A preliminary analysis by U.S. investigators concluded that Iranian hackers were probably behind a cyberattack targeting dozens of municipal water systems in Minnesota this week, an escalation in Iran’s retaliatory moves sprouting from the war.Tenable, the security firm investigating around 30 cyberattacks on water management infrastructure from Sunday to Monday, was careful not to explicitly attribute the attack to any one group, but noted that the attack pattern was consistent with that of the faux hacktivist group “CyberAv3ngers,” a group the U.S. government says is a front for the Islamic Revolutionary Guard Corps Cyber-Electronic Command. The cyberattacks were aimed at wells and treatment plants, specifically targeting automated systems and plants’ computer systems.
In all cases, the attacks didn’t affect the quality of the water supplies. The most severe targeted the 1,700-member community of Braham, disabling its well and water treatment plant’s computerized operating controls for about two hours. The city of Plymouth’s IT division disconnected its cellular-connected equipment at two water towers and multiple wastewater stations in fear of a wider compromise, fixing it with manual procedures. Some automated water utility controls were compromised in South St. Paul, while Maple Plain declared a local state of emergency to manage a similar attack.










