Thursday, July 30, 2026
Google search engine
HomeGadgetsA Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran

A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran


In its report on the Minnesota water cyberattacks, Tenable pointed to an advisory from CISA that was initially released in April but was updated last week, warning that Iran-linked actors were targeting programmable logic controllers (PLCs) used for automation and coordination in critical infrastructure to cause “operational disruption and financial loss.” That advisory specifically pointed the finger at an “Iranian-affiliated” hacker group and noted that CyberAv3ngers specifically had carried out similar targeting of PLCs.

The updated advisory, however, still doesn’t mention the Minnesota attacks—only the timing of its update on July 22 suggests a connection to the more recent hacking of the state’s water utilities. The WaterISAC memo is the first official document to explicitly draw that connection, tying the attack to Iran.

The WaterISAC memo states that, according to the Minnesota Fusion Center, the hackers who targeted the water utilities compromised remotely accessible PLCs, just as in the earlier hacking campaign described by CISA, “with the likely desired impact to cause loss of system pressure and potential contamination of the water supply.” The memo adds that the facilities “were able to mitigate further compromise, but the full impact is still being assessed.”

In the wake of the cyberattacks earlier this week, Minnesota officials said that all drinking water is still safe, and statements from multiple targeted municipalities emphasized that failsafes had protected the systems. “While the incident affected certain automated controls, established contingency procedures were immediately implemented, allowing Public Works staff to maintain normal water and wastewater operations,” South St. Paul officials wrote in a statement.

The CISA advisory that was updated last week, which specifically cited water and wastewater systems operators as part of the “intended audience” of its warning, noted that the attackers were exfiltrating and manipulating the project files that govern automated industrial systems. The alert, which issued with a consortium of US federal agencies including the FBI, the National Security Agency, Cyber Command, the Environmental Protection Agency, and the Department of Energy, originally warned in April that likely Iranian hackers were tampering with PLCs to change information on the displays of industrial control systems, which can in some scenarios cause system disruption, damage, or dangerous conditions for utilities. “In a few cases, this activity has resulted in operational disruption and financial loss,” the advisory reads.

That advisory also notes that similar activity, including the targeting of PLCs, was carried out by CyberAv3ngers. That group first emerged in a hacking campaign in late 2023, after Hamas’ October 7 attacks and Israel’s war on Gaza that followed. In that first wave of cyberattacks, CyberAv3ngers targeted devices sold by industrial control systems firm Unitronics, which are typically used in water and wastewater facilities, setting devices to read “Gaza” and display an image of the CyberAv3ngers logo. While the attacks appeared to be mere vandalism, cybersecurity firms that tracked the attacks such as Dragos and Claroty told WIRED that the hackers had in fact rewritten the Unitronics’ devices’ code, leading to disruption of water-related services from Israel to Ireland to a US facility in Pittsburgh, Pennsylvania.



Source link

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -
Google search engine

Most Popular

Recent Comments