Investigators believe a cyberattack this week on dozens of municipal water systems in Minnesota was probably the work of Iranian hackers, according to U.S. and state officials and others familiar with the matter, a potential act of aggression that comes at a precarious moment in the U.S. war against Iran.
Officials cautioned that they had not definitively determined who was responsible for the attack and that the preliminary assessment could change as the authorities collected more technical data.
They also warned that the hackers could be attempting to pose as Iran-based in an effort to ratchet up tensions between the two countries, though former intelligence officials said such a scenario was unlikely.
Local officials reported that the well and treatment plant in at least one city was temporarily offline on Monday, while other cities in the state had to use manual workarounds to cope with attempted attacks on automated operations.
There were no indications that any water supply had been rendered unsafe to drink.
Even with its limited impact, the hack — if confirmed to be linked to Tehran — comes at a sensitive time as direct fighting between the United States and Iran has resumed in the Middle East.
Three state officials briefed on the investigation into the breach said the tradecraft used, and the absence of a ransom demand, had led analysts to tentatively conclude that it was the work of Iranian hackers. Those officials spoke on the condition of anonymity to discuss a continuing criminal investigation.
“The F.B.I. is aware of the incident and in contact with victims to resolve the matter,” said Matthew Vogel, a spokesman for the bureau, which declined to comment further.
While the investigation continued, former officials and cybersecurity experts said they expected the suspicions about Iran’s involvement would only grow stronger.
“Almost every initial assumption of attribution turns out to be true,” said Cynthia Kaiser, a former senior F.B.I. official who oversaw investigations into cyberattacks attributed to foreign governments. Several clues pointed to Iran in this instance, Ms. Kaiser said, including that it appeared focused on disruption rather than financial gain and that Tehran has demonstrated a recent interest in targeting the U.S. water supply.
John Israel, Minnesota’s chief information security officer, said that hackers targeted roughly 36 municipal water systems in the state as part of a breach that was first detected on Sunday.
The first report prompted state officials to warn municipalities with similar vulnerabilities to be on alert, which enabled a swift response, Mr. Israel said. The hackers targeted infrastructure used to remotely manage and monitor water towers maintained by municipal governments.
“Minnesota was one of the early detectors of this, but we’re seeing that this same threat activity has likely been occurring in other states throughout the nation,” he said.
Mr. Israel said that as of Wednesday afternoon, there had been no indication that any of the breaches contaminated or disrupted water delivery.
Iran has targeted the United States with an increased barrage of cyberattacks since the war began in February, with limited success. One notable exception was a hack in March on Stryker, a major medical equipment supplier, that caused a temporary companywide shutdown.
Other cyberactivity conducted by Iran against the United States has risen to the level of nuisance more than alarm. For example, a group affiliated with Iranian intelligence took responsibility for the release of emails and photographs stolen from a personal account of Kash Patel, the F.B.I. director.
Nick Andersen, the acting director of the Cybersecurity and Infrastructure Security Agency, said on Wednesday that the agency was aware of “multiple potential incidents affecting local water utilities.”
Mr. Andersen did not comment on who was responsible but referred to a recent cybersecurity advisory updated by the agency just days before the Minnesota attack began. It warned that “Iranian-affiliated cyberactors” were attempting to break into operational technology devices to potentially disrupt critical infrastructure in the United States, including in water and wastewater systems.
Cybersecurity experts have long said that U.S. water systems, which tend to be old and underfunded, were vulnerable to digital disruption.
Nate George, the mayor of Braham, Minn., a small city 65 miles north of Minneapolis, said public works personnel noted early Monday that the well that feeds the city’s water tower was malfunctioning.
“Public works isolated the affected system, restored a backup and restarted the plant within approximately 90 minutes,” Mr. George said in a statement. The city briefly urged residents to conserve water but promptly lifted that advisory.
“This attack on critical public infrastructure should be a warning to policymakers in St. Paul,” Mr. George wrote. “Minnesota’s local governments are expected to defend essential systems against foreign adversaries and sophisticated criminals, often with limited staff, aging technology and inadequate resources.”
The post U.S. Sees Iran as Likely Behind Cyberattack on Minnesota Water Systems appeared first on New York Times.




