Back to all lessons
Awareness Lessons
2 months ago

Coordinated OT Attacks Hit 30+ Minnesota Water Utilities via Cellular Links

A coordinated cyberattack targeting operational technology (OT) systems at over 30 Minnesota water and wastewater utilities exposed a critical weakness: remote infrastructure assets relying on cellular communication links with insufficient security controls. Threat actors, potentially linked to Iranian groups CyberAv3ngers and Handala, exploited these internet-accessible entry points to disrupt automated control functions across multiple facilities simultaneously. The fact that contingency procedures kept services running highlights the importance of manual fallback plans, but the scale of the attack demonstrates that vulnerable OT communication pathways can enable adversaries to strike many targets at once. Water utilities are classified as critical infrastructure, making attacks like these not just operational disruptions but potential national security threats.

Tactical Insight

Immediate actions

  • Audit and harden all cellular and internet-facing communication links connecting remote OT/ICS assets, disabling unused remote access protocols immediately.
  • Deploy multi-factor authentication on all remote access points to SCADA and industrial control systems.
  • Activate heightened monitoring and alerting on OT networks and flag any anomalous command traffic to PLCs or RTUs.

Long-term improvements

  • Implement strict network segmentation between IT and OT environments, and isolate remote field devices behind encrypted, authenticated VPN tunnels rather than direct cellular exposure.
  • Develop and regularly test OT-specific incident response playbooks, including manual override and contingency operating procedures for all automated control functions.
  • Conduct annual third-party OT security assessments and maintain a complete, up-to-date inventory of all internet-connected industrial devices.

Detection measures

  • Deploy OT-aware intrusion detection systems (e.g., Claroty, Dragos, or Nozomi) capable of baselining normal control system behavior and alerting on deviations.
  • Establish log aggregation and SIEM integration for all OT network traffic and forward alerts to a 24/7 monitored security operations function.
  • Subscribe to sector-specific threat intelligence feeds (e.g., WaterISAC) to receive early warning of campaigns targeting water sector infrastructure.