Officials and cybersecurity experts warn of increased threats targeting critical infrastructure
WASHINGTON: US officials suspect Iran may be behind a cyberattack that targeted more than 30 municipal water systems in Minnesota earlier this week, according to a report by The Washington Post, which cited unnamed government officials familiar with the investigation.
According to Minnesota IT Services, the cyber incidents occurred on Sunday and Monday, prompting a coordinated response from state and municipal authorities. However, officials said the affected communities did not issue any advisories regarding the safety of residents’ drinking water, indicating that water services continued without public health restrictions.
Separately, on Thursday, the US Cybersecurity and Infrastructure Security Agency (CISA) warned of a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) used in the nation’s water and wastewater systems. The agency urged operators of critical infrastructure to strengthen cybersecurity measures against potential intrusions.
Experts point to broader cyber campaign
Joe Slowik, director of threat research at Dataminr, told The Washington Post that similar cyber incidents have affected water and energy infrastructure across the United States since the conflict involving Iran intensified earlier this year.
Meanwhile, Kurt Gaudette, head of intelligence at Dragos, said many of the attacks have focused on smaller utilities with internet-exposed systems and weak security practices, including the continued use of default passwords.
Analysts assess possible objectives
Alex Orleans, head of threat intelligence at Sublime Security, told the newspaper that the apparent objective of the campaign was psychological rather than destructive.
According to Orleans, the alleged strategy seeks to create public anxiety about the security of critical infrastructure while also demonstrating to Iranian authorities that cyber operators are contributing to the country’s broader strategic efforts.
US authorities have not publicly attributed responsibility for the attacks, and Iran has not commented on the allegations reported by The Washington Post. The investigation remains ongoing as federal agencies continue to assess the scope, origin and potential impact of the cyber incidents.
