OTHER

What We Understand About the Alleged Iranian Cyberattacks Targeting U.S. Water Utilities

Since the end of last month, numerous water utilities across the United States have been targeted by cyberattacks, sparking significant concerns nationwide.

For many years, hackers—whether state-sponsored or independent—have focused on water utilities and other critical infrastructure, particularly in the energy sector. What heightens the alarm regarding these recent attacks—reportedly carried out by Iranian operatives—is their extensive impact, affecting facilities in nearly a dozen states.

The U.S. is home to more than 150,000 water systems, many of which are operated by local entities. This should, in theory, complicate the hackers’ efforts to attack multiple sites simultaneously. However, the downside is that these operating companies often lack the necessary resources or cybersecurity expertise to effectively defend against such threats.

Cybersecurity experts have long asserted that Iranian hackers tend to exploit easily accessible targets in isolated incidents; thus, this coordinated hacking campaign may signify a substantial escalation.

Since the initial reports of these attacks emerged two weeks ago, numerous developments have occurred. Therefore, we believe it is an appropriate moment to summarize what is known thus far, alongside what remains unclear.

Where have there been attacks?

On July 28, authorities in Minnesota announced that water treatment facilities in over 30 communities had been the targets of coordinated cyberattacks.

Just two days later, the FBI reported that water and wastewater utility companies in “at least seven states” had experienced incidents, with some attacks leading to degraded water operations. Similar hacks have been documented in Arkansas, Georgia, New Jersey, and Michigan, in addition to Minnesota.

Who is behind the attacks?

The short answer remains uncertain: the identities of the perpetrators are still unknown, but the leading suspect is the Iranian government.

Currently, the U.S. government has not officially identified the source of this wave of coordinated hacks.

However, the initial incidents in Minnesota occurred shortly after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued warnings about Iranian hackers targeting internet-connected devices in both water systems and the energy sector, although they did not specify the locations of these attacks. (CISA’s warning was first issued in April and updated just prior to the Minnesota incidents.)

Following the preliminary attacks in Minnesota, former President Donald Trump expressed skepticism regarding the idea of an Iranian cyberattack, instead attributing the situation to state management under Democratic Governor Tim Walz, who is the vice presidential candidate for Kamala Harris in the 2024 elections.

Trump’s comments came a day after Wired reported that the Water Information Sharing and Analysis Center (WaterISAC), a nonprofit organization that disseminates cybersecurity information within the water sector, indicated that the recent attacks “aligned” with the hacking campaign highlighted by CISA—essentially implicating the Iranian government.

Earlier this week, The Washington Post disclosed that U.S. intelligence agencies are “confident” that Iran—specifically the Islamic Revolutionary Guard Corps (IRGC)—is responsible for the attacks. However, according to the paper’s sources, this attribution has yet to be made public as the agencies are still uncertain about which specific unit within the IRGC is accountable and may also wish to avoid contradicting Trump’s statements.

Iranian state-sponsored hackers have a documented history of targeting critical infrastructure in the U.S., and these recent attacks may serve as retaliation for ongoing tensions related to the six-month war.

Up until now, Iranian hackers have had limited success with their cyber initiatives against U.S. targets. In March, a hacktivist group known as Handala disrupted operations for the medical technology company Stryker. The U.S. later alleged that Handala was operated by Iran’s Ministry of Intelligence and Security (MOIS). The group also claimed responsibility for hacking the personal Gmail account of FBI Director Kash Patel.

What effects have the attacks had?

The reality is that certain systems within critical infrastructure are exposed to the internet and relatively easy to identify. Earlier this month, cybersecurity firm Forescout reported finding over 2,800 controllers in U.S. water systems that are accessible online. Just because a system is exposed does not mean hackers can gain control and cause significant consequences. However, there have been isolated instances of such outcomes in recent attacks.

The FBI noted that some of the cyberattacks nationwide caused pressure loss, which “could potentially allow untreated groundwater to infiltrate pipes,” in addition to flooding.

The city of Braham in Minnesota, one of the first to report a breach, had to temporarily shut down its water plant, advising its approximately 1,700 residents to conserve water. The city of Maple Plain, also in Minnesota, briefly declared a state of emergency. In a county outside Atlanta, Georgia, local authorities temporarily advised residents to boil water before consumption as a precaution.

However, the most damaging impact may be psychological. Extensive coverage of these attacks in both national and local media has led to public anxiety regarding the safety of a basic necessity, like water. This could very well be a part of the hackers’ intent: to instill panic and fear.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.