Hackers aren’t just stealing data anymore — Minnesota cyberattack shows they’re targeting your water

There’s a new, urgent federal government warning about the security of water systems in Minnesota and across the country.
That advisory is from the Cybersecurity and Infrastructure Security Agency, or CISA — a branch of the Department of Homeland Security (DHS).
RELATED: Cyberattack on over 30 Minnesota water systems may be linked to Iran
The agency, citing a “significant increase” in cyber threat actors targeting water systems, is urging operators to remove those systems from the internet, enable password protection, change passwords and allow remote access only through a VPN or gateway device.
The FBI also issued a warning Friday that it’s monitoring cyberattacks targeting operational technology devices, adding that “threat actors are remotely accessing internet-facing PLCs, changing IPs and passwords, and causing operational disruption, including pressure loss and flooding.”
The new government warning follows what Feras Batarseh, a cybersecurity expert at Virginia Tech University, calls a “cyber-biosecurity attack.”
“Our adversaries, I would say, are actively targeting our infrastructure,” he declares. “This is an active scenario. This is ongoing. It’s happening every day, all day.”
Authorities say more than 30 water systems across Minnesota have been impacted by cyberattacks.
Batarseh says hackers targeting water systems are no longer focused solely on stealing data or demanding a ransom.
He says bad actors are trying to manipulate the physical systems that produce and distribute safe drinking water.
“You’re talking about poisoning water systems,” Batarseh notes. “You’re talking about drinking water impacts, impacting the public health population.”
It sounds scary, but municipal leaders in the impacted Minnesota communities emphasize that water safety was never compromised.
Braham Mayor Nate George says city staffers disconnected the municipal water plant from the internet once an issue was discovered Monday and have been operating the system manually ever since.
“All indications are we caught it almost immediately,” he explains.
The government says hackers are targeting programmable logic controllers — industrial computers used to control and monitor equipment.
Batarseh says these latest attacks have all the earmarks of Iranian hackers, but at this point, it’s too early to know for sure.
“It’s very difficult to tell today,” he explains. “However, the coordinated form that was performed in this one, it definitely meets the pattern recognition for Iranian attacks.”
Batarseh says there’s an additional concern that some water systems have outmoded equipment.
“Fairly old computers and network devices and security protocols applied to those systems without … active security protocols in place,” he notes.
But Batarseh says upgrading those systems to provide better security could cost a municipality thousands of dollars.
Mayor George says creating an IT infrastructure department with just one full-time manager would result in a 24% tax levy increase in just the first year and a 14% increase every year after that.
He explains that could cost from about $730 to $1,400 per household, depending on the actual final costs.
The mayor says he’s calling for a meeting with staff and the city’s IT and internet providers to discuss security options going forward.
Braham’s water system serves about 850 customers.
George says he’s hoping for state funding to help.
State Rep. Kristin Bahner, DFL-Maple Grove, with 30 years of experience in the IT industry, is predicting lawmakers will be taking a hard look at ramping up cybersecurity rules in the next legislative session.
“Cybersecurity is national security on a digital level, and that is what makes this so critical,” she says. “I have a feeling there will be some serious discussions happening in the next few days and weeks about what we can do to make that a reality.”




