Back to all lessons
Awareness Lessons
2 months ago

Iran-Linked Cyberattacks Disrupt Minnesota Water Utilities

Iranian-affiliated threat actors successfully targeted dozens of Minnesota water and wastewater utilities, exploiting shared technologies and likely poor network segmentation or weak access controls to disrupt operational systems. These attacks resulted in boil-water notices and forced manual intervention, demonstrating that attacks on critical infrastructure carry direct public health consequences. The fact that a leaked WaterISAC memo — rather than proactive disclosure — brought this to light raises concerns about information sharing and incident response maturity in the sector. Water utilities, often under-resourced, frequently rely on legacy OT/ICS systems that are internet-exposed and inadequately hardened, making them attractive and accessible targets for nation-state actors.

Tactical Insight

Immediate actions

  • Isolate operational technology (OT) and industrial control systems (ICS) from internet-facing IT networks using strict network segmentation.
  • Audit and revoke unnecessary remote access credentials, enforcing multi-factor authentication (MFA) on all remaining remote access points.
  • Conduct an emergency inventory of all internet-exposed assets and disable or patch those running known vulnerable firmware or software.

Long-term improvements

  • Develop and regularly exercise an OT-specific incident response plan that includes manual fallback procedures for critical processes.
  • Enroll in threat intelligence sharing programs such as WaterISAC and CISA's critical infrastructure advisories to receive early warning of sector-specific campaigns.
  • Implement a vulnerability management program with scheduled assessments of ICS/SCADA systems against known CVEs and ICS-CERT advisories.

Detection measures

  • Deploy continuous monitoring and anomaly detection tools tailored for OT environments to identify unusual command sequences or traffic patterns.
  • Establish centralized logging for all remote access and control system events with defined alerting thresholds and escalation procedures.
  • Conduct regular tabletop exercises simulating nation-state attacks on water utility control systems to validate detection and response capabilities.