Three Minnesota cities reported cyber incidents affecting municipal water technology on Monday: South St. Paul, Braham, and Plymouth.
Edit: A fourth water utility in Maple Plain was impacted.
All three cities said drinking water remained safe. Braham officials also said they were told at least four other communities were attacked “with the same result,” suggesting at least two affected municipalities have not been publicly named.
The timing is notable because CISA and federal partners updated an advisory five days earlier warning that Iranian-affiliated actors were targeting internet-connected programmable logic controllers used across U.S. critical infrastructure. The advisory describes operational disruptions involving control configurations, sensor readings and interfaces.
That said, there is currently no public evidence connecting these Minnesota incidents to the activity in the CISA advisory. The cities have not disclosed the affected vendors, PLC models, access methods or threat actors, and officials have not confirmed that the three incidents share a common source.
For people working in water or operational technology security, do the reported symptoms resemble the activity CISA described, or is the available information still too limited to draw a meaningful comparison?
submitted by
/u/DysruptionHub [link] [comments]