Minnesota and Michigan Supply Systems Hacked, FBI Launches Investigation

Earlier this week, over 30 water supply systems in Minnesota were targeted in a cyber attack. On Saturday (August 1st), Michigan reported that nine water supply systems also fell victim to network attacks, with officials reassuring the public that the systems are operating safely. The Federal Bureau of Investigation (FBI) is leading the investigation into the source of the cyber attacks. Meanwhile, there have been warnings that Iranian hackers have been continuously targeting water supply systems across various states in the United States.

In a statement released on Saturday, the FBI, responsible for the investigation, stated, “The FBI has noticed recent public reports about cyber attacks on water and wastewater systems. The FBI and its interagency partners are fully committed to protecting critical infrastructure, and we have the capability to defend against various types of cyber threats.”

According to reports from the Associated Press, Michigan had received a federal cybersecurity alert as early as Tuesday warning of attempts to alter water system operations. Shortly after, reports came in confirming attacks on nine water systems within the state.

Dale George, Communications Director of the Michigan Department of Environment, Great Lakes, and Energy, revealed in a statement that fortunately, the systems continue to operate securely. Operators have addressed the relevant issues, and there are currently no known threats that pose risks to public health.

On Thursday (July 30th), the FBI declined to disclose the potential culprits behind the attacks. However, the FBI, the Cybersecurity and Infrastructure Security Agency, along with other agencies, had previously warned in a joint advisory report that Iranian hackers have been targeting control systems of U.S. water and wastewater treatment facilities, as well as other critical infrastructure sectors.

In modern military conflicts, cyber warfare is becoming increasingly common, with water facilities and medical institutions in many areas becoming prime targets for cyber attacks. This is due to the lack of funds and expertise to install the latest software patches or take other security measures, making these systems not only relatively easy to infiltrate but also highly likely to cause immense panic once breached.

Iran has long set its sights on domestic water supply systems in the United States. In 2016, the U.S. Department of Justice charged Iranian hackers with launching a cyber attack on a small dam near New York City.

The Information Technology Services Division in Minnesota stated that as of Thursday, no requests had been received from residents to change their water consumption levels. Most confirmed attacks were related to the technical equipment used for remote monitoring and control of water supply systems. The report also mentioned that a network being attacked only indicates that investigators have detected malicious activity within the system’s technology and does not mean a disruption in water services.

On Monday, the city of Braham in Minnesota requested residents to conserve water for a few hours to investigate the reason for the water plant shutdown. A press release from the city government stated that the plant shutdown was due to a cyber attack but had no impact on water quality. Hackers had shut down the operational control systems of the wells and water treatment plants, causing the plant to rely on stored water in the water tower to supply residents temporarily.

Officials from the town of Plymouth in the suburbs of Minneapolis also disclosed that following a cyber attack, communication in the town’s water supply infrastructure was restored on Tuesday afternoon.