Authorities investigating a coordinated cyberattack against Minnesota water systems | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Federal and state authorities are investigating what they call a coordinated cyberattack over two days against operational technology at more than 30 community water systems in Minnesota. 

Minnesota IT Services (MNIT), the state agency in charge of information technology, said it is coordinating with various state and federal agencies and private sector partners to respond to the attacks. 

John Israel, assistant commissioner at MNIT and the chief information security officer in Minnesota, said authorities were actively working with partners to restore operations and provide other services. 

Nate George, the mayor of Braham, Minn., said the attack should serve as a wake-up call to state lawmakers. 

“Minnesota’s local governments are expected to defend essential systems against foreign adversaries and sophisticated criminals, often with limited staff, aging technology and inadequate resources,” he said in a post on X.

He added that Braham was prepared for such an attack, using strong internal controls, routine monitoring, back systems and a swift response by local employees.   

The coordinated attacks took place over two days, starting on Sunday, according to authorities. There is no evidence that local officials have instructed residents to modify their usage of drinking water, MNIT said. 

In a statement posted on their  official website, authorities in South St. Paul, Minn., said they identified a cyberattack on Monday that impacted certain automated controls. 

After implementing contingency procedures, officials confirmed no major impact to drinking and wastewater treatment operations. Drinking water remains safe for use. Staff are monitoring their systems and taking additional measures to restore normal automated operations. 

Federal response

Authorities, including the FBI, the Environmental Protection Agency and the Cybersecurity and Infrastructure Security Agency, are coordinating with local utilities to assess the immediate impact of the attacks, share threat information and remediate any damage. 

“The FBI is aware of the incident and in contact with victims to resolve the matter,” a spokesperson told Cybersecurity Dive via email.

The attacks come days after U.S. agencies warned that state-linked hackers were widening their targeting of programmable logic controllers from Rockwell Automation and other makers, following a series of attacks that took place earlier this year. 

Iran-linked hackers have been exploiting vulnerable devices in an effort to disrupt a series of critical infrastructure providers, including drinking water, wastewater treatment and energy companies.

Officials at CISA and the EPA were not immediately available for comment, but are actively looking into the matter.

Editor’s note: Updates story with comment from the FBI. 



——————————————————-


Click Here For The Original Source.

National Cyber Security

FREE
VIEW