Water utility hacks now reach a dozen states as FBI probes PLC attacks

Iran-linked actors are the leading suspects in a campaign that has hit at least 12 states since late July.

CSBadmin
2 Min Read

The water sector attack wave that began in Minnesota late July has spread to at least 12 states, according to SecurityWeek, with the FBI investigating incidents across the country. Georgia and Michigan confirmed activity consistent with the intrusions that hit more than 30 Minnesota community water systems over July 26-27.

Nine Michigan water systems reported hostile activity to state authorities, with no public health consequences. Georgia confirmed it was affected but said damage was limited. The FBI advisory notes that since July 27, water and wastewater utilities in at least seven states have reported incidents, some degrading operations. The bureau has observed activity only against Rockwell Automation and Allen-Bradley programmable logic controllers, while a CISA advisory says Iran-affiliated actors are also targeting Schneider Electric and Siemens gear.

Researchers at Tenable were among the first to suspect Iran, citing similarities with past attacks by the IRGC-linked CyberAv3ngers group. The FBI has not publicly attributed the campaign. President Trump rejected the Iran theory and blamed Minnesota’s governor instead, drawing pushback from cyber professionals and from Governor Tim Walz, who pointed to federal funding cuts that left water facilities more exposed.

An OT security coalition is pressing Congress and CISA for action: reauthorize the State and Local Cybersecurity Grant Program, support the new DOE cyber office director, and renew the Cybersecurity Information Sharing Act authority expiring at the end of September. About 148,000 public water systems exist in the US, most with uneven security and little threat-intel sharing.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.