Hackers target more than 30 Minnesota water utilities in coordinated cyberattack

More than a dozen community water systems in Minnesota have been targeted by hackers in a “coordinated cyberattack.”
According to a press release by the state, the water treatment facilities were hit on July 26th and 27th.
As soon as the incident came to light, Minnesota IT Services (MNIT) immediately enabled its cybersecurity protocols to minimize the impact. In addition, Minnesota’s critical infrastructure has been strengthened to prevent recurrence.
Federal, state, local, tribal, and private-sector partners are currently investigating the attack. At the same time, affected communities are being supported. At this time, there’s no need for residents to modify their water usage.
“Cyberattacks against critical infrastructure require a coordinated, whole-of-government response,” John Israel, MNIT Assistant Commissioner and Minnesota Chief Information Security Officer (CISO), said in a statement.
“This incident demonstrates why Minnesota has invested in strong cybersecurity capabilities and partnerships. Our response worked as intended, enabling agencies at every level of government to rapidly coordinate, contain the incident, and help prevent more serious impacts to critical services,” he continued.
Several cities in Minnesota have also reported cyberattacks on their water supply systems.
Mayor of Maple Plain, Julie Maas-Kusske, even went so far as to declare a local state of emergency, allowing the city to allocate more resources to deal with the incident.
“At this time, there has been no disruption to water or wastewater service, and there is no indication that the safety or quality of the city’s drinking water has been affected,” she stated.
The City of Braham temporarily took the water treatment plant offline because attackers had disabled the controls. The plant is now back online, and there was never any danger to the city’s water quality or safety.
The City of South St. Paul was also affected by the cyberattack. During the incident, the drinking water remained safe, and the water and wastewater services were fully operational.
In Plymouth, the attack affected the communications at two of the city’s water towers and multiple lift stations in the city.
“Water levels and water quality are unaffected; the water is safe, and there is no need for the public to adjust consumption. The issue is limited to equipment connected via cellular communications within the system, and crews have continued operating as normal through manual procedures,” the city said in a press release.
Officially, it remains a mystery who’s behind the cyberattacks on the Minnesota water plants. However, according to cybersecurity firm Tenable, the tactics, techniques, and procedures (TTPs) are consistent with the CyberAv3ngers, a pro-Iranian hacktivist group.
Since 2023, the CyberAv3ngers have targeted water and wastewater systems, energy providers, government services and facilities, healthcare institutions, and food and beverage sectors.