Media outlet Tech Times published some detailed coverage over the past few days about the hacking of U.S. drinking water systems in Minnesota and six other states. The cyber-attacks are believed to have originated in Iran. Iran is one of the top countries in the world involved in cyberattacks. The other top hacking countries are China, North Korea, Russia, and India.
“The Chinese hacking group Volt Typhoon spent at least
five years undetected inside a US critical infrastructure network before anyone
noticed. A separate Chinese group, Salt Typhoon, burrowed into at least nine
major American telecommunications carriers — including AT&T, Verizon, and
Lumen — and accessed the government's own law enforcement wiretap systems.
Senator Mark Warner called it the worst telecom hack in the nation's history.
Neither attack was stopped by the isolation plans that power grids, water
utilities, and telecoms had on paper.”
I know an IT manager for a large
law firm, and he says Chinese hacking is insidious.
The Center for Strategic
International Studies (CSIS), citing Congressional testimony from Emily
Harding, Vice President, Defense and Security Dept., Director, Intelligence,
National Security, and Technology Program, concluded in January 2026:
“A dramatic change is needed in the cyber domain.
Washington urgently needs to integrate cyber into its broader foreign policy
toolkit and determine how cyber activity aligns with larger foreign policy
actions, including deterrence, proportional response, and international norms.
In other words, the United States needs a new playbook to respond to
increasingly disruptive and aggressive cyberattacks.”
Meanwhile, after the attacks on
U.S. water systems, there have been some recommendations issued. Agencies such
as the US Cybersecurity and Infrastructure Security Agency (CISA), along with
counterparts from Australia, the UK, and Canada, are seeking to address the
issue of cyberattacks.
“On July 28, 2026, the US Cybersecurity and
Infrastructure Security Agency (CISA), Australia's signals intelligence
directorate, the UK's National Cyber Security Centre, and the Canadian Centre
for Cyber Security published a joint framework titled CI Fortify — Advice for
Isolating Vital Systems. Its core demand is simple and unambiguous: isolation
must be pre-engineered and tested before an attack arrives, not improvised
during one. But the guidance is voluntary. And experts named on record say cost
barriers will prevent most operators from actually building what the agencies
are asking for.”
CISA found that isolation
strategies are not working as designed and that inadequate preparation is
leading to vulnerabilities. The CI Fortify strategy they recommend involves
isolation and recovery of systems. Unfortunately, the urgency is real.
“Intelligence agencies have confirmed that
state-sponsored actors from China, Russia, and Iran have pre-positioned inside
US critical infrastructure networks with the specific purpose of enabling
disruption during a future geopolitical crisis.”
American aviation, rail, mass
transit, highway, maritime, pipeline, water, and power infrastructure has been
targeted by the Chinese state-sponsored group Volt Typhoon. Salt Typhoon, the
group that compromised American telecommunications companies, is also a Chinese
state-run hacking group.
“In April 2026, six federal agencies confirmed that
Iranian state actors had actively exploited internet-facing OT devices at
water, wastewater, energy, and government facilities, causing documented
operational disruptions and financial losses.”
Australia issued similar guidance
in October 2025, explicitly warning that isolation will break automated
business processes that cross the OT/IT boundary. OT stands for operational
technology. CISA issued similar guidance in May 2026. Also in May:
“Senator Ron Wyden demanded that CISA, the Office of
Management and Budget, and NIST impose a binding two-year deadline for federal
agencies to remove legacy VPN appliances and require zero-trust compliance from
vendors. The two initiatives address the same underlying problem — legacy
network architectures that create lateral movement opportunities for
adversaries — from different angles.”
The guidance also suggests that
companies be able "to operate, monitor, and update systems manually for
an indefinite period — potentially months.”
On July 29. Tech Times reported
that Iranian hackers exploited an unpatchable PLC flaw to breach 30 Minnesota
water systems. This happened on the nights of July 26 and 27. This resulted in
a temporary shutdown of one city's water treatment plant and triggered
emergency response at local, state, and federal levels. Cybersecurity experts
at Tenable believe the attack was perpetrated by CyberAv3ngers, a hacker group
associated with Iran’s Islamic Revolutionary Guard Corps. The attack targeted
Rockwell Automation controllers and included equipment from Siemens and
Schneider Electric.
