Why Are Our Water Utilities Still So Exposed? The Minnesota Attacks Show a Systemic Problem.
The recurrence of this specific attack pattern against critical infrastructure is a persistent concern. Over 30 Minnesota water utilities just got hit with a coordinated cyberattack on their operational technology (OT) systems. Over a recent two-day period, we observed everything from a water plant going offline in Braham to cellular comms issues at water towers in Plymouth, and automated controls affected in South St. Paul and Maple Plain. While officials were quick to emphasize that drinking water remained safe, the inherent vulnerability of these systems to disruption warrants careful consideration. The recent incidents affecting Minnesota water utilities highlight a critical need for enhanced cybersecurity measures.
A common question arises regarding the internet connectivity of these critical systems, particularly in smaller municipalities. But the reality is, remote monitoring, operational efficiency, and the sheer cost of maintaining legacy infrastructure often necessitate the accessibility of these systems, presenting a complex trade-off.
How a Common Vulnerability Becomes a Coordinated Attack
The Minnesota IT Services (MNIT) agency confirmed a malicious cyber-attack on computerized operating systems, detailing the incident. In Braham, the water plant was restored within about three hours. Other communities switched to manual operations. MNIT's confirmation highlighted the 'coordinated' nature of the attacks, noting common timing, methods of access, and infrastructure targeted. This suggests not a series of bespoke attacks against individual utilities, but rather a single attacker or group exploiting a widespread vulnerability across multiple targets, including many Minnesota water utilities.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued multiple warnings regarding such threats, including recent advisories. CISA recently expanded an advisory about Iranian-affiliated actors targeting internet-facing Programmable Logic Controllers (PLCs) from Rockwell Automation, Schneider Electric, Siemens, and potentially other manufacturers. These actors, often linked to the CyberAv3ngers threat ecosystem (affiliated with Iran's Islamic Revolutionary Guard Corps Cyber-Electronic Command), have been exploiting exposed PLCs and Human-Machine Interfaces (HMIs) since at least 2023. These are the same types of systems found in many Minnesota water utilities.
The typical attack chain begins with Reconnaissance, where threat actors scan the internet for exposed PLCs. This leads to Initial Access, where attackers exploit known vulnerabilities or default/weak credentials on these internet-facing PLCs. CISA's April advisory, for example, specifically mentioned Iranian actors exploiting exposed Rockwell Automation/Allen-Bradley PLC devices. Once initial access is gained, the next stage is Manipulation. Attackers exfiltrate and modify project files, manipulate data through HMIs and SCADA systems, and can even disable shutdown and alarm logic. This is the phase where operational disruption occurs, such as changing pump speeds, opening valves, or, as observed in Braham, taking a plant offline.
While MNIT has not publicly attributed the Minnesota attacks, the observed timing and operational patterns align with tactics employed by groups such as CyberAv3ngers in other incidents. This strategy involves identifying a common weak point and then exploiting it across a broad range of targets.
The Real Impact on Minnesota Water Utilities: Disruption and the Hidden Costs
Fortunately, MNIT reported no requests for residents to change drinking water usage, indicating minimal immediate public health impact. The Braham plant was back online quickly, and other communities managed to maintain services through manual operations.
However, 'minimal impact' should not be confused with 'no impact,' as several significant consequences emerged. First, the incident constituted an Availability Incident. Systems went offline or automated controls were disrupted, forcing staff to switch to manual operations, which is both resource-intensive and stressful. Maple Plain, for instance, declared a local state of emergency.
Second, there was significant Operational Strain. Relying on manual operations, even for a few hours, places considerable demands on staff and resources, diverting attention from routine maintenance and other critical operations. Third, such incidents contribute to an Erosion of Trust. Every disruption, even if quickly resolved, can diminish public confidence in the reliability of critical infrastructure.
Finally, there is The Unseen Bill. The costs associated with incident response, forensic investigation, remediation, and hardening systems are substantial. For smaller municipalities, often operating on already constrained budgets, this can impose a severe financial burden. These utilities, like many Minnesota water utilities, frequently operate with limited funds, making it challenging to invest in modern cybersecurity practices or even fundamental network segmentation.
What We Do Now: Isolate, Inspect, and Validate Critical Systems
MNIT, in collaboration with federal partners like CISA, EPA, and FBI, is leading a statewide response, focusing on impact assessment, threat intelligence sharing, and direct assistance to affected utilities. CISA also recently published "CI Fortify – Advice for isolating vital systems," providing valuable guidance for securing these environments.
Utilities, particularly those with internet-facing OT, should prioritize immediate action. Gaining visibility is paramount: if PLCs or other OT devices utilize cellular modems for remote access, these connections must be logged. Tracking who connects, when, and from where provides fundamental visibility that is frequently overlooked. This is especially vital for Minnesota water utilities and similar small-to-medium critical infrastructure operators.
Access must also be restricted. Industrial controllers should only be accessible by authorized systems, necessitating proper network segmentation, robust firewalls, and strong access controls. Direct exposure to the public internet presents an unacceptable security posture.
Beyond access controls, inspecting running project files is crucial. Attackers frequently modify these to manipulate operations or disable safety features. Regular inspection for unauthorized changes, validated against known good backups, is a critical practice.
When restoration is necessary, backups must be validated thoroughly, as restoring a compromised backup only reintroduces the problem. Furthermore, for controllers equipped with a physical mode switch (e.g., Run/Program), this feature should be utilized. The switch should be placed in run mode only after project files are validated, thereby adding a physical layer of control that cannot be bypassed remotely, serving as an important failsafe.
These Minnesota water utilities attacks clearly remind us that critical infrastructure, particularly in smaller towns, remains a prime target. While the quick response was commendable, the underlying vulnerability points to a systemic issue we, as a nation, have yet to fully address. Reliance on manual overrides and temporary fixes is unsustainable.
A long-term solution necessitates a fundamental investment in securing these systems at their source, thereby increasing the difficulty for attackers to exploit widespread vulnerabilities. This involves prioritizing robust network segmentation to isolate critical OT, implementing strong multi-factor authentication for all access points, and establishing continuous monitoring capabilities to detect anomalous activity proactively, shifting from reactive incident response to a more resilient, proactive defense posture.