24.7 C
New York

Wararka: A Leaked Memo Ties Cyberattacks on Minnesota Water Utiliti…

Published:

Since the US launched its war against Iran in late February, the country’s hackers have struck back with retaliatory intrusions that have ranged from paralyzing medical supplies company Stryker to breaching the personal email of FBI director Kash Patel. Now, after an unprecedented wave of disruptive cyberattacks hit water utilities in Minnesota, a memo circulated within the water industry ties those attacks to Iran, too, in the widest and most disruptive strike yet inflicted by the country’s hackers against the US since the war began.

News

A communication obtained by WIRED on Thursday and sent to members of the Water Information Sharing and Analysis Center, or WaterISAC, an industry group for water utilities to share cybersecurity information, links to Iran a series of cyberattacks that targeted dozens of Minnesota water and wastewater utilities.

The WaterISAC note states that the Minnesota Fusion Center, a state-level intelligence-sharing entity, issued an alert “regarding ongoing malicious cyber activity impacting public drinking water systems across Minnesota” and adds that the fusion center has found that those attacks were “aligned” with a hacking campaign first described in April by the US Cybersecurity and Infrastructure Security Agency (CISA) as having been carried out by “Iran-affiliated” hackers. (Both the WaterISAC and Minneso

Confirmation of Iran’s responsibility for hacking the water utilities represents a kind of state-sponsored targeting of civilian infrastructure that has rarely been seen outside of Russia’s war against Ukraine, says Joe Slowik, a former Los Alamos National Labs cybersecurity researcher working on contract for the Department of Energy. “Now we have documented disruption and even modification of safety and protection parameters in critical infrastructure,” Slowik says. “Seeing this sort of tradecr

Details

Slowik adds that there’s no reason to believe that the attacks would stop with the incidents in Minnesota. “There are plenty of other sites that have the same targeted technology,” he says. “There’s plenty of areas for this to still be executed by an adversary that has shown a willingness to do so.”

A new CISA advisory related to the attacks released Thursday warns that “these threat actors are targeting water entities of all sizes” and warns utilities to disconnect PLCs from the internet, password-protect access with strong passwords, and “allow-list” only trusted devices to connect to them.

Earlier this week, Minnesota state officials revealed that more than 30 municipal water and wastewater systems had been targeted in hacker breaches that had in some cases disabled telecommunications between the industrial control system technologies and water utility equipment. In at least one municipality, the 1,700-person city of Braham, the hacking reportedly led to a brief outage of the city’s water plant, though there’s not yet evidence of any resulting water shortages or a threat to the sa

Analysis

In the days since that wave of incidents became public, Iran has emerged as the leading suspect behind the attacks, despite the lack of any official confirmation of the country’s involvement or any statement from an Iranian hacker group claiming responsibility. In a report published Monday, cybersecurity firm Tenable wrote that signs suggested CyberAv3ngers, an Iranian hacker group tied to the Iranian Revolutionary Guard Corps, may be responsible for the water utility breaches, noting that “the

In its report on the Minnesota water cyberattacks, Tenable pointed to an advisory from CISA that was initially released in April but was updated last week, warning that Iran-linked actors were targeting programmable logic controllers (PLCs) used for automation and coordination in critical infrastructure to cause “operational disruption and financial loss.” That advisory specifically pointed the finger at an “Iranian-affiliated” hacker group and noted that CyberAv3ngers specifically had carried o

The updated advisory, however, still doesn’t mention the Minnesota attacks—only the timing of its update on July 22 suggests a connection to the more recent hacking of the state’s water utilities. The WaterISAC memo is the first official document to explicitly draw that connection, tying the attack to Iran.

Stay informed with the latest news on Wararka.so — your trusted source for Somalia and world news.

Related articles

Recent articles

spot_img