Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States

Michigan, South Dakota, and Georgia are reportedly on the list of states whose water systems have been targeted by Iran-linked hackers.

Water system

The recent cyber campaign targeting the water and wastewater sector in the United States has hit at least seven states as more information has come to light regarding Iran’s connection to the hacker attacks.

Minnesota reported last week that operational technology (OT) systems at more than 30 water and wastewater facilities were targeted in a cyberattack on July 26 and 27. 

Only a handful of cities issued public statements about the attack. One city briefly took down its water plant in response, but most reported no operational impact, reassuring citizens that drinking water remains safe.

As expected, the campaign was not limited to Minnesota, and several mainstream media outlets reported learning from sources that at least seven states are impacted. 

Michigan has also officially confirmed that a “small number” of communities have seen malicious cyber activity, noting that all systems continued to operate safely and there were no public health concerns.

Rapid City in South Dakota also reported experiencing a cybersecurity incident, and its description suggests that it may be part of the same campaign. 

Advertisement. Scroll to continue reading.

“Recently, the City of Rapid City experienced a cyber incident involving one of its lift stations, which is used as part of the city’s wastewater system,” the city said in a Facebook post, adding, “At no time was the city’s water or wastewater infrastructure systems placed in jeopardy and city officials assure Rapid City residents the city’s water supply remains safe and protected.”

ABC News reported that Georgia is also among the seven states targeted in the water sector cyberattacks. The names of the other affected states remain unknown at the time of writing. 

Iran blamed for the water sector cyberattacks

Iran was immediately named as the primary suspect considering that its hackers have been known to target ICS and other OT systems, including in the water sector

While the US government has not publicly blamed Iran for the attacks, several mainstream media outlets reported last week that federal investigators had been looking into Iran’s potential involvement

In addition, WaterISAC, which serves as the communications and information-sharing organization for the water sector, reportedly wrote a report revealing that Minnesota’s Fusion Center had found evidence that the attacks were “aligned” with hacking campaigns previously linked by the US to Iran. 

Wired obtained a copy of the report, but WaterISAC noted that it was marked TLP:Amber and was not meant for public release or broad sharing. 

Technical details for OT defenders

Few technical details have been made available by the cities whose water facilities have been targeted by hackers. 

However, one city in Minnesota noted that the incident was limited to “equipment connected via cellular communications,” and industry professionals agree that OT endpoints connected to the internet via cellular networks are a potential intrusion vector.

Iran-linked hackers previously targeted water facilities in Israel via vulnerable cellular routers

Infracritical has made available a continuously updated report that summarizes all of the currently known technical information for the OT security community and defenders.

After the attacks on Minnesota water facilities came to light, CISA urged the sector to protect OT, specifically programmable logic controllers (PLCs).

In addition, days before the Minnesota attacks, federal agencies updated an April advisory on Iranian attacks aimed at OT devices, warning that industrial control systems (ICS) made by Siemens, Schneider Electric, and Rockwell Automation have been targeted. 

Internet security firm Censys reported that roughly 10,000 Rockwell, Siemens, and Schneider PLCs are exposed to the internet, though it’s unclear how many are actually vulnerable to attacks.

Related: Rockwell Patches Code Execution Flaws in Arena Simulation Software

Related: US, Australia Release OT Isolation Guidance for Critical Infrastructure

Related: 1 in 5 Data Center Assets Are Within Easy Reach of Attackers

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

1Kosmos has named Frank Cohen Chief Revenue Officer.

ServiceNow has appointed Simon Mouyal as Chief Marketing Officer.

James Wilkinson has been named Chief Information Security Officer for the City of Dallas.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.