ics-ottrade-pressNewsThe Broadside2 min read

CISA orders water utilities to pull internet-exposed ICS after Minnesota attacks

Second suspected Iran-linked strike on U.S. water infrastructure in 18 months, and utilities are still leaving PLCs wide open.


TL;DR

CISA issued a formal alert Thursday directing all U.S. water utilities to disconnect internet-exposed programmable logic controllers and industrial control systems. The order follows coordinated attacks on more than 30 Minnesota community water systems July 26, 27, which forced manual operations in several towns and triggered a boil-water notice in Braham. Investigators suspect Iran-aligned actors, though formal attribution remains pending. This is the second confirmed campaign against U.S. water infrastructure by suspected Iran-linked groups since the Aliquippa, Pennsylvania defacement in late 2023. The advisory reiterates guidance CISA and EPA have published repeatedly since November 2023 (most recently in a December 2024 joint fact sheet on exposed HMIs) which many utilities have ignored.

The attacks hit more than 30 systems in a single weekend. That's a campaign, not opportunistic scanning. And the response from CISA (a formal alert ordering internet-exposed PLCs taken offline) is language the agency rarely uses outside of active exploitation windows.

The Minnesota Fusion Center's memo to WaterISAC members says the activity is "aligned" with characteristics of an Iran-linked campaign CISA described in April. That advisory was quietly updated on July 22, four days before the Minnesota intrusions began. Investigators haven't released direct attribution evidence, but two officials told Nextgov/FCW the Iran connection is the working theory. One cautioned the investigation is still underway.

What actually happened on the ground

Braham, Minnesota lost controls for its well and water treatment plant. Other systems reverted to manual operation. No drinking-water contamination has been found, but boil-water notices went up in at least one community. These are the operational consequences CISA's been warning about since the Unitronics PLC exploitation advisory in November 2023. The playbook is consistent: find exposed HMIs or PLCs on Shodan, use default credentials or brute-force weak passwords, lock out the operator.

The part the press release won't say

CISA and EPA jointly told water utilities to secure internet-exposed HMIs in December 2024. They told them again in a March 2024 fact sheet listing "reduce exposure to the public-facing internet" as the number-one action. They told them in November 2023 after the Unitronics exploitation. The guidance hasn't changed. The exposure hasn't either.

One water-sector source told Nextgov/FCW, speaking anonymously: "If utilities are exposing programmable logic controllers to the public internet, and if the U.S. was a serious country, we'd shut down their operator and sell the utility operations to a competent entity." That's harsh. It's also hard to argue with after three years of the same advisory producing the same result.

The structural problem is real. Water utilities run aging equipment maintained by a patchwork of contractors across decades. Aurigo Software CISO Manish Sharma noted that cybersecurity has to be treated as an infrastructure requirement across the full asset lifecycle, planning, design, construction, commissioning, and replacement. Most municipal water authorities don't have that lifecycle, or the budget for it.

The geopolitical layer

This is the second confirmed water-infrastructure campaign by suspected Iran-linked actors in 18 months. The Aliquippa attack in late 2023 was a defacement, embarrassing but not operational. The Minnesota attacks disrupted actual water-system controls. If attribution firms up, it represents escalation beyond the hacktivist nuisance category and into operational sabotage.

The timing matters. A preliminary U.S.-Iran agreement was reached last month, but as Israel's top cyberdefense official told Nextgov/FCW in May: "There is no ceasefire in cyber." The Strait of Hormuz remains the central obstacle to a peace deal, and kinetic strikes resumed Wednesday. Cyber campaigns run on their own clock, one that doesn't pause for diplomacy.


Published ·Updated ·Deep Fathom