Malicious cyber activity affected technology at more than 30 community water systems across Minnesota this week, forcing some utilities to switch to manual operations as state and federal authorities dig into who is behind the attack, CBS News has learned. Investigators are probing to determine whether the activity is the work of Iranian hackers, according to U.S. officials and sources familiar with the incident.
Sources cautioned that since they had not definitively attributed the attack, their assessment could change as additional technical evidence is collected. They are also probing whether the actor could have attempted to appear Iran-based as a way of stirring the pot amid the ongoing U.S. conflict with Iran.
Minnesota and the federal government have not publicly attributed the activity to a particular actor. The FBI, Environmental Protection Agency and Cybersecurity and Infrastructure Security Agency all warned Thursday that attackers are targeting internet-exposed industrial controllers used by water and wastewater utilities. In at least some cases, federal authorities reported loss of monitoring and control functionality at critical infrastructure cites, leading to pressure loss and flooding.
Federal agencies did not identify affected states, and the FBI and EPA said the issue extends beyond Minnesota, with incidents reported in "at least seven states." Most confirmed cases in the Minnesota cyberattack involved technology used to remotely monitor and control water system equipment, including devices called programmable logic controllers, according to Minnesota IT Services. None of Minnesota's water supply has been reported compromised as a result of the attack, Mike Ernster, a public information officer for the Minnesota Department of Public Safety, told CBS News. The Bureau of Criminal Apprehension's Minnesota Fusion Center was working with municipalities, as well as state and federal partners, to address the issue, he added.
Nick Anderson, acting director of the federal Cybersecurity and Infrastructure Security Administration, confirmed that the agency "is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLC) at water utilities." "We urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible," he added. Minnesota said investigators identified some similarities in the timing of the recent incidents, in addition to the types of technology impacted, but had not yet confirmed that every incident was carried out by the same actor. A spokesperson for the city of South St.
Paul told CBS News it identified an issue early Monday and immediately implemented contingency procedures. Public works employees transitioned to manual operations, allowing water and wastewater services to continue without any interruption to service. The city added that the incident was limited to technology supporting portions of its water utility, while drinking water treatment, quality, pressure and delivery were not impacted.
Officials in South St. Paul found no indication that resident or customer data was accessed. In Braham, located in a more rural area north of Minneapolis, public works personnel also discovered the problem Monday after noticing the well supplying the city's water tower was malfunctioning.
Workers isolated the affected system, restored a backup and restarted the plant in about 90 minutes, Mayor Nate George confirmed to CBS News. Residents experienced no loss of water service, George added. The city's water tower typically holds enough drinking water to last about two days, and operators discovered the problem before receiving an automated alert, leading the city to believe the pump had been offline for only a brief period.
The city has since ensured the system is not connected to any public-facing internet networks and is meeting with its technology provider about remediation. In suburban Plymouth, Minnesota, officials detected an outage Sunday evening after noticing compromised PLCs at two water towers and fourteen sewer lift stations, then disconnecting them from the cellular network. A city official in Plymouth told CBS News that operators moved into a manual operation mode temporarily until the systems were brought back online, with normal communications restored by Tuesday afternoon.
Still, officials say water quality, treatment and pressures were never affected, with delivery remaining undisrupted throughout. Michael Thompson, the Plymouth Director of Public Works, told CBS News Minnesota his team first noticed there was a problem when communication between devices started to become interrupted on Sunday evening. By the early morning hours on Monday, just after midnight, Thompson said it was an all-hands-on-deck situation.
"I think you never expect it to happen to you," Thompson said. CISA said Thursday that it's "currently observing a significant increase in cyber threat actors" that are targeting PLCs in the Water and Wastewater Systems sector, noting those actors are targeting "water entities of all sizes." "CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible," said CISA, which is part of the Department of Homeland Security. "Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans," CISA added in its advisory .
Iran-linked hackers have previously targeted U.S. water utilities. Federal agencies confirmed previously that actors affiliated with Iran's Islamic Revolutionary Guard Corps used a similar playbook, accessing multiple water and wastewater facilities in 2023 by exploiting internet-connected controllers that retained their default passwords.
AI on pace to bypass cybersecurity systems soon, "Five Eyes" spy partners warn Canvas' parent company strikes deal with hackers to delete stolen data Canvas back online after cyberattack hit learning platform for U.S. schools Anthropic says Chinese hackers used its AI chatbot in cyberattacks Cybersecurity order warns of "imminent risk" to federal agencies Exclusive: Iran Plans to Seize Protestant Church The Dangerous Pause in Iran, with Mark Montgomery