The United States multi-land water facilities have been subjected to cyberattacks for nearly two weeks, and incidents have risen from the local level to federal attention. Public information indicates that the target groups include water plants and sewage treatment plants, which reach more than a dozen states. According to the FBI, some of the attacks have led to operational problems such as reduced water pressure and local water accumulation.

The range of attacks extends to the state.

The first cause of widespread concern was Minnesota. On 28 July, the local government indicated that more than 30 community water treatment facilities had been subjected to coordinated attacks. Two days later, the FBI stated that at least seven state water and sewage facilities had reported incidents and that some of the facilities had been affected.

Since then, information about the invasion of the facility has been heard from Arkansas, Georgia, New Jersey and Michigan. Reports indicate that there are more than 150,000 water supply systems across the United States, many of which are operated by local agencies or small companies, and that this decentralized structure has made it more difficult to unify attacks, but it also means that some operators lack adequate resources for cybersecurity.

The U.S. has yet to be formally attributed.

At present, the United States Government has not officially named the attackers. However, a number of institutions and media have directed their suspicions towards Iran.

The United States Cybersecurity and Infrastructure Security Agency (CISA) updated an early warning prior to the Mingzhou incident that Iranian hackers were operating against Internet-accessible water systems and energy facilities. Subsequently, WaterISAC, an information-sharing organization in the water sector, indicated to its members that the recent attack was consistent with the operational characteristics warned by CISA.

This week, the Washington Post quoted informed sources as saying that American intelligence agencies were “confident” that Iran, and in particular the Iranian Islamic Revolutionary Guard Corps, were responsible for the attack. However, due to the fact that no specific implementing unit has yet been identified and that the White House level of representation is not consistent with this judgement, the attribution remains undisclosed.

Some of the facilities were stopped on short notice

Not all of these attacks have had serious consequences, but they have had a real impact. Forescoout stated earlier this month that over 2,800 controls exposed to the public network had been found in the United States water system. Once exposed, such equipment is not necessarily fully taken over, but will significantly increase the risk of invasion.

According to the FBI, some of the attacks have led to a decrease in pressure on water supplies, which may theoretically allow untreated groundwater to penetrate the pipeline, and to the accumulation of water at individual sites. A water plant in the town of Braham, Minnesota, was therefore suspended for a few hours, and approximately 1,700 residents were asked to save water. The city of Maple Plain briefly declared a state of emergency. A district on the outskirts of Atlanta, Georgia, has also advised residents to boil their water before using it.

Apart from the operational dimension, the social impact of events is equally evident. The water supply system, which is a basic livelihood facility, has raised public concerns about water security following successive attacks that continue to ferment in local and national media. Reports suggest that such panic may in itself be one of the effects the attackers wish to produce.