Credited from: CBSNEWS
In a recent incident, more than 30 community water systems in Minnesota were compromised by a coordinated cyberattack, prompting investigations by state and federal authorities. The Minnesota IT Services revealed that these malicious activities occurred on July 26 and 27, forcing utilities to revert to manual operations in some areas due to compromised remote monitoring systems, including programmable logic controllers (PLCs) used to manage the water systems, according to aljazeera, CBS News, BBC, and Reuters.
The investigations have indicated that the attacks may have links to Iranian hackers, although this assertion is still under scrutiny as U.S. officials caution that the evidence is not definitive. Minnesota and federal agencies have stressed that they are collecting further technical evidence, which could alter their current assessments. Minnesota officials reported early indications of malicious activity but have confirmed that drinking water quality remained unaffected throughout the incident, according to CBS News, BBC, and Reuters.
The FBI has acknowledged its involvement, stating it is "actively engaged with victims" of the cyberattacks. The Bureau confirmed that reports have emerged from at least seven states about similar incidents affecting water and wastewater utilities, contributing to a broader investigation into rising threats to critical infrastructure across the nation. The FBI's efforts emphasize its commitment to assist these vulnerable sectors against malicious actors, particularly in this context of increased cyber threats targeting critical infrastructure, according to aljazeera, CBS News, BBC, and Reuters.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued warnings regarding the increasing frequency of targeted cyber threats against water and wastewater systems. As a part of its advisories, CISA has urged critical infrastructure operators to remove PLCs and other operational technology from public internet exposure to minimize vulnerabilities and reinforce their defenses against such attacks. This advisory comes in light of previous documented threats by Iranian-affiliated hackers targeting similar systems, reinforcing the agency's recommendation to bolster cybersecurity measures, according to CBS News, BBC, and Reuters.