Iran suspected of launching malicious cyberattacks on US water systems
Federal authorities are warning that critical infrastructure systems in the United States could be at risk after at least seven states reported cyberattacks that interrupted their water or wastewater operations this week.
According to a joint alert from the FBI and the Environmental Protection Agency, “malicious cyber actors” have been remotely tampering with some water systems’ internet-connected programmable logic controllers, or PLCs, causing loss of water pressure and flooding.
The warning, issued last week, comes after US intelligence officials said Iran was likely behind a co-ordinated cyberattack on more than 30 municipal water systems in Minnesota.
Experts have also warned for years that the US water industry, which has resisted regulation efforts, has been vulnerable to cyberattacks.
Intelligence agencies have not definitively concluded that Tehran was responsible for the disruptions in Minnesota.
However, the hack follows urgent warnings by federal cybersecurity officials that Iran for months has been targeting internet-exposed devices that control operations at water, wastewater and energy facilities in the US.
In July, federal cybersecurity authorities specifically warned that Iranian hackers were exploiting vulnerable PLCs.
US President Donald Trump has blamed Minnesota’s state government, not Iran, for that attack. The FBI did not respond to a request for comment about whether it believed Iran was responsible, saying the agency and others were “fully engaged to protect critical infrastructure”.
Federal authorities have not identified which states were affected in recent hacks. Outside of Minnesota, Michigan and South Dakota have also reported attacks.
However, experts said it is likely that many more US states are affected, given that the brand of PLCs targeted - Rockwell Automation/Allen-Bradley - is widely used.
Joshua Corman, a public safety and resilience expert at the Institute for Security and Technology. said: “We only have one internet and it’s the same equipment for all these victims ... Theoretically, you should see these [vulnerabilities] in all 50 states.”
To date, the cyber attackers have employed “low sophisticated tactics” to hack into internet-connected PLCs, often ones with weak or non-existent credentials, according to Alec Davison, an analyst with WaterISAC - which works with government to strengthen security.
He said the hackers had subsequently modified passwords to lock out operators and disconnect controllers.
He added: “This has led to boil water notices and forced utilities into sustained manual operations”.
The risk is that cyberattackers tampering with PLCs could change the “logic” or software of a system so that an operator might not detect an issue with, say, dangerous levels of chemicals.
Kurt Gaudette, head of intelligence for Dragos, a cybersecurity firm that specialises in protecting critical infrastructure, said: “Operators see normal displays. No alerts fire and the process can enter an unsafe condition without anyone knowing.”
Experts widely agreed that water infrastructure in the US has been uniquely vulnerable for more than a decade.
Of the roughly 151,000 water plants in the US, about one-third service residential communities year-round. But only about 420 water plants participate in WaterISAC to try to improve cybersecurity across the water sector.
Corman said: “We have under 0.5% paying attention to cybersecurity. U water is incredibly prone. We’ve been prey, we just didn’t have predators with an appetite for water, but that’s over.”
Another issue is that many small- to medium-size utilities are using third-party integrators or contractors to configure the security settings on their systems, and these contractors are using default credentials and weak passwords.
Compounding the problem, the water industry has also resisted efforts to be regulated for cybersecurity.
After the Biden Administration tried to impose cybersecurity audits of water utilities in 2023, some water industry groups and three states - Missouri, Arkansas and Iowa - sued, causing the EPA to roll back its standards.
Nate George, the Mayor of Braham, Minnesota, which experienced a hack this week that caused the town’s plant to briefly go offline, said in a statement to the Washington Post that cities such as his needed more resources to comply with mandates to ensure their utility systems and infrastructure were safe.
Cybersecurity threats to the water sector, however, are only expanding.
Trump, at a meeting with Cabinet officials at Camp David, waved off the suggestion that Iran was involved in the Minnesota attack - and in turn blamed its officials, a frequent political target.
Trump said: “I blame it on Minnesota because they’re grossly incompetent, I would blame it on Minnesota and the governor, the corrupt governor of Minnesota. Iran’s got bigger problems than worrying about Minnesota.”
Governor Tim Walz, a Democrat, pointed the finger at both Iran as well as at Trump, saying: “Trump knows exactly who is responsible for this attack, and knows that other states were hit too. This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran.”
Take your Radio, Podcasts and Music with you