Iranian Hackers Likely Behind Minnesota Water System Cyberattack
U.S. investigators believe Iranian hackers were likely behind a coordinated cyberattack that hit more than 30 municipal water systems across Minnesota this week, though officials caution the assessment remains preliminary as the investigation continues.
Minnesota IT Services (MNIT) said the cyberattack targeted operational technology at the water systems over Sunday and Monday. U.S. and state officials told The New York Times that the tradecraft used, along with the absence of any ransom demand, led analysts to initially point toward Iranian involvement, though that assessment could shift as more data is gathered. Malicious activity connected to the incident has reportedly been detected across at least seven states in total, according to CBS News, though officials have not publicly identified which other states are affected.
Despite the scale of the intrusion, officials say there's no indication the drinking water supply itself has been compromised. "There are no warnings to any of our Minnesota providers," said John Israel, MNIT's assistant commissioner and the state's chief information security officer. Mike Ernster, a public information officer for the Minnesota Department of Public Safety, echoed that assessment, saying none of the state's water supply has been reported compromised.
How the Attack Worked
According to Israel, the hackers gained access through internet-connected programmable logic controllers, remote devices used by system integrators and operators to manage water infrastructure. In most confirmed cases, the intrusions altered settings meant to disrupt remote management access rather than reaching systems that directly control the water supply. Kurt Gaudette, head of intelligence at the cybersecurity firm Dragos, described the targeted systems as largely "very low-hanging fruit," small utilities relying on default passwords with controllers left openly accessible on the internet.
Alex Orleans, head of threat intelligence at Sublime Security, told The Washington Post the goal appeared to be psychological rather than an attempt at physical sabotage, aimed at unsettling the American public over the ongoing conflict with Iran while also sending a message domestically within Iran itself.
Officials have also raised the possibility that the attacks could be a false-flag operation designed to implicate Iran and further escalate tensions, though people familiar with the investigation described that scenario as unlikely.
Part of a Documented Pattern
Iran's interest in targeting U.S. water infrastructure isn't new. In 2016, the Justice Department charged a group of Iranian hackers over a cyberattack on a small dam near New York City. More recently, federal agencies confirmed that actors affiliated with Iran's Islamic Revolutionary Guard Corps used a similar method to breach multiple U.S. water and wastewater facilities in 2023, again by exploiting internet-connected controllers still running default passwords.
A joint advisory issued July 22 by CISA, the FBI and other federal agencies had already warned that Iranian hackers were actively targeting water systems and other operational technology. FBI Cyber Division Assistant Director Brett Leatherman reiterated that warning this week following the Minnesota incident. CISA has urged water system operators to restrict direct internet access to their equipment and validate all external connections, noting that many vulnerable devices, including cellular modems installed by outside vendors, often go undocumented in routine security scans.
The FBI, CISA, the EPA and Minnesota's Bureau of Criminal Apprehension are continuing to investigate the incident alongside state officials, and no group has been formally attributed responsibility as of this week.
Curious for more stories that keep you informed and entertained? From the latest headlines to everyday insights, YourLifeBuzz has more to explore. Dive into what’s next.