美国调查伊朗是否为明尼苏达州供水系统网络攻击事件幕后黑手


2026年7月30日 / 美国东部时间晚上11:20 / 哥伦比亚广播公司(CBS)新闻

据CBS新闻获悉,本周有恶意网络活动影响了明尼苏达州逾30个社区供水系统的技术设备,迫使部分水务部门切换至人工操作模式,与此同时州和联邦当局正在调查攻击背后的组织者。

据美国官员和熟悉该事件的消息人士透露,调查人员正在探查此次网络活动是否为伊朗黑客所为。消息人士提醒称,由于目前尚未确定攻击的归属方,他们的评估可能会随着更多技术证据的收集而发生变化。他们同时也在调查,攻击者是否故意伪装成伊朗方面的势力,以期在美国与伊朗持续对峙的背景下加剧局势动荡。

明尼苏达州和联邦政府尚未公开将此次网络活动归咎于某一特定组织。

美国联邦调查局(FBI)、环境保护署(EPA)以及网络安全与基础设施安全局(CISA)周四均发出警告称,攻击者正瞄准水务和污水处理公用事业机构使用的、暴露在互联网上的工业控制器。联邦当局报告称,在至少部分案例中,关键基础设施站点的监控和控制功能出现失灵,导致压力损失和积水泛滥。

联邦机构未披露受影响的州,FBI和EPA表示,此次事件不仅限于明尼苏达州,“至少七个州”都报告了类似 incident。

明尼苏达州信息技术服务部门表示,此次明尼苏达州网络攻击中确认的多数案例涉及用于远程监控和控制供水系统设备的技术,包括名为可编程逻辑控制器(PLC)的装置。

明尼苏达州公共安全部公共信息官迈克·恩斯特告诉CBS新闻,目前没有报告明尼苏达州的供水系统因此次攻击受到破坏。他补充称,刑事调查局下属的明尼苏达融合中心正在与各市政当局以及州和联邦合作伙伴合作处理该问题。

联邦网络安全与基础设施安全局代理局长尼克·安德森证实,该局“目前正观察到针对水务机构可编程逻辑控制器的网络威胁行为者数量显著增加”。

他补充道:“我们敦促关键基础设施所有者和运营者尽快将暴露在公共网络中的可编程逻辑控制器和其他运营技术从互联网上移除。”

明尼苏达州表示,调查人员发现近期事件在发生时间和受影响的技术类型上存在一些相似之处,但尚未确认所有事件均为同一攻击者所为。


image2026年7月30日于明尼苏达州普利茅斯拍摄的水塔。州官员称,本周早些时候,一场网络攻击 targeting 该州包括普利茅斯在内的30多个供水系统的运营技术。美联社照片/艾伦·施密特

南圣保罗市的一名发言人告诉CBS新闻,该市周一早些时候发现了问题,并立即启动了应急程序。公共工程部门员工切换至人工操作模式,确保供水和污水处理服务得以继续,未出现任何服务中断。该市补充称,此次事件仅波及支持其水务部门部分业务的技术系统,饮用水处理、水质、水压和配送均未受到影响。

南圣保罗市的官员未发现任何居民或客户数据被访问的迹象。

在明尼阿波利斯以北更偏远地区的布拉厄姆市,公共工程人员在注意到为该市水塔供水的水井出现故障后,于周一发现了问题。市长内特·乔治向CBS新闻证实,工作人员隔离了受影响的系统,恢复了备份,并在约90分钟内重启了水厂。

乔治补充称,居民未出现停水情况。该市的水塔通常可储存足够维持约两天的饮用水,运营人员在收到自动警报前就发现了问题,因此该市认为水泵仅离线了很短一段时间。该市目前已确保该系统不再连接任何面向公众的互联网网络,并正在与其技术提供商就修复措施进行磋商。

在明尼苏达州郊区普利茅斯市,官员们周日晚间发现了一起中断事件,当时他们注意到两座水塔和14座污水提升泵站的可编程逻辑控制器遭到破坏,随后将这些系统与蜂窝网络断开连接。

普利茅斯市的一名官员告诉CBS新闻,运营人员暂时切换至手动操作模式,直到系统恢复上线,正常通信于周二下午恢复。不过官员们表示,水质、处理和水压从未受到影响,整个过程中配送始终未中断。

普利茅斯市公共工程主管迈克尔·汤普森告诉CBS新闻明尼苏达分部,他的团队最早是在周日晚间发现设备之间的通信开始中断时意识到出了问题。汤普森表示,周一凌晨刚过午夜时,情况已进入全员待命状态。

“我想你永远不会预料到这种事会发生在自己身上,”汤普森说道。

CISA周四表示,其“目前正观察到针对水务和污水处理系统行业可编程逻辑控制器的网络威胁行为者数量大幅增加”,并指出这些攻击者的目标“涵盖各种规模的水务机构”。

隶属于国土安全部的CISA表示:“我们敦促关键基础设施所有者、运营者和集成商尽快将暴露在公共网络中的可编程逻辑控制器和其他运营技术(OT)从互联网上移除。”

