Minnesota water systems hit in cyberattacks said to reach seven states

Plymouth, Minnesota, water tower
The water tower in Plymouth, Minnesota, one of over 30 municipalities in the state hit by cyberattacks on municipal water operations.
Adobe Stock

Braham, Minnesota, was one of more than 30 municipal water systems in the state hit by a coordinated cyberattack last week, with similar attacks reported in six other states.

Processing Content

The threat actors hacked into two internet ports used by a variety of water systems across Minnesota, Braham Mayor Nate George said Friday.

"There were two ports that were identified," he said. "So anyone who was on those ports got hit."

Most confirmed cases involved technology that water systems use to remotely monitor and control equipment, according to a statement from Minnesota IT Services, the information technology agency for the state's executive branch.

Braham's water plant was taken offline Monday, George said. "They just shut down the well pump so it wasn't pumping any water to the water tower," he said. "We caught it almost immediately after it occurred. It was back up and running within an hour and a half."

But Braham's water system is now operating manually, having been removed from any internet connection, and will continue to do so for the foreseeable future, George said.

"It requires more manual presence to operate it, so we're not sure what it's looking like as far as labor costs go," he said of the financial impact of the attack.

And "any IT upgrades that (it) might be recommended (we) make, anything IT-related tends to be pretty expensive," he said.

The Federal Bureau of Investigation said in a Thursday alert that since Monday, water and wastewater utilities in seven states have reported cyber incidents to the FBI, including attacks that "degraded water operations." 

The FBI said hackers are targeting operational technology, especially Rockwell brand programmable logic controllers. Accessing the system through internet-facing components, the hackers changed IP addresses and passwords, "resulting in a loss of monitoring and control functionality," the FBI said.

Omid Rahmani, public finance cyber risk lead at Fitch Ratings, said the switch to treating water manually in Braham was likely a cautionary step prompted by the suspicion or knowledge "that their systems may have been actually totally compromised." He said small water utilities like Braham's are at a disadvantage compared to electric utilities when it comes to cybersecurity.

"Federal resources for the sector have been much more meager in relation to the power sector historically," he said. "As a result, we have a situation where we have 50,000 drinking water systems, and to a certain degree, they can each come up with what cybersecurity means to them. 

"And obviously, the resource allocation across the sector is highly asymmetric, as well," he added. "We have large systems that do get a lot of support — for example, D.C. Water. And then we have much smaller systems serving smaller communities that really don't have the resources to do much, and you're seeing that in this situation."

George said it's "100% accurate" that small-town municipal water utilities are under-resourced.

"We are a town of 1,800 people," he said "Our median income is $55,000 to $60,000 a year." It has no IT department, he said; if it were to create one and hire full-time staffers, "it would be an ongoing 14% tax levy increase annually. That's just unaffordable for communities of our size," he said.

Compounding the risk are Trump administration cuts to the Cybersecurity and Infrastructure Security Agency, the branch of the Department of Homeland Security that runs cybersecurity protection. In a March report, Fitch noted that public finance issuers face heightened cyber risk amid the war with Iran, with utilities among the most vulnerable sectors.

"Smaller, resource-constrained public finance entities are particularly vulnerable, as federal cybersecurity resource reductions may hinder robust defense, coordination, and response," Fitch said.

The federal FY2024 budget provided $3.1 billion for CISA, while the FY2025 budget provided $3 billion for CISA. The FY2026 budget appropriated about $2.6 billion for CISA.

In its FY2026 executive budget, the Trump administration had proposed a 17% cut to CISA's budget, or nearly $500 million. It also wanted to fire more than 1,000 staffers in a bid to limit the agency's mission to defense of the federal network.

The American Water Works Association testified to a House subcommittee in 2024 that water utility technology systems that traditionally operated independently — IT systems and operational technology systems — are increasingly converging. 

In his testimony, AWWA Federal Relations Manager Kevin Morley said constraints on the state revolving fund program prevent water utilities from adding "the optimal cybersecurity support they need." He argued for more funding to accelerate capital-intensive technology upgrades. 

Water utilities need a more collaborative approach similar to the one adopted by the electric sector, Morley testified.

