Are hacks of U.S. water facilities a new front in the Iran war?

A water tower is seen on July 30 in Plymouth, Minn. A cyberattack targeted the operating technology at over 30 water systems in Minnesota, including Plymouth’s late last month, state officials said.

Ellen Schmidt/AP


hide caption



toggle caption

Ellen Schmidt/AP

On a recent Monday morning in Braham, Minn., a local water operator made an unsettling discovery — the pump at the treatment plant wasn’t working, threatening the flow of water to people’s homes.

While investigating the root cause, crews took the plant offline, and the city urged Braham’s 1,700 or so residents to conserve water while they drew on a backup supply stored in a local tank.

It only took a couple of hours for workers to restore the flow after taking manual control of the pump. The self-proclaimed homemade pie capital of Minnesota still hosted its annual Pie Day celebration at the Park Cafe just days later.

But what Braham officials quickly learned, after connecting with Minnesota state IT teams, was that they were not alone in the outages. The cause was a “coordinated cyberattack” against industrial technology nationwide, and cybersecurity experts and federal officials suspected Iran may be to blame.

It’s nothing new. Adversaries, including Iran, have been targeting U.S. critical infrastructure for years, to steal data or cause disruptions. Once inside, they can ransom the data to make money or threaten access to and trust in critical resources, from water and power to transportation and their bank accounts. “Everything’s connected to the internet in one way or another,” Nate George, the mayor of Braham, told NPR in an interview. “It’s not Braham in particular that’s being targeted. It’s the internet access points and the vulnerable technology,” George, a U.S. Air Force reservist, continued.

While the hackers failed to compromise the water supply, they succeeded in inspiring headlines and provoking uncertainty. And the scope, scale and real-world impacts of the attacks, like the one in Braham, have been remarkable even to the experts.

“I can’t recall a time when there’s been this many targets at once with operational impact,” said Rob Lee, the co-founder and CEO of Dragos, a cybersecurity firm focused on industrial technology. Lee told NPR he’s aware of victims of this recent spate of attacks outside the water sector, as critical infrastructure operators tend to rely on the same technology. It’s something Lee has been warning about for years. “This is pretty significant,” Lee said.

Leave a Comment

Your email address will not be published. Required fields are marked *