Federal officials are sounding the alarm over a string of cyberattacks targeting water utilities after more than 30 community water systems in Minnesota were compromised, with investigators examining whether hackers linked to Iran were involved.
The Cybersecurity and Infrastructure Security Agency issued an alert Thursday warning that cyber threat actors have been targeting programmable logic controllers, or PLCs, and changing passwords “to lock out operators.”
“This activity has resulted in boil water notices and sustained manual operations,” CISA said.
The warning came just days after Minnesota officials disclosed that water systems across the state were hit by cyberattacks on Sunday and Monday.
Multiple U.S. officials told ABC News investigators are looking into whether Iran or hackers associated with the country carried out the attacks. They cautioned that the forensic review remains ongoing and that the U.S. government has not formally attributed the intrusions to any specific actor.
The New York Times first reported authorities were investigating possible Iranian ties.
Minnesota IT Services said the attacks targeted systems used to remotely monitor and control critical equipment, including PLCs that help operate water infrastructure.
“In this situation, ‘impacted’ means investigators confirmed malicious activity involving a system’s technology. It does not mean every affected community experienced a disruption to water service,” the agency said in a statement.
POLL: Will You Support Trump And His Candidates In The Midterms?
State officials said there are currently no requests for residents to change their water use.
“We have provided relevant information to the federal government, which is evaluating this activity in the broader national context and leading efforts to determine whether it can be attributed to a specific threat actor,” Minnesota Chief Information Security Officer John Israel said in a statement.
The FBI said it is aware of the intrusions but has not assigned responsibility for the attacks.
The incidents resemble previous cyber campaigns that have targeted U.S. critical infrastructure, including water utilities, through internet-connected industrial control systems. Federal officials have repeatedly warned that Iran-linked hackers have sought to exploit those types of systems in the past.
CISA urged water utilities to strengthen their defenses by disconnecting internet-facing PLCs whenever possible. If remote access is required, the agency advised operators to route connections through a VPN or secure gateway device to reduce the risk of additional attacks.
POLL: Ilhan Omar Now Claims She’s Broke – Do You Believe Her?