"CISA's updated reporting shows a worrying
expansion in Iran-linked critical infrastructure targeting focused on the
United States," the agencies warned, urging water systems, energy
providers, and government facilities to remain on high alert, per CISA Advisory
AA26-097A.”
Small U.S. water utilities are
more vulnerable to cyber attacks than they should be and need to invest more in
cybersecurity. There are between 150,000 and 170,000 local water systems in the
U.S. Tech Times notes that CyberAv3ngers has systematically targeted U.S. water
infrastructure since 2020. Tenable believes the attacks are strongly consistent
with CyberAv3ngers MO, although Trump has suggested the attacks are somehow the
result of Minnesota’s government incompetence, even though six other states have
also been attacked. Oddly, Trump suggested Iran was not involved, which is
almost certainly incorrect. Minnesota’s governor, Tim Walz, suggested that
budget cuts to CISA were a factor. CISA cut one-third of its workforce under
the Trump administration cuts. CISA doesn’t currently have a Senate-confirmed
director, but an acting director, like many of Trump administration department
heads. The FBI is also probing whether another bad actor was simply making it
look like Iran was the perpetrator in a false flag attack, but frankly, that
does not seem likely to me, especially since Iran announced that it would do it
just days earlier.
More concerning is the FBI’s and
EPA’s assessment that cites a Minnesota law enforcement memo revealing “the
hackers' stated goal was not merely knocking systems offline — it was
contaminating the drinking water supply.” The goal was not merely to cause
a nuisance but to contaminate the water supply by manipulating control to drop
pressure enough to create backflows of untreated groundwater and even sewage.
This is known as back-siphonage. Water systems typically operate at 40-80psi.
Lowering the pressure to 20psi or below can initiate backflow. They note that
there is evidence that this was a goal. Iran even warned three days before the
attacks that they were targeting U.S. water infrastructure.
"The likely desired impact of the intrusion at the
water facilities was to cause loss of system pressure and subsequent potential
contamination of water supply," said a memo distributed this week by the
Minnesota Bureau of Criminal Apprehension and obtained by CNN.
The hackers did not succeed in
contaminating the water supply, but it could happen if the utilities are not
vigilant enough to notice and react quickly.
"CISA is currently observing a significant increase
in cyber threat actors targeting programmable logic controllers at water
utilities," said Nick Andersen, acting director of the Cybersecurity and
Infrastructure Security Agency. "We urge critical infrastructure owners
and operators to remove publicly exposed PLCs and other operational technology
from the internet as soon as possible," he added.
Below are recommendations from
CISA and the FBI:
References:
FBI:
Water hacks in seven states aimed at contaminating drinking supplies. Kyle
Belmonte. Tech Times. July 31, 2026. FBI:
Water hacks in seven states aimed at contaminating drinking supplies
China
and Iran Are Already Inside US Grids: CISA Demands Tested Isolation Plans: Windows
services embedded in OT networks will disable plant control when isolation cuts
them off. Brandon Fisher. Tech Times. July 29, 2026. China
and Iran Are Already Inside US Grids: CISA Demands Tested Isolation Plans
Iranian
Hackers Exploited Unpatchable PLC Flaw to Breach 30 Minnesota Water Systems: Tenable
suspects CyberAv3ngers; the CVE-2021-22681 flaw they exploited cannot be
patched. Kyle Belmonte. Tech Times. July 29, 2026. Iranian
Hackers Exploited Unpatchable PLC Flaw to Breach 30 Minnesota Water Systems
U.S.
Cyber Capabilities to Deter and Disrupt Malign Foreign Activity Targeting the
Homeland. V=Center for Strategic & International Studies. Emily Harding.
U.S.
Cyber Capabilities to Deter and Disrupt Malign Foreign Activity Targeting the
Homeland

No comments:
Post a Comment