State and federal agencies respond to coordinated cyber attacks affecting over 30 water systems
Category: Technology
In a concerning escalation of cyber threats, federal authorities have reported that malicious actors are targeting water and wastewater facilities across at least seven states in the U.S., with Minnesota being the hardest hit. Over 30 water systems in the state experienced disruptions due to a coordinated cyber attack that took place on July 26 and 27, prompting officials to activate statewide incident response protocols.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a warning stating that these attacks are part of a broader trend where threat actors increasingly target operational technology in water facilities. The vulnerabilities stem from the facilities’ connections to the internet, allowing hackers to infiltrate systems, change passwords, and lock out operators. Fortunately, there have been no reports of drinking water contamination, but some utilities have announced boil-water notices and experienced low-pressure water flow in homes.
The cyber attack affected multiple municipalities, including the City of Braham, which urged residents to minimize water usage until the issues were resolved. Just three hours later, Braham reported that the cyber incident had been rectified, and water filtration and flow were back to normal. Other cities, such as Maple Plain and South St. Paul, also faced system outages but managed to implement contingency measures that ensured their water and wastewater operations remained unaffected.
Anonymous government officials have linked the cyber attacks to Iranian hackers, who have reportedly intensified their efforts against U.S. infrastructure since the onset of the current conflict. CISA had previously warned about Iranian-affiliated cyber attacks targeting programmable logic controllers used in water systems. The FBI has opened an investigation into these incidents but has not officially attributed the attacks to Iran.
Former President Donald Trump commented on the situation, placing the blame on Minnesota authorities. “I blame it on Minnesota because they’re grossly incompetent,” Trump stated during a cabinet meeting at Camp David. Minnesota Governor Tim Walz responded firmly, asserting that Trump knows who is responsible and that other states have also been targeted. “This is what modern warfare looks like, and it furthers the illustration that there’s no plan to win a war with Iran,” Walz added in a post on X.
Experts in cybersecurity have expressed concern over the targeting of water utilities, highlighting that these organizations are often seen as vulnerable due to limited resources. Joseph Perry, a cybersecurity researcher at Arcova, noted, “The targeting of multiple water utilities shows that threat actors are increasingly focused on providers of infrastructure, not just private companies.” He emphasized that attackers often seek organizations with the right vulnerabilities, regardless of their size or location.
John Israel, Assistant Commissioner and Chief Information Security Officer at Minnesota IT Services, stated that they are working closely with federal, state, local, and tribal authorities to respond to the cyber attack. “We are sharing intelligence, supporting affected communities, and helping utilities restore operations safely,” he said. The agency has advised water utilities to remain vigilant and on high alert to prevent similar incidents in the future.
Federal agencies, including the FBI and CISA, are coordinating efforts to investigate the attacks. They have assessed that water quality was not compromised and have urged utilities to adopt stricter security measures. The EPA has previously identified hundreds of vulnerabilities in operational technology systems across U.S. infrastructure, raising alarms about the potential for future attacks.
The Operational Technology Cybersecurity Coalition, which includes several prominent infrastructure and cybersecurity firms, has called for increased federal investment in cybersecurity for local utilities. “This week we are facing a reckoning of the consequences of ignoring the importance of investing in our nation’s cybersecurity for our infrastructure,” said Tatyana Bolton, executive director of the coalition. She highlighted the need for Congress to extend and fund the state and local cybersecurity grant program, which is due to expire in September. “By not extending this grant program, Congress is leaving small towns to protect themselves from nation-state actors like Iran,” Bolton stated.
Cybersecurity experts warn that the trend of targeting municipal utilities is likely to continue as attackers seek to exploit weaknesses in systems that are often under-resourced. Matt Hartman, Chief Strategy Officer at the Merlin Group, emphasized that every disruption chips away at public trust in these services. “Operational resiliency must reach the communities that need it most,” he said.
As the investigation continues, federal agencies are working to determine the full scope of the attacks and the specific groups responsible. The lack of ransom demands or political messages suggests that this may be a state-sponsored activity rather than financially motivated hacking. Cybersecurity experts remain cautious, noting that the attribution of such attacks can be complex and may evolve as more data becomes available.
The coordinated cyber attack on Minnesota's water utilities serves as a stark reminder of the vulnerabilities present in the nation’s infrastructure. As authorities work to bolster defenses against such threats, the call for increased investment in cybersecurity remains urgent. With the threat of future attacks lurking, both state and federal agencies must prioritize the security of water systems to protect public health and safety.