On July 22, CISA issued an updated advisory bulletin expanding a bulletin from April, saying Iran-affiliated threat actors are targeting programmable logic controllers in the water sector.

PLCs are small industrial computers that run the physical equipment at a water plant — the pumps, valves, chemical dosing systems, filters and similar equipment. 

The PLCs are essentially the final layer between the IT systems and operational systems like the Supervisory Control and Data Acquisition System and the physical plant equipment, Rahmani said. 

"What targeting of PLCs means is they're trying to translate a digital attack into a physical outcome," he said of the attackers. Fitch warned a year ago about "conflict-driven cyber activity of this exact nature, of translating digital into kinetic… We have been monitoring this type of activity specifically because of the risk and the threat that it can pose to operations," he said.

The overall cyber threat has evolved rapidly over the last five years, said Tom Kozlik, head of public policy and municipal strategy at Hilltop Securities. The muni industry has gone from thinking of cyberattacks as just an IT threat to facing a broader threat to civilian infrastructure.

"There's been a change in the motives that investors and issuers should be thinking about," Kozlik said. "It's not just money or data that they're looking for, it's also strategic leverage against the U.S. and against certain regions of the U.S."

Kozlik said he'll be watching to see if entities are able to maintain operations and resilience. "Are they going to be able to operate through an extended period of time using manual controls, backup operations?" he said.

He also stressed the vulnerability of water compared to other sectors, and its cascading impact on other sectors like healthcare.

"The level of government almost doesn't matter where this is concerned," he said. "I don't think that foreign adversaries really care what level of government is responsible for a particular water (system). They just understand the strategic importance of the region."

Jeff Lipton, market intelligence analyst at The Bond Buyer, recently developed a muni credit scorecard that listed cyber threats as a top risk to public finance sectors, including the water/sewer sector. Lipton listed the outlook on that sector as "stable/cautious."

"This is exactly what I was talking about," Lipton said of the coordinated cyberattacks. "(The muni market needs) to create a unified task force that could put together some kind of cohesive strategy. There are certain protocols that are out there that certain issuers do follow... But I think we've got to create a more uniform set of standards."

Cyberattack preparedness needs to be at the top of every conversation that investment bankers, municipal advisors and rating agencies have with municipal issuers, Lipton said. "That's critically important... I've always been unhappy about the boilerplate disclosure language. I think we have to go beyond the boilerplate."

Smaller utilities are most at risk, Lipton said. They're short on funding and on dedicated cybersecurity professionals. Ideally, he said, municipal issuers would have a designated individual charged with setting up an internal task force that brings together senior leadership and department heads, to not only withstand a cyberattack, but prepare for one in advance.

"For most of these water utilities across the country, you're talking about aging technology, aging infrastructure; there's a great deal of deferred maintenance," Lipton said. "For many of these issuers, certainly the smaller issuers, it's just a matter of fiscal constraints."

In Braham, George said they're still waiting to hear from the FBI and the state "as far as mitigation goes." He confirmed the cyberattack had some markers of a nation-state, but said "nothing's been passed on to us definitively."

George said he doubts the attackers were trying to affect water quality. "You would have had to do a whole lot more than just shut down the well pump to impact water quality," he said. But "the risk was there, and that was outlined in the latest bulletin that was received."

He recommended other municipalities implement daily physical checks at the water plant, which has been the policy in Braham since at least four years ago.

"We credit that for catching it as quickly as we did," he said. "They happened to find it during one of those checks. I think that prevented it from becoming much worse," including possibly causing the town to run out of water.  

In a July 30 posting, Minnesota IT Services said officials "continue to respond to malicious cyber activity" hitting 30-plus community water systems.

"The investigation remains active, and Minnesota has not attributed the activity to a specific actor," the agency added.

As of July 28, the agency said there were no requests from municipalities that residents cut water usage, although Braham had earlier asked residents to minimize water use and cease use for recreational and landscaping purposes entirely.

"This problem is going to get worse," Rahmani said. "If it gets better, it's going to be later. In the short term, we're going to be dealing with more of it."


For reprint and licensing requests for this article, click here.
Cyber Security Minnesota Utilities Cyber attacks
MORE FROM BOND BUYER
Load More