Leaked Memo Links Dozens of Cyberattacks on Minnesota Water Utilities to Iran
A leaked WaterISAC memo ties dozens of cyberattacks on Minnesota water utilities to Iran, exposing critical infrastructure vulnerabilities and prompting urgent CISA guidance.
A leaked memo from the Water Information Sharing and Analysis Center (WaterISAC) has linked dozens of cyberattacks against Minnesota water utilities to Iran, according to a report by WIRED. The memo, obtained by WIRED, details a coordinated campaign targeting more than 30 community water systems across the state.
The attacks, which occurred over recent months, involved intrusions into programmable logic controllers (PLCs) and other operational technology (OT) systems. Dark Reading reported that the likely Iran-backed actor exploited internet-exposed controllers, gaining unauthorized access to critical water infrastructure.
Attack Details and Affected Systems
The WaterISAC memo, shared among member utilities, outlines a pattern of reconnaissance and exploitation targeting small to medium-sized water utilities. Key facts from the reporting include:
- More than 30 community water systems in Minnesota were targeted, with some intrusions resulting in unauthorized control of water treatment equipment.
- The attackers used known vulnerabilities in PLCs and other OT devices that were exposed to the internet without proper security controls.
- WaterISAC attributed the campaign to an Iranian state-linked threat actor, though the memo did not name a specific group.
- The intrusions did not cause significant service disruptions or public health incidents, but they raised alarms about the sector's cybersecurity posture.
CISA Response and Sector Implications
In response to the attacks, the Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent advisory urging water and wastewater utilities to secure internet-exposed OT systems. SecurityWeek reported that CISA's guidance emphasized the need for network segmentation, multi-factor authentication, and regular patching of PLCs and other controllers.
The incident underscores the persistent vulnerability of the U.S. water sector, which relies on aging infrastructure and often lacks dedicated cybersecurity resources. Many small utilities operate with limited IT staff and budget, making them attractive targets for state-sponsored actors seeking to probe critical infrastructure defenses.
What comes next is a push for federal funding and technical assistance to help utilities harden their systems. CISA and WaterISAC are expected to release additional threat indicators and best practices in the coming weeks. The attacks also may accelerate legislative efforts to mandate baseline cybersecurity standards for the water sector, which currently operates under voluntary guidelines.
Fact check
-
A leaked WaterISAC memo links dozens of cyberattacks against Minnesota water utilities to Iran.
reported · source
-
More than 30 community water systems in Minnesota were targeted.
reported · source
-
CISA issued an urgent advisory urging water utilities to secure internet-exposed OT systems after the attacks.
reported · source
Source reporting (4)
- Techmeme · A leaked memo, issued by the water utilities information sharing group WaterISAC, links dozens of cyberattacks against Minnesota water utilities to Iran (Andy Greenberg/Wired)
- WIRED · A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran
- Dark Reading · Minnesota Water Utility Attacks Expose Sector's Cyber-Risks
- SecurityWeek · CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs
Related Articles
Snowflake hacker pleads guilty to stealing data from 165 organizations, faces 32 years in prison
Aug 5, 2026
AI Agents From OpenAI and Anthropic Breach Real Websites During Security Tests
Aug 5, 2026
AI Agent Security Startups Zenity and Horizon3.ai Raise $375M Combined as SentinelOne Expands Autonomous SOC
Aug 3, 2026
0 Comments
No comments yet
Be the first to share your thoughts on this article.