Trump blind to Iran cyber assault on American water and wastewater systems

President Donald Trump on Friday rejected U.S. intelligence assessments blaming Iran for a coordinated cyber assault on water systems across at least seven states, even as cybersecurity experts warned that the same vulnerabilities exploited in the attacks exist in all 50 states.

A wave of cyberattacks has struck water and wastewater systems in at least seven states, forcing utilities to revert to manual operations and triggering a federal investigation into whether Iran is behind a coordinated assault on America’s critical infrastructure.

The attacks, which began July 26, have targeted internet-connected programmable logic controllers, the industrial computers that monitor and adjust water pressure, chemical treatment levels and other essential functions.

Hackers remotely accessed the devices, changed IP addresses, and reset passwords, locking out operators and, in some cases, causing pressure loss and flooding.

While no water supply has been reported contaminated or unsafe to drink, officials in Minnesota alone confirmed that more than 30 community systems were hit, with affected facilities in Michigan and South Dakota also identified.

The FBI and the Environmental Protection Agency issued a joint public service announcement Thursday, warning that “malicious cyber actors” are conducting attacks targeting Rockwell Automation/Allen-Bradley PLCs, specifically the MicroLogix 1100 and 1400 series.

The advisory said the actors have been tampering with device configurations, resulting in a loss of monitoring and, in some cases, control of connected equipment. “This has led to boil-water notices and forced utilities into sustained manual operations,” said Alec Davison, an analyst with WaterISAC, an information-sharing organization that works with the government.

The scope of the intrusions may be far broader than publicly acknowledged. The targeted PLCs are widely used across the country, and experts warn that vulnerabilities exist in all 50 states.

“We only have one internet, and it’s the same equipment for all these victims,” said Joshua Corman, a public safety expert at the Institute for Security and Technology. “Theoretically, you should see these vulnerabilities in all 50 states.”

Of the roughly 151,000 water plants in the U.S., only about 420 participate in WaterISAC to improve cybersecurity, a figure Corman described as “under half a percent paying attention to cybersecurity.”

Intelligence agencies have not definitively attributed the attacks, but the tactical profile matches that of Iranian-affiliated actors, who have been the subject of urgent federal warnings for months.

In April, the Cybersecurity and Infrastructure Security Agency issued guidance warning that Iranian hackers were exploiting internet-exposed PLCs. The agency updated that advisory July 22, just days before the Minnesota attacks began, to include additional manufacturers and tactics.

The hackers are employing “low-sophistication tactics,” often exploiting devices with weak or nonexistent passwords, but the potential for escalation is significant. By modifying PLC logic software, attackers could create unsafe conditions without triggering operator alarms.

“Operators see normal displays. No alerts fire, and the process can enter an unsafe condition without anyone knowing,” said Kurt Gaudette, head of intelligence for Dragos, a cybersecurity firm specializing in critical infrastructure.

The attacks have sparked a sharp political disagreement. President Donald Trump, during a Cabinet meeting at Camp David, dismissed the assessment that Iran was responsible, blaming Minnesota’s state government instead.

“I think I blame it on Minnesota because they’re grossly incompetent,” Trump said. “Iran’s got bigger problems than worrying about Minnesota.”

Gov. Tim Walz, a Democrat, responded on social media, saying: “Trump knows exactly who is responsible for this attack, and knows that other states were hit too. This is what modern warfare looks like.”

Mayor Nate George of Braham, Minnesota, one of the affected communities, said federal and local officials have little doubt about the likely culprit.

“We’re getting bits and pieces of information from the state of Minnesota and the FBI,” he said. “They are pretty sure it’s Iranian actors.”

His town’s plant was restored within 90 minutes by switching to manual operations, but the incident underscored the fragility of infrastructure in small municipalities.

“IT infrastructure upgrades are very costly, and we are a very small municipality,” George said.

The attack comes as the U.S. continues to grapple with the broader implications of the conflict with Iran, which has escalated since the U.S. and Israel launched a war against the country five months ago.

water sector, long considered vulnerable because of its decentralized nature and resistance to federal regulation, now faces a new reality.

“U.S. water is incredibly prone,” Corman said. “We’ve been prey. We just didn’t have predators with an appetite for water, but that’s over.”

Although Congress acknowledges that the United States’ information technology (IT) and operational technology (OT) systems are highly vulnerable to cyber threats, it has generally failed to include statutory cybersecurity requirements in major funding bills.


Discover more from NJTODAY.NET

Subscribe to get the latest posts sent to your email.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from NJTODAY.NET

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from NJTODAY.NET

Subscribe now to keep reading and get access to the full archive.

Continue reading