from Minnesota cities to have residents modify their drinking water usage,” indicating that no known risk to drinking water has been identified.

How the hackers targeted America’s water infrastructure

Investigators believe the attackers focused on internet-connected programmable logic controllers (PLCs) — industrial devices that control and monitor critical operations at water treatment plants, pumping stations and wastewater facilities.

PLCs regulate essential functions such as water pressure, chemical dosing, pumps and other operational processes. If manipulated successfully, they could potentially cause system failures or create conditions that increase contamination risks.

According to an internal Minnesota Bureau of Criminal Apprehension memo, the hackers’ “likely desired impact” was “to cause loss of system pressure and subsequent potential contamination of water supply.”

Officials say the attacks themselves were not highly sophisticated. Instead, attackers exploited PLCs that were directly connected to the internet and inadequately secured.

John Israel, Minnesota’s chief information security officer, warned that the attackers were likely scanning infrastructure nationwide for vulnerable systems.

“I suspect that those attackers are going to … continue to look nationally across the infrastructure,” Israel told CNN.

STORY CONTINUES BELOW THIS AD

The hackers will “continue to rattle those doorknobs and try to break into systems that have weak configurations,” he added.

Several communities were able to minimise disruption by switching quickly to manual operations.

In South St. Paul, public works staff transitioned immediately to manual controls, allowing water and sewer services to continue without interruption while officials confirmed that no customer data had been compromised.

In Braham, workers detected a malfunctioning well pump early on Monday and restored a backup system within 90 minutes, preventing service disruption.

Meanwhile, Plymouth discovered compromised controllers at two water towers and 14 sewer lift stations before restoring automated operations after manual management.

Is Iran responsible? What investigators know so far

Although investigators are examining possible Iranian involvement, no US agency has formally blamed Iran for the attacks.

Federal officials are treating Iran as one of several possible suspects because the methods used resemble
previous campaigns attributed to Iranian-linked hacking groups.

However, investigators have cautioned that cybercriminals can deliberately imitate another country’s tactics to mislead investigators and create political confusion, particularly during periods of heightened geopolitical tensions.

Zimmer said authorities cannot yet discuss formal attribution.

STORY CONTINUES BELOW THIS AD

At the same time, cybersecurity researchers note that the campaign shares characteristics with previous attacks on US critical infrastructure.

Earlier this year, CISA issued an advisory warning that Iranian-affiliated hackers were targeting internet-facing programmable logic controllers manufactured by Rockwell Automation.

A subsequent update expanded the warning to include devices produced by Schneider Electric, Siemens and potentially other manufacturers.

Joe Slowik, director of threat research and cyber engineering at cybersecurity firm Dataminr, warned that the latest intelligence reflects a broader targeting campaign.

“CISA’s updated reporting shows a worrying expansion in Iran-linked critical infrastructure targeting focused on the United States,” he told Reuters.

He added, “Extending this activity to encompass additional equipment lines and pairing this with process manipulation and safety degradation makes matters more concerning as it enables various physical impact scenarios.”

Federal agencies have also pointed to previous Iranian cyber campaigns.

In 2023, according to CISA, hackers linked to Iran’s Islamic Revolutionary Guard Corps exploited internet-connected industrial controllers that still relied on factory-default passwords to compromise multiple US water and wastewater facilities.

STORY CONTINUES BELOW THIS AD

Separately, the US Department of Justice previously charged an Iranian hacker over the 2013 intrusion into the control systems of a dam in Rye, New York.

Earlier this year, Iran-linked hackers were also reported to have disrupted operations at multiple US oil, gas and water facilities.

Political dispute as cybersecurity concerns grow

During a Cabinet meeting, US President Donald Trump rejected suggestions that Iran was responsible for the Minnesota attacks and instead blamed state officials. “I just want to mention that we heard in Minnesota there was a cyberattack, and they blame it on Iran,” Trump said.

“I don’t think so. I think I blame it on Minnesota because they’re grossly incompetent.”

He added, “There was a cyberattack of 30 water plants, and I would blame it on Minnesota and the governor, the corrupt governor of Minnesota. They like to say, ‘Oh, it’s Iran.’ Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota.”

Minnesota Governor Tim Walz responded on X by criticising Trump’s remarks.

“Trump knows exactly who is responsible for this attack, and knows that other states were hit too. This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran.”

Why experts say the attacks are alarming

Cybersecurity specialists say the scale and coordination of the recent attacks make them among the most significant incidents affecting US water infrastructure in years.

CISA has warned that attackers “are targeting water entities of all sizes” and has urged operators to immediately disconnect exposed operational technology and cellular modems from the public internet.

STORY CONTINUES BELOW THIS AD

Acting CISA Director Nick Anderson also warned that federal agencies are seeing a sharp increase in attempts to compromise industrial controllers across water utilities nationwide.

The Water Information Sharing and Analysis Center (WaterISAC) has similarly urged utilities to strengthen their cyber defences as investigators continue examining the incidents.

Gus Serino, a longtime cybersecurity specialist focused on the water sector, told CNN, “The scale and coordination of the recent cyberattacks targeting Minnesota water suppliers is unprecedented.”

He added, “While the inherent resilience of the water sector helped limit operational impacts, these incidents once again demonstrate that many drinking water utilities continue to rely on technology architectures that lack fundamental cybersecurity controls capable of preventing or significantly impeding this type of attack.”

Joshua Corman, industrial cybersecurity expert and co-founder of I am the Cavalry, warned that the growing number of compromises highlights the importance of protecting water infrastructure.

“The rising number of water compromises is deeply concerning. So much depends upon water… No water, no hospital, no kidding… in 2-4 hours.”

STORY CONTINUES BELOW THIS AD

He told CNN, “Water systems have enjoyed the benefits of remote access, but now those who wish us harm have it, too.”

“With great connectivity comes great responsibility. We should be asking ourselves: if we can’t protect it, should we disconnect it?”

As investigations continue, authorities have emphasised that no confirmed evidence currently links the attacks to Iran.

With inputs from agencies



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW