A cyberattack struck water systems across at least seven states this week, forcing some utilities to abandon automated controls and switch to manual operations. Federal and state investigators are now working to determine who carried it out, and whether Iran is responsible.
According to CBS News, which first reported the story, investigators are probing whether Iranian hackers were behind the attack. Officials cautioned that attribution had not been confirmed and that their assessment could change as more technical evidence comes in. Investigators are also considering whether the attacker may have deliberately appeared to be Iran-based in order to stir tension during the ongoing U.S. conflict with Iran.
The FBI reported incidents in at least seven states but did not name them. CBS News learned that more than 30 community water systems in Minnesota were affected. The attack targeted programmable logic controllers, devices used to remotely monitor and operate water system equipment.
In at least some cases, federal authorities reported a loss of monitoring and control capability at critical infrastructure sites, leading to pressure loss and flooding. Minnesota IT Services confirmed that most cases in the state involved the remote control technology.
Mike Ernster, a public information officer for the Minnesota Department of Public Safety, told CBS News that none of Minnesota's water supply has been reported compromised. The Bureau of Criminal Apprehension's Minnesota Fusion Center was coordinating with municipalities and state and federal partners to address the situation.
The city of South St. Paul identified an issue early Monday and immediately put contingency procedures in place. Public works employees moved to manual operations, allowing water and wastewater services to continue.
The FBI, the Environmental Protection Agency, and the Cybersecurity and Infrastructure Security Agency all issued warnings Thursday that attackers were targeting internet-exposed industrial controllers at water and wastewater utilities.
Nick Anderson, acting director of the Cybersecurity and Infrastructure Security Administration, confirmed that the agency "is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLC) at water utilities." He added: "We urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible."
Minnesota investigators found similarities in the timing of recent incidents and in the types of technology affected. However, they said they had not yet confirmed that a single actor was responsible for all of them.
Neither Minnesota nor the federal government has publicly attributed the attack to any particular group or country as of Thursday.
