A wave of coordinated cyberattacks recently struck operational technology (OT) systems across more than 30 community water utilities in Minnesota. According to Minnesota IT Services (MNIT), the incident occurred between July 26 and 27, prompting an immediate activation of state-level incident response protocols. Several municipalities, including Braham, Maple Plain, Plymouth, and South St. Paul, confirmed being impacted, with the town of Braham experiencing a total facility shutdown after intruders disabled the computerized controls managing its well and water treatment processes.
While official attribution is currently under investigation, security analysts have noted that the tactics align with the behavior of CyberAv3ngers, a group previously linked by the U.S. government to Iran's Islamic Revolutionary Guard Corps Cyber-Electronic Command. This context is significant, as the attacks transpired just days after federal authorities issued alerts regarding Iranian-affiliated actors targeting programmable logic controllers (PLCs) within critical national infrastructure. According to Security Affairs, the attackers consistently focused on modifying passwords and altering IP addresses to lock out legitimate operators, forcing some jurisdictions to issue boil-water advisories or revert to manual system management.
In response to the surge in hostile activity against the Water and Wastewater Systems (WWS) sector, the Cybersecurity and Infrastructure Security Agency (CISA) has issued a stern advisory. Federal officials are now mandating that all utility operators identify and remove any internet-exposed PLCs and related OT hardware from public access. The agency emphasizes that these devices were never designed to be exposed to the open internet, and maintaining such configurations creates an unnecessary vulnerability that hostile actors are actively exploiting to disrupt essential public services.
Reader Discussion & Insights