Advertisement

Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities

A cyberattack of undetermined origin disrupted water treatment plants in at least 30 communities in Minnesota, according to the state's technology bureau.
Listen to this article
0:00
Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment.
water treatment plant
(Getty Images)

More than 30 Minnesota communities saw their water and wastewater utilities disrupted by a coordinated cyberattack on Sunday and Monday, the state’s technology bureau announced Tuesday.

Among those was the City of Braham, a community of 1,700 people that brands itself the “Homemade Pie Capital of Minnesota.” Braham officials on Monday morning announced on the city website that its water plant was “offline for an unknown reason” and asked its residents to minimize water use because the city water tower held only a “limited quantity.” A second notice later that day noted that the plant was back online, explaining that the outage had been the result of “a malicious cyber-attack of computerized operating systems by unknown actors.”

A spokesperson from Plymouth, a Minneapolis suburb of about 80,000 people, explained in an email that the city’s IT division “disconnected the affected equipment from the network to stop the cyberattack and avoid any potential retargeting while the equipment is reconfigured.” In Plymouth’s case, the attack was limited to “equipment connected via cellular communications” at two city water towers and “multiple” lift stations. As in other communities, the official said water quality was unaffected — “the water is safe and there is no need for the public to adjust consumption.”

Minnesota Information Technology Services, the state technology agency, said its response efforts have included “sharing threat intelligence, providing guidance on response efforts and best practices, and helping affected utilities contain, investigate, and remediate damages from the attack.” The agency said it’s working with numerous other agencies, including its own public safety and health departments, and a state fusion center, along with federal agencies such as the Cybersecurity and Infrastructure Security Agency, the Environmental Protection Agency and FBI. John Israel, Minnesota’s chief information security officer, is quoted in a press release as saying that the “whole-of-government response” worked as intended, helping “prevent more serious impacts to critical services.”

Advertisement

The Minnesota state government and several local governments contacted for this story declined to comment on who attacked the state’s water utilities, though Iran is a reasonable guess. CISA and a cohort of other federal agencies last week updated an advisory “urgently” warning the nation of ongoing attempts by Iranian hacking groups, such as CyberAv3ngers, to target internet-connected operational technology devices, including programmable logic controllers. That warning “should give everyone nightmare fuel,” said Joshua Corman, an executive in residence at the Institute for Security and Technology, a nonprofit think tank focused on issues of national security and global stability.

There were also the U.S. strikes this month along Iran’s southern coast, near the Strait of Hormuz, that destroyed a water facility and cut off water access to more than 20,000 people as temperatures rose above 100 degrees Fahrenheit. The following day, the hacker group Hanzala claimed it had breached water utility systems in several California cities — including Bakersfield, Chico, Salinas and Stockton — as a warning to Washington. The group said it had restrained itself this time from disrupting the California communities’ water supplies.

“We have at least two [adversaries] whose motivation is not to steal information or to monetize their access, but rather to disrupt and destroy at a time and place of their choosing,” Corman, who heads an initiative at IST called UnDisruptable27, which aims to help water utilities improve their preparedness, said in an interview. “We are in a new place where we were always prone, we were always prey, but now they have an appetite to disrupt and destroy.” Corman said the other key adversary, China, is unlikely to direct its military to poison Americans by hacking water plants, “but a different predator might.”

TJ Sayers, senior director of threat intelligence at the nonprofit Center for Internet Security, affirmed that the Minnesota attacks have not yet been attributed to any particular party, and that “it is unclear” whether the attacks involved the programmable logic controllers CISA warned about. “Offense cyber activity of this nature is expected to greatly accelerate in the short-term with the continued release of frontier AI models, with a plateau expected in the mid to long-term as those same models are used to harden new and existing infrastructure code,” Sayers wrote in an emailed statement. Sayers also noted that, of the numerous nation-state attacks on U.S. water facilities in recent years, none has documented “major downstream health impacts.”

U.S. water utilities are a highly distributed network of some 150,000 to 170,000 systems, many of them small, rural and with few resources to defend themselves against cyberattacks or other disruptions. The EPA in 2024 warned that more than 70% of water systems were failing to comply with a provision of a 2018 law requiring them to develop or update risk assessments and emergency response plans, and to certify them with the environmental agency. An audit of 1,000 water systems serving 193 million people found 97 systems with critical- or high-risk vulnerabilities.

Advertisement

The national cyber drill, an annual event hosted by the EPA’s Office of Water Emergency Response and Cybersecurity, which is designed to boost emergency readiness, this month saw “a really tiny participation rate,” said Corman, the IST executive. He said the event asked participants who could operate their facilities for one day without their Supervisory Control and Data Acquisition, or SCADA, systems, the systems used to remotely monitor and control their plants. The answer, he said, was “not that many.”

As many water utilities continue on unprepared, attackers are equipping themselves with more powerful tools. Corman said frontier AI models are allowing malevolent groups to craft surprisingly plausible attack plans that could be carried out against utilities that had been outmatched to begin with. He urged the public and policymakers to update their mental models of what’s possible: “We have an unhealthy and unsound assumption that our stuff isn’t connected to the internet. And it’s not merely water. Water is life.” Corman said he’s especially worried about how an attack against a water utility could affect community hospitals, large consumers of water that could run out of reserves within “two to four hours” — “Many people could die in the hospitals that depend on that water very quickly.”

Latest Podcasts