Minnesota’s Water Under Siege: Leaked Memo Points to Iranian Cyberwarfare
In a significant escalation of cyber hostilities, a confidential memo circulating within the water industry has explicitly linked recent, disruptive cyberattacks on Minnesota’s water utilities to Iran. This revelation marks the widest and most impactful strike by Iranian-affiliated hackers against the United States since the onset of an undeclared cyberwar in late February, which has already seen attacks ranging from paralyzing medical suppliers to breaching high-profile government emails.
The Unfolding Cyber Offensive
WaterISAC Confirms Iranian Link
A critical communication, obtained by WIRED, was dispatched to members of the Water Information Sharing and Analysis Center (WaterISAC), a vital industry group facilitating cybersecurity information exchange among water utilities. This memo unequivocally ties a series of cyberattacks, which targeted dozens of Minnesota’s public drinking water and wastewater systems, directly to Iran.
The WaterISAC note references an alert from the Minnesota Fusion Center, a state-level intelligence hub, detailing “ongoing malicious cyber activity.” Crucially, the fusion center determined these attacks were “aligned” with a hacking campaign first identified in April by the US Cybersecurity and Infrastructure Security Agency (CISA), which attributed the activity to “Iran-affiliated” hackers. While both reports were marked unclassified, their “for official use only” designation underscores the sensitivity of the intelligence.
A New Frontier in State-Sponsored Hacking
Joe Slowik, a former Los Alamos National Labs cybersecurity researcher now contracting for the Department of Energy, emphasizes the gravity of this development. He states that Iran’s confirmed responsibility for targeting water utilities represents a form of state-sponsored assault on civilian infrastructure rarely witnessed outside of Russia’s conflict with Ukraine. “Now we have documented disruption and even modification of safety and protection parameters in critical infrastructure,” Slowik warns. “Seeing this sort of tradecraft expand to Iran, and seeing it across multiple sites, it should really be making people concerned right now.”
Slowik further cautioned that these incidents might not be isolated to Minnesota, given the widespread use of the targeted technology across numerous other sites. This suggests a potential for broader, continued attacks by an adversary demonstrating clear intent and capability.
The Scope of the Attack and Its Implications
Disruptions and Warnings
Earlier this week, Minnesota state officials disclosed that over 30 municipal water and wastewater systems had been compromised. These breaches, in some instances, severed telecommunications between industrial control systems and water utility equipment. In at least one case, the city of Braham, with a population of 1,700, experienced a brief outage of its water plant. While immediate evidence of widespread water shortages or direct threats to safety is pending, a recent CISA advisory confirmed that the attacks have led to “boil-water notices”—indicating fears of contamination—and necessitated “sustained manual operations.”
Identifying the Adversary: CyberAv3ngers?
As the incidents became public, Iran quickly emerged as the primary suspect, despite a lack of official confirmation or claims of responsibility from Iranian hacker groups. Cybersecurity firm Tenable, in a report published Monday, pointed to CyberAv3ngers, an Iranian hacker group reportedly linked to the Iranian Revolutionary Guard Corps, as a likely culprit. Tenable noted that the “operational pattern is consistent with” this group or its associates. Concurrently, The New York Times reported that US and state officials, along with other informed sources, concluded the Minnesota attacks were “likely” executed by Iranian state-sponsored hackers, though without naming a specific entity.
Tenable’s report highlighted an updated CISA advisory, initially released in April, which warned of Iran-linked actors targeting programmable logic controllers (PLCs)—devices crucial for automation in critical infrastructure—to cause “operational disruption and financial loss.” This advisory specifically implicated an “Iranian-affiliated” group, noting CyberAv3ngers’ history of similar PLC targeting. While the updated advisory itself doesn’t explicitly mention the Minnesota attacks, its timing (July 22 update) strongly suggests a connection to the recent events, a link now explicitly drawn by the WaterISAC memo.
Securing the Lifeline: CISA’s Urgent Advisory
In response to these escalating threats, CISA issued a new advisory urging water utilities to take immediate protective measures. The agency warns that “these threat actors are targeting water entities of all sizes.” Key recommendations include disconnecting PLCs from the internet, implementing strong password protection for access, and establishing “allow-lists” to ensure only trusted devices can connect to these critical systems. The attacks underscore the urgent need for robust cybersecurity protocols to safeguard essential public services against increasingly sophisticated and brazen state-sponsored threats.
For more details, visit our website.
Source: Link









Leave a comment