As the war in Iran drags on, Minnesota reported that at least 30 of its municipal water systems suffered a “coordinated cyberattack”. The report that came out in late July was followed by a Federal Bureau
of Investigation (FBI) warning that malicious cyber actors broke into water and wastewater systems in at least seven states of the United States.
The attack disrupted everyday operations, while also exposing cracks in crucial public service systems. Since the report surfaced, several states –– Georgia, New Jersey and South Dakota –– have reported similar cyberattacks. However, it is yet to be ascertained whether they are part of the attack unfolded in the seven states from the FBI’s list.
Although the Donald Trump–led administration previously accused the hackers allegedly aligned with Iran of orchestrating the cyberattacks, it yet remains to formally attribute the hacks to anyone.
A Glimpse Into US Water System
According to the government data, there are 1,52,000 public drinking water systems coupled with over 16,000 wastewater treatment facilities across the United States. Most municipalities receive their water from lakes, rivers, or underground water bodies.
The water is then moved by electric pumps through pipes before being dispatched to a treatment plant that filters out impurities and disinfect it. The treated water is supplied into storage tanks, and is distributed among houses, businesses, and public utility areas.
How Hackers Are Targeting Water Systems
Cybercriminals are targeting internet-facing programmable logic controllers (PLCs), which manage and monitor vital industrial processes at water facilities. These devices control functions such as water pressure and chemical dosing, helping ensure the safety of drinking water supplies, according to CNN.
According to William Akoto, Assistant Professor of Global Security at American University School of International Service, attackers scan internet addresses for controllers and outside companies to fetch remote access services.
After this, they eye a default or stolen password to log in before exploiting the vulnerability by changing a password or even issuing commands.
Now the question is: Is Iran carrying out these attacks?
According to a report by the CBS News, US officials are investigating whether the cyberattacks are linked to Iranian hackers. However, at a cabinet meeting last week, Trump accused Minnesota authorities of acting irresponsibly, leading to the hack.
“They like to say, ‘Oh, it’s Iran.’ Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota,” he said.
While there have been no reports pointing to corruption in the water systems, they have led to several disruptions requiring manual intervention and precautionary boil-water advisories.














