CISA alerts that hackers are progressively focusing on US water systems following an attack in Minnesota.
A coordinated cyberattack disrupted industrial controllers at over 30 water systems in Minnesota. The US Cybersecurity and Infrastructure Security Agency (CISA) is advising utilities to remove this hardware from the internet.
CISA has raised alarms about the increasing targeting of the nation’s water systems by hackers, urging utilities to secure the industrial controllers that manage water distribution. This alert comes shortly after the aforementioned attack, which impacted equipment at multiple Minnesota water systems, reminiscent of a previous incident in Poland where water plants were compromised due to default passwords.
The Minnesota breach served as the catalyst. Over the weekend of July 26, intruders accessed the programmable logic controllers that oversee treatment and pumping operations, locking out operators and forcing several towns to manually manage their water systems. Four municipalities—Plymouth, South St. Paul, Maple Plain, and Braham—were specifically mentioned, with at least one well and treatment plant going offline before staff were able to restore service, typically within about 90 minutes.
One official described the threat starkly, stating that attackers could effectively “turn the well off,” highlighting the risks of unauthorized control over machinery that regulates a town’s water supply. Officials reassured the public that the water remained safe, with no calls for residents to alter their usage and no contamination of drinking water, although the incident revealed how precarious the situation can be.
CISA indicated that this is part of a broader pattern rather than an isolated incident. Following an earlier breach where the agency itself was unprepared, CISA noted that Iranian-affiliated groups have been exploiting internet-exposed controllers in water, energy, and government networks.
The technical aspects are concerning. CISA’s advisory revealed that attackers have accessed controller project files and altered the code modules governing safety logic, deactivating alarms that would alert operators to the tampering.
The vulnerable hardware is widespread. The advisory cited controllers from Rockwell Automation, Schneider Electric, Siemens, and Unitronics, which are fundamental to industrial automation but were not designed to be exposed on the open internet.
Much of the vulnerability stems from basic issues. Investigators identified unsecured controllers, default passwords, inadequate network segmentation, and misconfigured software as key problems, rather than sophisticated exploits—failings that have long affected the sector.
When specific flaws were present, they were often older ones. CISA pointed to a high-severity authentication-bypass vulnerability in Rockwell controllers from 2021 that remains unpatched by the vendor and must be mitigated through other means.
CISA offered clear recommendations. Operators are advised to disconnect controllers from the public internet, set physical mode switches to “run,” segment IT and operational networks, and implement multi-factor authentication for remote access.
The scale of the exposure is significant. The US is home to between 150,000 and 170,000 water systems, many of which are small, rural operations managed by personnel with limited budgets and expertise in cybersecurity.
Regulators have previously highlighted this gap. The EPA reported that over 70% of US water systems have not complied with a 2018 law mandating updated risk assessments, with audits revealing numerous high-risk vulnerabilities affecting systems that serve nearly 200 million citizens.
The attack is believed to be linked to a familiar group. CyberAv3ngers, an Iran-associated group responsible for targeting Pennsylvania water infrastructure in 2023, is suspected to be behind the Minnesota intrusion, though state officials have not publicly identified a perpetrator.
This incident reflects a larger trend of state-sponsored hacking. Western governments have responded by imposing sanctions on Russia’s cyber network and conducting drills for potential infrastructure attacks, underscoring the increasing importance of water, energy, and transportation as potential targets.
For water utilities, the situation is troubling. The tools necessary for such intrusions are inexpensive, defenses are often inadequate, and future attacks may be more severe than a mere 90-minute manual operation.
Other articles
CISA alerts that hackers are progressively focusing on US water systems following an attack in Minnesota.
Following a coordinated assault that disabled controllers in over 30 water systems in Minnesota, CISA is recommending that utilities disconnect their industrial equipment from the internet.
