Monday, August 3, 2026

Cyber Attacks Against U.S. Water Infrastructure Linked to Iran, Lack of CISA Oversight, and Lack of Small Utility Readiness


  

      Media outlet Tech Times published some detailed coverage over the past few days about the hacking of U.S. drinking water systems in Minnesota and six other states. The cyber-attacks are believed to have originated in Iran. Iran is one of the top countries in the world involved in cyberattacks. The other top hacking countries are China, North Korea, Russia, and India.

The Chinese hacking group Volt Typhoon spent at least five years undetected inside a US critical infrastructure network before anyone noticed. A separate Chinese group, Salt Typhoon, burrowed into at least nine major American telecommunications carriers — including AT&T, Verizon, and Lumen — and accessed the government's own law enforcement wiretap systems. Senator Mark Warner called it the worst telecom hack in the nation's history. Neither attack was stopped by the isolation plans that power grids, water utilities, and telecoms had on paper.”

     I know an IT manager for a large law firm, and he says Chinese hacking is insidious.

     The Center for Strategic International Studies (CSIS), citing Congressional testimony from Emily Harding, Vice President, Defense and Security Dept., Director, Intelligence, National Security, and Technology Program, concluded in January 2026:

A dramatic change is needed in the cyber domain. Washington urgently needs to integrate cyber into its broader foreign policy toolkit and determine how cyber activity aligns with larger foreign policy actions, including deterrence, proportional response, and international norms. In other words, the United States needs a new playbook to respond to increasingly disruptive and aggressive cyberattacks.”

     Meanwhile, after the attacks on U.S. water systems, there have been some recommendations issued. Agencies such as the US Cybersecurity and Infrastructure Security Agency (CISA), along with counterparts from Australia, the UK, and Canada, are seeking to address the issue of cyberattacks.   

On July 28, 2026, the US Cybersecurity and Infrastructure Security Agency (CISA), Australia's signals intelligence directorate, the UK's National Cyber Security Centre, and the Canadian Centre for Cyber Security published a joint framework titled CI Fortify — Advice for Isolating Vital Systems. Its core demand is simple and unambiguous: isolation must be pre-engineered and tested before an attack arrives, not improvised during one. But the guidance is voluntary. And experts named on record say cost barriers will prevent most operators from actually building what the agencies are asking for.

     CISA found that isolation strategies are not working as designed and that inadequate preparation is leading to vulnerabilities. The CI Fortify strategy they recommend involves isolation and recovery of systems. Unfortunately, the urgency is real.

Intelligence agencies have confirmed that state-sponsored actors from China, Russia, and Iran have pre-positioned inside US critical infrastructure networks with the specific purpose of enabling disruption during a future geopolitical crisis.”

     American aviation, rail, mass transit, highway, maritime, pipeline, water, and power infrastructure has been targeted by the Chinese state-sponsored group Volt Typhoon. Salt Typhoon, the group that compromised American telecommunications companies, is also a Chinese state-run hacking group.

In April 2026, six federal agencies confirmed that Iranian state actors had actively exploited internet-facing OT devices at water, wastewater, energy, and government facilities, causing documented operational disruptions and financial losses.”

     Australia issued similar guidance in October 2025, explicitly warning that isolation will break automated business processes that cross the OT/IT boundary. OT stands for operational technology. CISA issued similar guidance in May 2026. Also in May:

Senator Ron Wyden demanded that CISA, the Office of Management and Budget, and NIST impose a binding two-year deadline for federal agencies to remove legacy VPN appliances and require zero-trust compliance from vendors. The two initiatives address the same underlying problem — legacy network architectures that create lateral movement opportunities for adversaries — from different angles.”

     The guidance also suggests that companies be able "to operate, monitor, and update systems manually for an indefinite period — potentially months.”

