Popular Posts

Iran Behind Minnesota Water Cyberattack? US Investigates

Iran Behind Minnesota Water Cyberattack? US Investigates

Cyberattack Hits Minnesota Water Systems: What You Need to Know

TL;DR: Hackers targeted the computer systems controlling water pumps and treatment at over 30 Minnesota towns this week. No drinking water was contaminated, but some cities had to switch to manual operations. Federal agencies warn this is part of a broader campaign hitting at least seven states, possibly linked to Iranian hackers.


What Happened?

Imagine you have a remote control for your garden sprinkler. Now imagine someone else grabs that remote and turns your sprinklers on and off whenever they want. That’s essentially what happened to more than 30 community water systems across Minnesota this week.

  • Who: Unknown attackers (investigators are looking at possible Iranian hackers, but nothing is confirmed yet).
  • What: Malicious cyber activity targeted the industrial controllers that run pumps, valves, and monitoring equipment.
  • When: Starting Sunday night through Monday (late July 2026).
  • Where: At least 30 Minnesota water utilities, plus similar incidents in at least six other states.
  • Impact: Some cities temporarily lost remote monitoring and control, forcing staff to run systems manually (by hand). No drinking water quality or safety was compromised.

The Technology Under Attack: PLCs Explained Simply

Important Point: The attackers went after Programmable Logic Controllers (PLCs).

Think of a PLC as a tiny, rugged computer that sits inside a water tower or pump station. Its job is simple: "If the water level drops below X, turn on the pump. If pressure gets too high, open the relief valve."
These devices are not supposed to be directly on the public internet—but many were, often through cellular modems installed by vendors that the utility didn’t even know about.


How Three Minnesota Cities Responded

City What Happened How They Fixed It
South St. Paul Detected issue early Monday. Switched to manual operations immediately. Water service never stopped. No customer data accessed.
Braham (rural, north of Minneapolis) Well pump malfunctioned Monday. Workers noticed before automated alert. Isolated the system, restored a backup, restarted plant in ~90 minutes. Water tower had 2-day supply. Now disconnected from public internet.
Plymouth (suburban) Compromised PLCs at 2 water towers + 14 sewer lift stations Sunday night. Disconnected from cellular network. Manual mode until Tuesday afternoon. Water quality, pressure, delivery unaffected.

Quote from Plymouth Public Works Director Michael Thompson:
"I think you never expect it to happen to you."


What the Federal Government Is Saying

Three major agencies issued joint warnings on Thursday, July 30, 2026:

  1. FBI – Federal Bureau of Investigation
  2. EPA – Environmental Protection Agency
  3. CISA – Cybersecurity and Infrastructure Security Agency (part of Dept. of Homeland Security)

Key Takeaways from Their Alerts

  • Confirmed: "Significant increase in cyber threat actors targeting PLCs at water utilities."
  • Confirmed: Targeting water entities of all sizes—big cities and tiny towns alike.
  • Confirmed: Some cases led to loss of monitoring/control, pressure loss, and flooding.
  • Urgent Advice: "Remove publicly exposed PLCs and other operational technology from the internet as soon as possible."
  • Hidden Risk: Even utilities with good security may have undocumented cellular modems installed by vendors or integrators that don’t show up in normal security scans.

Is Iran Behind This?

Investigator Notes (Not Publicly Confirmed):

  • U.S. officials and sources say they are probing possible Iranian hacker involvement.
  • Attribution is not definitive—assessment could change as more technical evidence is collected.
  • Investigators are also checking if the attacker deliberately made it look like Iran to stir tensions amid ongoing U.S.–Iran conflict.
  • Minnesota and federal govt. have NOT publicly blamed any specific actor.

Historical Context

  • 2023: Iran-linked hackers (Islamic Revolutionary Guard Corps affiliates) did breach multiple U.S. water/wastewater facilities.
  • Their playbook: Exploited internet-connected controllers that still had default passwords (like "admin/admin").

What Should Water Utilities Do Right Now? (Step-by-Step)

If you run a water or wastewater system—or know someone who does—here’s the immediate action checklist from CISA:

  1. Identify every PLC and operational technology (OT) device connected to the internet (including cellular modems).
  2. Disconnect them from the public internet immediately.
  3. Require VPN + MFA (multi-factor authentication) for any remote access.
  4. Change all default passwords on every controller, modem, and router.
  5. Audit vendor/installed equipment—ask integrators for a full list of remote-access modems they installed.
  6. Monitor logs for unusual login attempts or configuration changes.
  7. Report suspicious activity to CISA and your state fusion center.

Summary

  • 30+ Minnesota water systems hit by cyberattack targeting industrial controllers (PLCs).
  • No water contamination—drinking water remained safe everywhere.
  • Manual operations kept taps running in South St. Paul, Braham, Plymouth.
  • At least 7 states total affected; federal agencies call it a significant, ongoing campaign.
  • Possible Iran link under investigation—not confirmed.
  • Root cause: Too many PLCs exposed on the internet, often via undocumented cellular modems.
  • Fix: Pull PLCs off the public internet NOW. Use secure remote access (VPN + MFA) instead.

FAQ

1. Was my drinking water poisoned or contaminated?

No. Multiple officials (Minnesota Dept. of Public Safety, city managers) confirmed water quality, treatment, pressure, and delivery were never affected. The attack hit the control computers, not the water itself.

2. What is a PLC, and why does it matter?

A Programmable Logic Controller (PLC) is a small industrial computer that automatically runs equipment—like turning on a pump when a water tower gets low. If a hacker takes over the PLC, they can turn pumps off, open valves, or disable alarms. That’s why keeping them off the public internet is critical.

3. Has this happened before?

Yes. In 2023, hackers linked to Iran’s Revolutionary Guard Corps breached several U.S. water utilities using the same method: finding PLCs on the internet that still had default passwords.

4. Why would hackers target small-town water systems?

Attackers often go after easy targets—small utilities with limited IT staff and older equipment. Also, hitting many small systems creates widespread disruption and fear, even if each individual system is small.

5. What can I do as a resident?

  • Stay informed via your city’s official website or alerts.
  • Trust your tap water—officials confirm it’s safe.
  • Report oddities (e.g., sudden pressure loss, strange taste) to your local public works department.
  • Support local funding for cybersecurity upgrades—water systems need modern defenses just like power grids do.

Final Thought: This attack is a wake-up call. Water systems are critical infrastructure, and their control computers must not be reachable from the open internet. The fix isn’t high-tech—it’s basic hygiene: disconnect, password-protect, and monitor.

Leave a Reply

Your email address will not be published. Required fields are marked *