The series of cyberattacks recently targeting water and wastewater sectors across the United States have now been connected to at least seven states. Emerging details point towards Iran’s involvement in orchestrating these attacks.
States Affected by Cyber Campaigns
In late July, Minnesota experienced a breach in its operational technology (OT) systems at over 30 water and wastewater facilities. Despite the alarming breach, most cities reported minimal operational disruption and confirmed the safety of drinking water.
Beyond Minnesota, the campaign’s reach extends to several other states. Mainstream media sources indicate that at least seven states were affected, although specific details remain limited. Official confirmation from Michigan highlights minor cyber activities affecting a few communities, yet all systems reportedly functioned safely without posing public health risks.
Incident Reports from Affected Cities
Rapid City in South Dakota acknowledged a cybersecurity incident involving its wastewater system lift station. Officials assured residents that the city’s water infrastructure remained secure and unaffected. Similarly, Georgia is identified among the impacted states, while the identities of other affected states remain undisclosed.
Iran’s Involvement in Cyberattacks
Iran has been identified as the primary suspect due to its history of targeting industrial control systems (ICS) and OT systems, including those in the water sector. Although the US government has not officially named Iran, federal investigations are underway to explore possible connections.
WaterISAC, a key communications entity for the water sector, released a report indicating that Minnesota’s Fusion Center found evidence linking the attacks to known Iranian campaigns. However, the report was marked TLP:Amber, limiting its public dissemination.
Protective Measures for Water Sector
Detailed technical information remains sparse, but some Minnesota facilities noted breaches limited to equipment using cellular communications. Industry experts warn that OT endpoints using such networks are potential entry points for cyber threats.
Following these events, the Cybersecurity and Infrastructure Security Agency (CISA) emphasized the importance of securing OT systems, particularly programmable logic controllers (PLCs). Federal advisories have been updated to highlight vulnerabilities in devices from Siemens, Schneider Electric, and Rockwell Automation, urging protective measures.
Internet security firm Censys identified around 10,000 PLCs from these manufacturers exposed online, though the extent of their vulnerability is uncertain. As investigations continue, water systems nationwide are being urged to bolster their cybersecurity defenses.
