A GoCheckMy site
GoCheckMyNews Every story, sourced. Every source, rated.
VerifiedUpdatenewsgovernment

U.S. investigating Iranian attribution in cyberattack on Minnesota water systems

More than 30 Minnesota water utilities lost monitoring and control functions in coordinated cyber incidents this week. Federal investigators are examining whether Iranian actors were responsible, though attribution remains unconfirmed. No water supply has been compromised.

Malicious cyber activity struck more than 30 Minnesota community water systems this week, forcing operators to abandon remote monitoring and control functions and shift to manual operations. Federal investigators are now examining whether Iranian actors were behind the attack, according to U.S. officials and sources familiar with the incident, though no definitive attribution has been made.

The FBI, Environmental Protection Agency, and Cybersecurity and Infrastructure Security Agency all warned Thursday that attackers are targeting internet-exposed industrial controllers used by water and wastewater utilities. In at least some cases, federal authorities reported loss of monitoring and control functionality at critical infrastructure sites, leading to pressure loss and flooding. The incidents extend beyond Minnesota, with cases reported in at least seven states.

Most confirmed cases in the Minnesota cyberattack involved programmable logic controllers (PLCs), devices used to remotely monitor and control water system equipment. The city of South St. Paul identified an issue early Monday and immediately implemented contingency procedures, transitioning public works employees to manual operations. South St. Paul found no indication that resident or customer data was accessed. In Braham, public works personnel discovered the problem Monday after noticing the well supplying the city's water tower was malfunctioning; workers isolated the affected system, restored a backup, and restarted the plant in about 90 minutes, according to CBS News. Braham's water tower typically holds enough drinking water to last about two days, and operators discovered the problem before receiving an automated alert. Mayor Nate George of Braham confirmed residents experienced no loss of water service. In suburban Plymouth, officials detected an outage Sunday evening after noticing compromised PLCs at two water towers and fourteen sewer lift stations; Plymouth officials moved into manual operation mode temporarily until systems were brought back online, with normal communications restored by Tuesday afternoon, per Michael Thompson, Plymouth's Director of Public Works.

Nick Anderson, acting director of the federal Cybersecurity and Infrastructure Security Administration, confirmed that the agency is currently observing a significant increase in cyber threat actors targeting PLCs at water utilities. CISA urges critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible. Mike Ernster, a public information officer for the Minnesota Department of Public Safety, said the Bureau of Criminal Apprehension's Minnesota Fusion Center was working with municipalities, as well as state and federal partners, to address the issue.

However, sources cautioned that they had not definitively attributed the attack to Iran; their assessment could change as additional technical evidence is collected. Investigators are also probing whether the actor could have attempted to appear Iran-based as a way of stirring the pot amid the ongoing U.S. conflict with Iran. Minnesota identified some similarities in the timing of the recent incidents, in addition to the types of technology impacted, but had not yet confirmed that every incident was carried out by the same actor. Neither Minnesota nor the federal government has publicly attributed the activity to a particular actor.

Iran-linked hackers have previously targeted U.S. water utilities. Federal agencies confirmed previously that actors affiliated with Iran's Islamic Revolutionary Guard Corps accessed multiple water and wastewater facilities in 2023, according to CBS News reporting. None of Minnesota's water supply has been reported compromised as a result of the current attack.

The key fact

Malicious cyber activity affecting more than 30 community water systems across Minnesota prompted federal investigation into possible Iranian attribution, with officials cautioning that assessment could change as technical evidence is collected.

The Bottom Line

The attribution question will be answered over the coming days and weeks as investigators collect technical evidence and confirm whether all incidents share a common actor. Watch for official statements from the FBI, CISA, or the Department of Homeland Security naming the responsible party, if attribution is determined. If no definitive attribution is made within 30 days, the investigative baseline shifts and the story moves from "Iranian attack" to "unattributed cyberattack with Iranian characteristics."

Every story, sourced. Every source, rated.

Charles Independence The GoCheckMyNews Desk Ranked, source-checked, and verified by the desk's independent review pass.

Sources

  1. cbsnews.com lean-left / high

Single-source report. As published, only cbsnews.com had reported this development. No independent outlet had corroborated it.

Outlet ratings are the public AllSides and Media Bias/Fact Check charts' calls, not ours. How we rate sources.

GoCheckMyNews reports events. It does not editorialize and it does not advise. Nothing here is political advocacy, legal advice, or financial advice.