Full transcript
[00:04.9]
Good afternoon. My name is Christy Majoris. I am the regional analyst for North America here on Everbridge’s Global Insights team. Today I’m here to talk about a coordinated cyber campaign that targeted more than 30 community water systems across Minnesota earlier this week. These attacks quickly drew national attention and prompted a coordinated response from federal, state, local authorities.
[00:29.3]
But these weren’t the kind of cyber attacks that we typically think about where hackers are trying to steal sensitive information or deploy ransomware. Instead, these attackers went after the OT systems responsible for running the physical equipment inside the water treatment plants.
[00:47.8]
So in other words, the purpose of these attacks was to disrupt the physical operations of the facilities themselves and by extension, disrupt the delivery of essential services. Clean water in this case. In response to these attacks, several of the sites transitioned to manual operations or in some cases, briefly took facilities offline before restoring service.
[01:11.9]
And the good news is that affected water systems are operational. And officials have stated that drinking water remains safe for public use at this time. Investigations remain ongoing, but initial assessments have now indicated that the campaign was likely conducted by Iranian state linked cyber actors.
[01:34.5]
So why would Iran target water utilities in Minnesota? Well, the question isn’t necessarily why Minnesota, it’s why water facilities. And it’s possible that water systems, simply present an easy target because many community water systems are operating with older technology or smaller cybersecurity teams.
[01:57.5]
But ultimately the objective was less likely about water specifically and more about demonstrating the ability to disrupt essential services inside the United States. And this is especially important if that initial attribution to Iranian linked actors, proves to be correct.
[02:18.8]
These attacks are occurring against the backdrop of an ongoing military conflict between the United States and Iran. And in fact, just days before these water system attacks, cisa, the FBI, the NSA and the EPA issued a joint advisory warning, stating that Iranian affiliated cyber actors were actively targeting industrial control Systems, supporting U.S.
[02:46.3]
infrastructure. And this is something that our Global Insights team picked up on and issued a threat assessment for as well. And these Minnesota attacks do appear to be consistent with those warnings at this time. The biggest takeaway from this incident isn’t that water service was disrupted because it wasn’t substantially.
[03:08.9]
The real significance is that a suspected state linked cyber actor demonstrated the ability to reach systems responsible for controlling physical infrastructure. And although the impacts were limited in this case, this is a good example of how international conflicts don’t always stay overseas.
[03:29.9]
They are increasingly being fought in cyberspace. And this enables attackers to cause physical disruptions remotely. And water utilities are only one example, similar industrial control systems are used in energy, manufacturing, transportation, chemical, oil and gas sectors.
[03:54.0]
So for businesses and organizations, that’s an important shift. Cyber incidents are no longer just about protecting information. They are increasingly about protecting operations and ensuring that essential services can continue during an attack.
[04:13.5]
And there are some practical steps that businesses and organizations can take to reduce this risk, such as reviewing the security of OT environments, limiting unnecessary Internet access to critical systems, separating business IT networks from OT wherever possible, or regularly testing manual operating procedures.
[04:38.1]
Be better prepared in the event of an incident such as this. Our Global Insights team will continue to monitor the situation and the investigation, for indications of expanded targeting or evolving risks to critical infrastructure.
[04:54.1]
And we will continue to provide updates, as warranted. Thank you so much for watching.