CISA在其 advisory 中补充道:“即使是拥有成熟网络安全流程的水务机构也应验证其外部连接情况,因为此次 targeting 活动包括运营商、供应商或系统集成商安装的蜂窝调制解调器,这些设备可能未被记录或未纳入常规攻击面扫描范围。”

与伊朗有关联的黑客此前曾 targeting 美国水务机构。联邦机构此前证实,隶属于伊朗伊斯兰革命卫队的攻击者使用了类似的作案手法,在2023年通过利用保留默认密码的联网控制器入侵了多家水务和污水处理设施。

康纳·赖特为本报道撰稿。

U.S. investigating whether Iran was behind cyberattack on Minnesota water systems

July 30, 2026 / 11:20 PM EDT / CBS News

Malicious cyber activity affected technology at more than 30 community water systems across Minnesota this week, forcing some utilities to switch to manual operations as state and federal authorities dig into who is behind the attack, CBS News has learned.

Investigators are probing to determine whether the activity is the work of Iranian hackers, according to U.S. officials and sources familiar with the incident. Sources cautioned that since they had not definitively attributed the attack, their assessment could change as additional technical evidence is collected. They are also probing whether the actor could have attempted to appear Iran-based as a way of stirring the pot amid the ongoing U.S. conflict with Iran.

Minnesota and the federal government have not publicly attributed the activity to a particular actor.

The FBI, Environmental Protection Agency and Cybersecurity and Infrastructure Security Agency all warned Thursday that attackers are targeting internet-exposed industrial controllers used by water and wastewater utilities. In at least some cases, federal authorities reported loss of monitoring and control functionality at critical infrastructure cites, leading to pressure loss and flooding.

Federal agencies did not identify affected states, and the FBI and EPA said the issue extends beyond Minnesota, with incidents reported in “at least seven states.”

Most confirmed cases in the Minnesota cyberattack involved technology used to remotely monitor and control water system equipment, including devices called programmable logic controllers, according to Minnesota IT Services.

None of Minnesota’s water supply has been reported compromised as a result of the attack, Mike Ernster, a public information officer for the Minnesota Department of Public Safety, told CBS News. The Bureau of Criminal Apprehension’s Minnesota Fusion Center was working with municipalities, as well as state and federal partners, to address the issue, he added.

Nick Anderson, acting director of the federal Cybersecurity and Infrastructure Security Administration, confirmed that the agency “is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLC) at water utilities.”

“We urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible,” he added.

Minnesota said investigators identified some similarities in the timing of the recent incidents, in addition to the types of technology impacted, but had not yet confirmed that every incident was carried out by the same actor.

A water tower is seen in Plymouth, Minnesota, on July 30, 2026. A cyberattack targeted the operating technology at over 30 water systems in the state, including Plymouth’s, earlier this week, state officials said. AP Photo/Ellen Schmidt

A spokesperson for the city of South St. Paul told CBS News it identified an issue early Monday and immediately implemented contingency procedures. Public works employees transitioned to manual operations, allowing water and wastewater services to continue without any interruption to service. The city added that the incident was limited to technology supporting portions of its water utility, while drinking water treatment, quality, pressure and delivery were not impacted.

Officials in South St. Paul found no indication that resident or customer data was accessed.

In Braham, located in a more rural area north of Minneapolis, public works personnel also discovered the problem Monday after noticing the well supplying the city’s water tower was malfunctioning. Workers isolated the affected system, restored a backup and restarted the plant in about 90 minutes, Mayor Nate George confirmed to CBS News.

Residents experienced no loss of water service, George added. The city’s water tower typically holds enough drinking water to last about two days, and operators discovered the problem before receiving an automated alert, leading the city to believe the pump had been offline for only a brief period. The city has since ensured the system is not connected to any public-facing internet networks and is meeting with its technology provider about remediation.

In suburban Plymouth, Minnesota, officials detected an outage Sunday evening after noticing compromised PLCs at two water towers and fourteen sewer lift stations, then disconnecting them from the cellular network.

A city official in Plymouth told CBS News that operators moved into a manual operation mode temporarily until the systems were brought back online, with normal communications restored by Tuesday afternoon. Still, officials say water quality, treatment and pressures were never affected, with delivery remaining undisrupted throughout.

Michael Thompson, the Plymouth Director of Public Works, told CBS News Minnesota his team first noticed there was a problem when communication between devices started to become interrupted on Sunday evening. By the early morning hours on Monday, just after midnight, Thompson said it was an all-hands-on-deck situation.

“I think you never expect it to happen to you,” Thompson said.

CISA said Thursday that it’s “currently observing a significant increase in cyber threat actors” that are targeting PLCs in the Water and Wastewater Systems sector, noting those actors are targeting “water entities of all sizes.”

“CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible,” said CISA, which is part of the Department of Homeland Security.

“Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans,” CISA added in its advisory.

Iran-linked hackers have previously targeted U.S. water utilities. Federal agencies confirmed previously that actors affiliated with Iran’s Islamic Revolutionary Guard Corps used a similar playbook, accessing multiple water and wastewater facilities in 2023 by exploiting internet-connected controllers that retained their default passwords.

Conor Wight contributed to this report.

评论

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注

湘ICP备2026001899号-2