U.S. officials are looking into whether Iran was behind a cyberattack on Minnesota water systems this week. More than 30 municipal water systems were hit.
No formal attribution has been made, according to CBS News, The Washington Post and NBC News.
The attacks happened Sunday and Monday. That is according to a statement from Minnesota IT Services.
The activity forced some utilities to switch to manual operations.
Most confirmed cases involved equipment used to remotely control water systems. That includes devices called programmable logic controllers, or PLCs. Minnesota IT Services shared those details.
No water supply has been compromised, officials said.
Mike Ernster is a public information officer for the Minnesota Department of Public Safety. He told CBS News the state's Bureau of Criminal Apprehension is working with cities and state and federal partners on the issue.
Emily Zimmer is a spokesperson for Minnesota's information technology agency. She said the breaches did not contaminate any city's water supply.
She said no residents have been asked to change their drinking water use.
U.S. intelligence agencies have assessed that Iran was likely behind the attack. That is according to several U.S. officials cited by The Washington Post.
A senior law enforcement official told NBC News the breach bears the hallmarks of Iran-backed hackers. But that official said the forensic work is still in early stages.
CBS News reported that investigators are also checking something else. They want to know if the hacker tried to look like Iran to stir tension during the current U.S.-Iran conflict.
Sources told CBS News their view could change as more evidence comes in.
Minnesota has not named a specific actor. "Attribution requires careful analysis of technical evidence alongside broader national and international threat intelligence, and our federal partners are best positioned to lead that work," Zimmer said, according to NBC News.
The FBI is leading the probe. It is working with federal, state and local partners.
"The FBI is aware of the incident and in contact with victims to resolve the matter," the bureau said in a statement to NBC News.
In South St. Paul, the city found an issue early Monday. It switched right away to manual operations, a city spokesperson told CBS News. Water and wastewater service kept running with no gaps. The city said drinking water quality, pressure and delivery were not hurt. It found no sign that resident data was accessed.
In Braham, public works staff found a problem Monday. They noticed the well that feeds the city's water tower had stopped working. Mayor Nate George said crews isolated the system, restored a backup and restarted the plant in about 90 minutes. Residents had no loss of water service, George said.
George said his city's response should be a warning to state leaders. He said local governments must defend key systems from foreign threats. He noted they often do this with few staff and old technology.
In Plymouth, officials found an outage Sunday evening. They spotted hacked PLCs at two water towers and 14 sewer lift stations, a city official told CBS News. Crews cut those devices off from the cellular network. The city moved to manual operations. Normal service came back by Tuesday afternoon. Officials said water quality and pressure were never hurt.
"I think you never expect it to happen to you," Michael Thompson, Plymouth's public works director, told CBS News.
The FBI, the Environmental Protection Agency and the Cybersecurity and Infrastructure Security Agency, or CISA, issued a joint warning Thursday. They said hackers are targeting exposed industrial controls at water and wastewater utilities. The agencies said this goes beyond Minnesota. They cited incidents in at least seven states, CBS News reported.
Nick Anderson is the acting director of CISA. He confirmed the agency is seeing a sharp rise in threats to water utility controllers. "We urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible," he said.
CISA also flagged a specific risk. Some water groups should check their outside connections. That is because the activity includes cell modems that may not show up in routine security scans.
Chris Butera holds the title of acting executive assistant director for cybersecurity at CISA. He told NBC News the agency "has consistently warned critical infrastructure stakeholders that Iranian-affiliated threat actors are conducting a range of targeted cyber activity."
Federal agencies have said before that hackers tied to Iran's Islamic Revolutionary Guard Corps (IRGC) hit several U.S. water plants in 2023. Those hackers used controllers that still had default passwords, CBS News reported.
Joe Slowik leads threat research at Dataminr. He told The Washington Post that hackers have hit water and energy systems across the country since the U.S.-Iran war began on Feb. 28. He linked the Minnesota case and others to a Revolutionary Guard unit known as the Cyber Electronic Command.
Kurt Gaudette leads intelligence at Dragos. He told The Washington Post the Minnesota attack fits a pattern seen in March. Hackers are targeting small utilities that use exposed controllers with default passwords.
He pointed to a 2023 hack at a water pumping station in Aliquippa, Pennsylvania. A group tied to the Revolutionary Guard, known as CyberAv3ngers, claimed that attack.
Alex Orleans leads threat intelligence at Sublime Security. He told The Washington Post that Iran's cyberattacks aim more at psychological impact than destruction. He said the goal is to sway American opinion and to show Iran's own leaders the hackers are helping the war effort.