Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks

State and federal agencies are conducting an investigation after a coordinated cyberattack hit operational technology (OT) systems at dozens of water utilities in Minnesota.

According to Minnesota IT Services (MNIT), more than 30 community water systems were targeted on July 26 and 27.

Statements issued by some of the cities whose systems have been targeted – including Maple Plain, Braham, South St. Paul, and Plymouth – revealed that some “automated control functions” were affected. Still, contingency procedures were activated and in a majority of cases water and wastewater operations remained operational.

The City of Braham did briefly take its water plant offline after the cybersecurity incident was detected, urging residents to minimize water use. Braham revealed that the “attackers shut down the operating controls, which shut down the well and water treatment plant”.

Plymouth noted that “The issue is limited to equipment connected via cellular communications within the system.”

The affected cities all informed citizens that drinking water remains safe and water and wastewater services are operational.

Advertisement. Scroll to continue reading.

It’s unclear who is behind the attack, which comes shortly after the US government warned critical infrastructure organizations about Iran-linked attacks targeting industrial control systems (ICS) made by Siemens, Rockwell Automation, and Schneider Electric.

Iranian threat groups such as CyberAv3ngers and Handala would fit the profile for the attacks targeting Minnesota water systems. Still, investigators have not attributed the incidents to any specific actor, and officials have stressed that formal attribution has not been made.

“When I read about cyberattacks affecting water systems in Minnesota, my mind does not immediately go to attribution. It goes to the operator and the potential operational consequences,” commented Harry Thomas, CTO and co-founder of OT security firm Frenos. “In MITRE ATT&CK for ICS those consequences include denial or loss of view, denial or loss of control, and manipulation of view or control. A physical process may continue running even when operators can no longer see it, influence it, or trust what their screens are telling them.”

“Those distinctions matter,” Thomas added. “A denial of view or control can be temporary. A sustained loss may require hands-on intervention or manual operation. Manipulation can be even more dangerous because the process may be in a different state than what is being reported to the operator. From there, an incident can escalate into loss of availability, loss of protection, loss of safety, or physical damage.”

Denis Calderone, CTO of Suzu Labs, pointed to Plymouth’s statement that the impact is limited to equipment connected via cellular communications. 

“Water towers, lift stations, pump stations, these remote assets often connect back to the SCADA system over cellular modems, and in our experience secondary and/or alternative comm links are often overlooked when doing risk and vulnerability analysis, so it’s not too surprising then that the vector of attack may have been via these cellular connections,” Calderone said.

“Oftentimes, regarding SCADA and Industrial Control networks, the infrastructure is largely built out by the integrator which increases the chance that these connections get overlooked,” Calderone added. “We saw in the reporting that Braham’s city administrator is now asking for their system vulnerability study to be reevaluated, and I wouldn’t be surprised if that study never included those cellular communication paths in the first place.”

SecurityWeek ICS Cybersecurity Conference Heads to Nashville for Special 25-Year Anniversary Edition

It’s worth noting that in the 2020 attacks targeting water facilities in Israel, threat actors linked to the Iranian government exploited vulnerable cellular routers as a point of entry. 

Seemant Sehgal, founder & CEO of BreachLock, pointed out that investigators need to establish the common thread in the Minnesota water attacks because the same vulnerability “almost certainly exists in water infrastructure well beyond Minnesota”.

Related: Rockwell Patches Code Execution Flaws in Arena Simulation Software

Related: SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity

Related: Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *