A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran

A leaked memo reveals that Iran-affiliated hackers are responsible for cyberattacks on water and wastewater utilities in Minnesota. Experts warn that this targeting of critical civilian infrastructure represents a dangerous escalation in state-sponsored cyber warfare.
Why it matters
The vulnerability of public drinking water systems to foreign state-sponsored cyberattacks poses a significant threat to national security and public safety.
A communication obtained by WIRED on Thursday and sent to members of the Water Information Sharing and Analysis Center, or WaterISAC, an industry group for water utilities to share cybersecurity information, links to Iran a series of cyberattacks that targeted dozens of Minnesota water and wastewater utilities.
The WaterISAC note states that the Minnesota Fusion Center, a state-level intelligence-sharing entity, issued an alert “regarding ongoing malicious cyber activity impacting public drinking water systems across Minnesota” and adds that the fusion center has found that those attacks were “aligned” with a hacking campaign first described in April by the US Cybersecurity and Infrastructure Security Agency (CISA) as having been carried out by “Iran-affiliated” hackers. (Both the WaterISAC and Minnesota Fusion Center reports were marked as unclassified but “for official use only.”)
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in