Menu

Cyberattacks on Municipal Water Systems Raise Alarm Nationwide

5 days ago 0

This week, cyberattacks have targeted municipal water systems in at least seven states, leading the FBI and the Environmental Protection Agency (EPA) to issue a warning to utilities across the country. They reported that hackers aim to disrupt essential water infrastructure.

In a public service announcement on Thursday, these agencies noted that numerous water and wastewater utilities had informed the FBI of incidents involving malicious activities. Such activity has hampered water operations, although the announcement did not specify the affected states.

A notable attack took place in Minnesota, where over 30 municipal water facilities were targeted, possibly indicating Iranian involvement. This is currently under investigation. A representative from Minnesota’s information technology services confirmed via email that no evidence suggested contamination of any water supplies in the municipalities affected.

The latest federal advisory emphasizes that the malicious cyber actors (MCAs) targeted particular brands of control systems used by municipal water utilities. Consequently, the FBI and EPA advised operators of all systems to take necessary precautions.

This situation underlines the exposure of U.S. infrastructure systems to interference from adversaries. This is particularly concerning as tensions with Iran are rising, and the U.S. remains involved in the conflict in the region.

Minnesota officials reported that these attackers accessed internet-facing devices, altered IP addresses and passwords, and caused a loss of monitoring and control capabilities for the utilities.

The advisory recommends system operators:

  • Remove programmable logical controllers (PLCs) from direct internet exposure by securing them behind gateways and firewalls.
  • Implement strong password policies.
  • Restrict communication among authorized control system devices using access control lists.

The agencies have not identified those responsible for the breaches. Likewise, neither the U.S. government nor state officials have publicly connected the suspicious activities in Minnesota to a specific actor.

Emily Zimmer, a spokesperson for Minnesota’s information technology agency, highlighted that determining responsibility requires an in-depth analysis of technical evidence together with national and international threat intelligence. Federal partners are best positioned to spearhead this assessment.

This breach came shortly after U.S. authorities publicly cautioned that hackers backed by Iran were focusing on the country’s critical infrastructure amidst the escalating conflict between Washington and Tehran. The Cybersecurity and Infrastructure Security Agency, alongside the FBI and additional federal entities, released a public advisory urging companies to fortify their defenses. They warned that hackers linked to Tehran aimed to infiltrate online automated infrastructure management systems.

U.S. intelligence agencies have also warned that Iran is becoming more assertive in executing cyber operations, having attempted to penetrate water systems in 2023.

The EPA had previously cautioned about the increasing frequency and intensity of cyberattacks on water utilities nationwide. In an enforcement notice issued in May 2024, the agency stated that around 70% of utilities inspected in the preceding year had flouted standards intended to ward off breaches and other security intrusions.

Leave a Reply

Leave a Reply

Your email address will not be published. Required fields are marked *