Following a recent wave of targeted cyberattacks in at least a dozen states, the Minnesota Pollution Control Agency and other state, local, and federal officials have been responding to malicious cyber activity targeting technology at more than 30 community water systems across Minnesota.
The state activated its coordinated cyber-response capabilities, and worked directly with impacted water systems to contain the activity, assess potential impacts, restore normal operations, and reduce the risk of further disruption. Most confirmed cases involved technology that water systems use to remotely monitor and control equipment, including programmable logic controllers and the computer screens operators use to manage them. When the attacks were detected, Minnesota officials instructed water and wastewater systems to identify operational technology accessible from the internet and secure it. Fortunately, none of the confirmed malicious activity involving a system’s technology led to active requests from Minnesota communities for residents to modify their drinking water use.
Though Minnesota investigators have identified similarities among the incidents, the investigation has not determined that every incident was carried out by the same actor. Minnesota IT Services is coordinating response efforts with several state agencies, including the Minnesota Pollution Control Agency, local water utilities, and federal agencies including U.S. EPA, the Cybersecurity & Infrastructure Security Agency, and the Federal Bureau of Investigation.
Technical guidance is available in CISA’s cybersecurity advisory. Visit ECOS’s Water Cybersecurity page for related state and federal resources.
