Since the US launched its war against Iran in late February, the country’s hackers have struck back with retaliatory intrusions that have ranged from paralyzing medical supplies company Stryker to breaching the personal email of FBI director Kash Patel. Now, after an unprecedented wave of disruptive cyberattacks hit water utilities in Minnesota, a memo circulated within the water industry ties those attacks to Iran, too, in the widest and most disruptive strike yet inflicted by the country’s hackers against the US since the war began.A communication obtained by WIRED on Thursday and sent to members of the Water Information Sharing and Analysis Center, or WaterISAC, an industry group for water utilities to share cybersecurity information, links to Iran a series of cyberattacks that targeted dozens of Minnesota water and wastewater utilities.The WaterISAC note states that the Minnesota Fusion Center, a state-level intelligence-sharing entity, issued an alert “regarding ongoing malicious cyber activity impacting public drinking water systems across Minnesota” and adds that the fusion center has found that those attacks were “aligned” with a hacking campaign first described in April by the US Cybersecurity and Infrastructure Security Agency (CISA) as having been carried out by “Iran-affiliated” hackers. (Both the WaterISAC and Minnesota Fusion Center reports were marked as unclassified but “for official use only.”)Confirmation of Iran’s responsibility for hacking the water utilities represents a kind of state-sponsored targeting of civilian infrastructure that has rarely been seen outside of Russia’s war against Ukraine, says Joe Slowik, a former Los Alamos National Labs cybersecurity researcher working on contract for the Department of Energy. “Now we have documented disruption and even modification of safety and protection parameters in critical infrastructure,” Slowik says. “Seeing this sort of tradecraft expand to Iran, and seeing it across multiple sites, it should really be making people concerned right now.”Slowik adds that there’s no reason to believe that the attacks would stop with the incidents in Minnesota. “There are plenty of other sites that have the same targeted technology,” he says. “There’s plenty of areas for this to still be executed by an adversary that has shown a willingness to do so.”A new CISA advisory related to the attacks released Thursday warns that “these threat actors are targeting water entities of all sizes” and warns utilities to disconnect PLCs from the internet, password-protect access with strong passwords, and “allow-list” only trusted devices to connect to them.Earlier this week, Minnesota state officials revealed that more than 30 municipal water and wastewater systems had been targeted in hacker breaches that had in some cases disabled telecommunications between the industrial control system technologies and water utility equipment. In at least one municipality, the 1,700-person city of Braham, the hacking reportedly led to a brief outage of the city’s water plant, though there’s not yet evidence of any resulting water shortages or a threat to the safety of Minnesota’s water supply. The latest CISA advisory notes that the attacks have, however, “resulted in boil-water notices”—suggesting fears of water contamination— and “sustained manual operations.”In the days since that wave of incidents became public, Iran has emerged as the leading suspect behind the attacks, despite the lack of any official confirmation of the country’s involvement or any statement from an Iranian hacker group claiming responsibility. In a report published Monday, cybersecurity firm Tenable wrote that signs suggested CyberAv3ngers, an Iranian hacker group tied to the Iranian Revolutionary Guard Corps, may be responsible for the water utility breaches, noting that “the operational pattern is consistent with” the group or hacking groups associated with it. Separately, The New York Times reported Thursday that US and state officials and others familiar with the hacking incidents had concluded the Minnesota attacks were “likely” carried out by Iranian state-sponsored hackers, but without naming a specific group.In its report on the Minnesota water cyberattacks, Tenable pointed to an advisory from CISA that was initially released in April but was updated last week, warning that Iran-linked actors were targeting programmable logic controllers (PLCs) used for automation and coordination in critical infrastructure to cause “operational disruption and financial loss.” That advisory specifically pointed the finger at an “Iranian-affiliated” hacker group and noted that CyberAv3ngers specifically had carried out similar targeting of PLCs.The updated advisory, however, still doesn’t mention the Minnesota attacks—only the timing of its update on July 22 suggests a connection to the more recent hacking of the state’s water utilities. The WaterISAC memo is the first official document to explicitly draw that connection, tying the attack to Iran.The WaterISAC memo states that, according to the Minnesota Fusion Center, the hackers who targeted the water utilities compromised remotely accessible PLCs, just as in the earlier hacking campaign described by CISA, “with the likely desired impact to cause loss of system pressure and potential contamination of the water supply.” The memo adds that the facilities “were able to mitigate further compromise, but the full impact is still being assessed.”In the wake of the cyberattacks earlier this week, Minnesota officials said that all drinking water is still safe, and statements from multiple targeted municipalities emphasized that failsafes had protected the systems. “While the incident affected certain automated controls, established contingency procedures were immediately implemented, allowing Public Works staff to maintain normal water and wastewater operations,” South St. Paul officials wrote in a statement.The CISA advisory that was updated last week, which specifically cited water and wastewater systems operators as part of the “intended audience” of its warning, noted that the attackers were exfiltrating and manipulating the project files that govern automated industrial systems. The alert, which issued with a consortium of US federal agencies including the FBI, the National Security Agency, Cyber Command, the Environmental Protection Agency, and the Department of Energy, originally warned in April that likely Iranian hackers were tampering with PLCs to change information on the displays of industrial control systems, which can in some scenarios cause system disruption, damage, or dangerous conditions for utilities. “In a few cases, this activity has resulted in operational disruption and financial loss,” the advisory reads.That advisory also notes that similar activity, including the targeting of PLCs, was carried out by CyberAv3ngers. That group first emerged in a hacking campaign in late 2023, after Hamas’ October 7 attacks and Israel’s war on Gaza that followed. In that first wave of cyberattacks, CyberAv3ngers targeted devices sold by industrial control systems firm Unitronics, which are typically used in water and wastewater facilities, setting devices to read “Gaza” and display an image of the CyberAv3ngers logo. While the attacks appeared to be mere vandalism, cybersecurity firms that tracked the attacks such as Dragos and Claroty told WIRED that the hackers had in fact rewritten the Unitronics’ devices’ code, leading to disruption of water-related services from Israel to Ireland to a US facility in Pittsburgh, Pennsylvania.Even after the US State Department offered a $10 million bounty for information about the group and the US Treasury sanctioned six IRGC officials alleged to be linked to it, CyberAv3ngers’ attacks continued to escalate. According to Dragos, it went on to breach a US oil and gas company in 2024 and then to carry out a widespread hacking campaign infecting industrial control and internet-of-things devices with a piece of malware known as IOControl.Whether CyberAv3ngers is behind the cyberattacks on the Minnesota water utilities remains far from clear. In an interview with WIRED, Yhonatan Harari, a researcher at the cybersecurity firm Claroty, said the company had found other evidence that the attacks might have been carried out by Handala, a distinct hacker group that claimed responsibility for the Stryker cyberattack in March, the breach of Kash Patel’s email later the same month, and numerous other disruptive hacking incidents.Despite that uncertainty, Harari says that all signs point to Iran as the culprit. “We’re not sure yet if it’s CyberAv3ngers or Handala,” Harari says, “but in a very high likelihood we can say it’s Iranian actors.”The string of attacks on the Minnesota utilities does, however, closely fit the modus operandi of CyberAv3ngers, which has established itself as a rare state-sponsored hacker group that has shown its willingness to not only target but also sabotage industrial control systems—and water in particular.“They definitely have the capability; they have the intent,” Dragos cybersecurity researcher Kyle O’Meara told WIRED about CyberAv3ngers last year. “They have the interest in learning how to shut things off and potentially cause harm.”Additional reporting by Lily Hay Newman.
A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran
Full Article
Original Source
Read the full article at Wired →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.