     On July 29. Tech Times reported that Iranian hackers exploited an unpatchable PLC flaw to breach 30 Minnesota water systems. This happened on the nights of July 26 and 27. This resulted in a temporary shutdown of one city's water treatment plant and triggered emergency response at local, state, and federal levels. Cybersecurity experts at Tenable believe the attack was perpetrated by CyberAv3ngers, a hacker group associated with Iran’s Islamic Revolutionary Guard Corps. The attack targeted Rockwell Automation controllers and included equipment from Siemens and Schneider Electric.

"CISA's updated reporting shows a worrying expansion in Iran-linked critical infrastructure targeting focused on the United States," the agencies warned, urging water systems, energy providers, and government facilities to remain on high alert, per CISA Advisory AA26-097A.”

     Small U.S. water utilities are more vulnerable to cyber attacks than they should be and need to invest more in cybersecurity. There are between 150,000 and 170,000 local water systems in the U.S. Tech Times notes that CyberAv3ngers has systematically targeted U.S. water infrastructure since 2020. Tenable believes the attacks are strongly consistent with CyberAv3ngers MO, although Trump has suggested the attacks are somehow the result of Minnesota’s government incompetence, even though six other states have also been attacked. Oddly, Trump suggested Iran was not involved, which is almost certainly incorrect. Minnesota’s governor, Tim Walz, suggested that budget cuts to CISA were a factor. CISA cut one-third of its workforce under the Trump administration cuts. CISA doesn’t currently have a Senate-confirmed director, but an acting director, like many of Trump administration department heads. The FBI is also probing whether another bad actor was simply making it look like Iran was the perpetrator in a false flag attack, but frankly, that does not seem likely to me, especially since Iran announced that it would do it just days earlier.

     More concerning is the FBI’s and EPA’s assessment that cites a Minnesota law enforcement memo revealing “the hackers' stated goal was not merely knocking systems offline — it was contaminating the drinking water supply.” The goal was not merely to cause a nuisance but to contaminate the water supply by manipulating control to drop pressure enough to create backflows of untreated groundwater and even sewage. This is known as back-siphonage. Water systems typically operate at 40-80psi. Lowering the pressure to 20psi or below can initiate backflow. They note that there is evidence that this was a goal. Iran even warned three days before the attacks that they were targeting U.S. water infrastructure.

"The likely desired impact of the intrusion at the water facilities was to cause loss of system pressure and subsequent potential contamination of water supply," said a memo distributed this week by the Minnesota Bureau of Criminal Apprehension and obtained by CNN.

     The hackers did not succeed in contaminating the water supply, but it could happen if the utilities are not vigilant enough to notice and react quickly.

"CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers at water utilities," said Nick Andersen, acting director of the Cybersecurity and Infrastructure Security Agency. "We urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible," he added.

     Below are recommendations from CISA and the FBI:

 





References:

 

FBI: Water hacks in seven states aimed at contaminating drinking supplies. Kyle Belmonte. Tech Times. July 31, 2026. FBI: Water hacks in seven states aimed at contaminating drinking supplies

China and Iran Are Already Inside US Grids: CISA Demands Tested Isolation Plans: Windows services embedded in OT networks will disable plant control when isolation cuts them off. Brandon Fisher. Tech Times. July 29, 2026. China and Iran Are Already Inside US Grids: CISA Demands Tested Isolation Plans

Iranian Hackers Exploited Unpatchable PLC Flaw to Breach 30 Minnesota Water Systems: Tenable suspects CyberAv3ngers; the CVE-2021-22681 flaw they exploited cannot be patched. Kyle Belmonte. Tech Times. July 29, 2026. Iranian Hackers Exploited Unpatchable PLC Flaw to Breach 30 Minnesota Water Systems

U.S. Cyber Capabilities to Deter and Disrupt Malign Foreign Activity Targeting the Homeland. V=Center for Strategic & International Studies. Emily Harding. U.S. Cyber Capabilities to Deter and Disrupt Malign Foreign Activity Targeting the Homeland

No comments:

Post a Comment

       Kathleen "Katie" McGinty, Vice President and Chief Sustainability and External Relations Officer for Johnson Controls, ar...