A federal cybersecurity agency warned water systems throughout the United States on July 30 of an increase in threats to water and wastewater systems.
Minnesota IT Services activated emergency protocols immediately after the attacks on July 26 and July 27, and began an investigation that continues this week.
Among the communities affected by the breach was the city of Braham, also known as the “Homemade Pie Capital of Minnesota.” City officials announced its water plant was “offline for an unknown reason” at about 9:30 a.m. on July 27. The water was back online two hours later.
The FBI is investigating this week’s cyberattack in Minnesota but has not publicly identified what organization was responsible.
The agencies advised water systems to check operation programs manufactured by Rockwell Automation, Schneider Electric, Siemens, and other manufacturers.
In its latest alert July 30, CISA urged critical infrastructure owners, operators, and integrators to remove computer-automated systems and other technology from the internet as soon as possible.
Hackers targeting the systems have changed passwords to lock out operators and disconnected the systems by changing their IP addresses. The activity resulted in boil water notices and manual operations, CISA warned.
Water systems with proven cybersecurity systems were still encouraged to validate their external connections.
Targets for the threat actors include cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine scans, the agency said.
Tenable, a security exposure management company, theorized the cyberattack in Minnesota related to the escalating Iran conflict.







