🟠 High  |  Source: Schneier on Security


Iranian threat actors are attributed, preliminarily, to a series of cyberattacks targeting water treatment and distribution facilities across at least seven US states, with Minnesota among the most prominently affected. US intelligence agencies suspect Iran is responsible, though no significant operational damage has been confirmed to date. The incident highlights the persistent vulnerability of operational technology (OT) infrastructure in critical national infrastructure sectors.

Security Architect’s Take: Organisations managing or securing OT/ICS environments — including those using cloud-connected SCADA or industrial control systems — should review network segmentation between IT and OT layers, ensure remote access to control systems is restricted and MFA-enforced, and validate that anomaly detection is active on ICS protocols. If you support water or utilities clients, cross-reference your threat model against CISA’s water sector guidance and Iran-linked TTPs immediately.

Original advisory: Iran Cyberattacks Against Minnesota Water Systems