Skip to content
Tech News
← Back to articles

A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran

read original more articles
Why This Matters

The leaked memo highlighting Iran's cyberattacks on Minnesota water utilities underscores the increasing threat of state-sponsored cyber warfare targeting critical civilian infrastructure. This development signals a shift in the scope of cyber threats, emphasizing the need for enhanced cybersecurity measures across essential services to protect public safety and national security.

Key Takeaways

Since the US launched its war against Iran in late February, the country’s hackers have struck back with retaliatory intrusions that have ranged from paralyzing medical supplies company Stryker to breaching the personal email of FBI director Kash Patel. Now, after an unprecedented wave of disruptive cyberattacks hit water utilities in Minnesota, a memo circulated within the water industry ties those attacks to Iran, too, in the widest and most disruptive strike yet inflicted by the country’s hackers against the US since the war began.

A communication obtained by WIRED on Thursday and sent to members of the Water Information Sharing and Analysis Center, or WaterISAC, an industry group for water utilities to share cybersecurity information, links to Iran a series of cyberattacks that targeted dozens of Minnesota water and wastewater utilities.

The WaterISAC note states that the Minnesota Fusion Center, a state-level intelligence-sharing entity, issued an alert “regarding ongoing malicious cyber activity impacting public drinking water systems across Minnesota” and adds that the fusion center has found that those attacks were “aligned” with a hacking campaign first described in April by the US Cybersecurity and Infrastructure Security Agency (CISA) as having been carried out by “Iran-affiliated” hackers. (Both the WaterISAC and Minnesota Fusion Center reports were marked as unclassified but “for official use only.”)

Confirmation of Iran’s responsibility for hacking the water utilities represents a kind of state-sponsored targeting of civilian infrastructure that has rarely been seen outside of Russia’s war against Ukraine, says Joe Slowik, a former Los Alamos National Labs cybersecurity researcher working on contract for the Department of Energy. “Now we have documented disruption and even modification of safety and protection parameters in critical infrastructure,” Slowik says. “Seeing this sort of tradecraft expand to Iran, and seeing it across multiple sites, it should really be making people concerned right now.”

Slowik adds that there’s no reason to believe that the attacks would stop with the incidents in Minnesota. “There are plenty of other sites that have the same targeted technology,” he says. “There’s plenty of areas for this to still be executed by an adversary that has shown a willingness to do so.”

A new CISA advisory related to the attacks released Thursday warns that “these threat actors are targeting water entities of all sizes” and warns utilities to disconnect PLCs from the internet, password-protect access with strong passwords, and “allow-list” only trusted devices to connect to them.

Earlier this week, Minnesota state officials revealed that more than 30 municipal water and wastewater systems had been targeted in hacker breaches that had in some cases disabled telecommunications between the industrial control system technologies and water utility equipment. In at least one municipality, the 1,700-person city of Braham, the hacking reportedly led to a brief outage of the city’s water plant, though there’s not yet evidence of any resulting water shortages or a threat to the safety of Minnesota’s water supply. The latest CISA advisory notes that the attacks have, however, “resulted in boil-water notices”—suggesting fears of water contamination— and “sustained manual operations.”

In the days since that wave of incidents became public, Iran has emerged as the leading suspect behind the attacks, despite the lack of any official confirmation of the country’s involvement or any statement from an Iranian hacker group claiming responsibility. In a report published Monday, cybersecurity firm Tenable wrote that signs suggested CyberAv3ngers, an Iranian hacker group tied to the Iranian Revolutionary Guard Corps, may be responsible for the water utility breaches, noting that “the operational pattern is consistent with” the group or hacking groups associated with it. Separately, The New York Times reported Thursday that US and state officials and others familiar with the hacking incidents had concluded the Minnesota attacks were “likely” carried out by Iranian state-sponsored hackers, but without naming a specific group.