A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran

3 hours ago 3

In its study connected the Minnesota h2o cyberattacks, Tenable pointed to an advisory from CISA that was initially released successful April but was updated past week, informing that Iran-linked actors were targeting programmable logic controllers (PLCs) utilized for automation and coordination successful captious infrastructure to origin “operational disruption and fiscal loss.” That advisory specifically pointed the digit astatine an “Iranian-affiliated” hacker radical and noted that CyberAv3ngers specifically had carried retired akin targeting of PLCs.

The updated advisory, however, inactive doesn’t notation the Minnesota attacks—only the timing of its update connected July 22 suggests a transportation to the much caller hacking of the state’s h2o utilities. The WaterISAC memo is the archetypal authoritative papers to explicitly gully that connection, tying the onslaught to Iran.

The WaterISAC memo states that, according to the Minnesota Fusion Center, the hackers who targeted the h2o utilities compromised remotely accessible PLCs, conscionable arsenic successful the earlier hacking run described by CISA, “with the apt desired interaction to origin nonaccomplishment of strategy unit and imaginable contamination of the h2o supply.” The memo adds that the facilities “were capable to mitigate further compromise, but the afloat interaction is inactive being assessed.”

In the aftermath of the cyberattacks earlier this week, Minnesota officials said that each drinking h2o is inactive safe, and statements from aggregate targeted municipalities emphasized that failsafes had protected the systems. “While the incidental affected definite automated controls, established contingency procedures were instantly implemented, allowing Public Works unit to support mean h2o and wastewater operations,” South St. Paul officials wrote successful a statement.

The CISA advisory that was updated past week, which specifically cited h2o and wastewater systems operators arsenic portion of the “intended audience” of its warning, noted that the attackers were exfiltrating and manipulating the task files that govern automated concern systems. The alert, which issued with a consortium of US national agencies including the FBI, the National Security Agency, Cyber Command, the Environmental Protection Agency, and the Department of Energy, primitively warned successful April that apt Iranian hackers were tampering with PLCs to alteration accusation connected the displays of concern power systems, which tin successful immoderate scenarios origin strategy disruption, damage, oregon unsafe conditions for utilities. “In a fewer cases, this enactment has resulted successful operational disruption and fiscal loss,” the advisory reads.

That advisory besides notes that akin activity, including the targeting of PLCs, was carried retired by CyberAv3ngers. That radical archetypal emerged successful a hacking run successful precocious 2023, aft Hamas’ October 7 attacks and Israel’s warfare connected Gaza that followed. In that archetypal question of cyberattacks, CyberAv3ngers targeted devices sold by concern power systems steadfast Unitronics, which are typically utilized successful h2o and wastewater facilities, mounting devices to work “Gaza” and show an representation of the CyberAv3ngers logo. While the attacks appeared to beryllium specified vandalism, cybersecurity firms that tracked the attacks specified arsenic Dragos and Claroty told WIRED that the hackers had successful information rewritten the Unitronics’ devices’ code, starring to disruption of water-related services from Israel to Ireland to a US installation successful Pittsburgh, Pennsylvania.

Read Entire Article