A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran
A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran
泄露备忘录显示:明尼苏达州水务设施遭网络攻击与伊朗有关
Since the US launched its war against Iran in late February, the country’s hackers have struck back with retaliatory intrusions that have ranged from paralyzing medical supplies company Stryker to breaching the personal email of FBI director Kash Patel. Now, after an unprecedented wave of disruptive cyberattacks hit water utilities in Minnesota, a memo circulated within the water industry ties those attacks to Iran, too, in the widest and most disruptive strike yet inflicted by the country’s hackers against the US since the war began.
自美国于二月下旬对伊朗发动战争以来,伊朗黑客进行了报复性入侵,范围从瘫痪医疗用品公司 Stryker 到入侵联邦调查局局长卡什·帕特尔(Kash Patel)的个人电子邮件。如今,在一波针对明尼苏达州水务设施的前所未有的破坏性网络攻击发生后,水务行业内部流传的一份备忘录将这些攻击也指向了伊朗。这是自战争开始以来,伊朗黑客对美国发动的规模最大、破坏性最强的打击。
A communication obtained by WIRED on Thursday and sent to members of the Water Information Sharing and Analysis Center, or WaterISAC, an industry group for water utilities to share cybersecurity information, links to Iran a series of cyberattacks that targeted dozens of Minnesota water and wastewater utilities.
《连线》(WIRED)周四获得的一份通讯文件显示,该文件被发送给了水务信息共享与分析中心(WaterISAC)的成员——这是一个供水务设施共享网络安全信息的行业组织。该文件将针对明尼苏达州数十家水务和废水处理设施的一系列网络攻击与伊朗联系了起来。
The WaterISAC note states that the Minnesota Fusion Center, a state-level intelligence-sharing entity, issued an alert “regarding ongoing malicious cyber activity impacting public drinking water systems across Minnesota” and adds that the fusion center has found that those attacks were “aligned” with a hacking campaign first described in April by the US Cybersecurity and Infrastructure Security Agency (CISA) as having been carried out by “Iran-affiliated” hackers. (Both the WaterISAC and Minnesota Fusion Center reports were marked as unclassified but “for official use only.”)
WaterISAC 的备忘录指出,州级情报共享机构“明尼苏达州融合中心”(Minnesota Fusion Center)发布了一项警报,内容涉及“正在影响明尼苏达州各地公共饮用水系统的恶意网络活动”。备忘录补充说,融合中心发现这些攻击与美国网络安全与基础设施安全局(CISA)在四月份首次描述的一场黑客行动“一致”,该行动被认定是由“伊朗关联”黑客实施的。(WaterISAC 和明尼苏达州融合中心的报告均被标记为非机密,但仅供“官方使用”。)
Confirmation of Iran’s responsibility for hacking the water utilities represents a kind of state-sponsored targeting of civilian infrastructure that has rarely been seen outside of Russia’s war against Ukraine, says Joe Slowik, a former Los Alamos National Labs cybersecurity researcher working on contract for the Department of Energy. “Now we have documented disruption and even modification of safety and protection parameters in critical infrastructure,” Slowik says. “Seeing this sort of tradecraft expand to Iran, and seeing it across multiple sites, it should really be making people concerned right now.”
曾为美国能源部提供合同服务的洛斯阿拉莫斯国家实验室前网络安全研究员乔·斯洛维克(Joe Slowik)表示,确认伊朗应对此次水务设施黑客攻击负责,代表了一种国家支持的针对民用基础设施的攻击行为,这在俄罗斯对乌克兰的战争之外极为罕见。“现在我们已经记录了关键基础设施中安全和保护参数的破坏甚至篡改,”斯洛维克说,“看到这种手段扩展到伊朗,并且在多个地点出现,这确实应该引起人们的担忧。”
Slowik adds that there’s no reason to believe that the attacks would stop with the incidents in Minnesota. “There are plenty of other sites that have the same targeted technology,” he says. “There’s plenty of areas for this to still be executed by an adversary that has shown a willingness to do so.”
斯洛维克补充说,没有理由认为这些攻击会随着明尼苏达州的事件而停止。“还有很多其他地点使用了相同的目标技术,”他说,“对于一个已经表现出意愿的对手来说,仍有大量区域可以执行此类攻击。”
A new CISA advisory related to the attacks released Thursday warns that “these threat actors are targeting water entities of all sizes” and warns utilities to disconnect PLCs from the internet, password-protect access with strong passwords, and “allow-list” only trusted devices to connect to them.
CISA 周四发布的一份与此次攻击相关的新公告警告称,“这些威胁行为者正在针对各种规模的水务实体”,并提醒各设施将可编程逻辑控制器(PLC)与互联网断开,使用强密码保护访问权限,并仅允许受信任的设备连接。
Earlier this week, Minnesota state officials revealed that more than 30 municipal water and wastewater systems had been targeted in hacker breaches that had in some cases disabled telecommunications between the industrial control system technologies and water utility equipment. In at least one municipality, the 1,700-person city of Braham, the hacking reportedly led to a brief outage of the city’s water plant, though there’s not yet evidence of any resulting water shortages or a threat to the safety of Minnesota’s water supply. The latest CISA advisory notes that the attacks have, however, “resulted in boil-water notices”—suggesting fears of water contamination— and “sustained manual operations.”
本周早些时候,明尼苏达州官员透露,超过 30 个市政水务和废水处理系统遭到黑客入侵,在某些情况下,这些入侵切断了工业控制系统技术与水务设备之间的通信。据报道,在至少一个拥有 1700 人的布拉汉姆市(Braham),黑客攻击导致该市水厂短暂中断,尽管目前尚无证据表明这导致了缺水或对明尼苏达州供水安全构成威胁。CISA 的最新公告指出,这些攻击确实“导致了煮沸用水通知”(暗示对水污染的担忧)以及“持续的手动操作”。
In the days since that wave of incidents became public, Iran has emerged as the leading suspect behind the attacks, despite the lack of any official confirmation of the country’s involvement or any statement from an Iranian hacker group claiming responsibility. In a report published Monday, cybersecurity firm Tenable wrote that signs suggested CyberAv3ngers, an Iranian hacker group tied to the Iranian Revolutionary Guard Corps, may be responsible for the water utility breaches, noting that “the operational pattern is consistent with” the group or hacking groups associated with it. Separately, The New York Times reported Thursday that US and state officials and others familiar with the hacking incidents had concluded the Minnesota attacks were “likely” carried out by Iranian state-sponsored hackers, but without naming a specific group.
自这波事件公开以来的几天里,尽管缺乏官方确认或伊朗黑客组织的认领声明,伊朗已成为此次攻击的主要嫌疑对象。网络安全公司 Tenable 在周一发布的一份报告中写道,有迹象表明与伊朗伊斯兰革命卫队有关联的伊朗黑客组织 CyberAv3ngers 可能对此次水务设施入侵负责,并指出“其操作模式与该组织或其关联黑客组织一致”。另外,《纽约时报》周四报道称,美国和州政府官员以及其他知情人士已得出结论,明尼苏达州的攻击“很可能”是由伊朗国家支持的黑客实施的,但未指明具体组织。
In its report on the Minnesota water cyberattacks, Tenable pointed to an advisory from CISA that was initially released in April but was updated last week, warning that Iran-linked actors were targeting programmable logic controllers (PLCs) used for automation and coordination in critical infrastructure to cause “operational disruption and financial loss.” That advisory specifically pointed the finger at an “Iranian-affiliated” hacker group and noted that CyberAv3ngers specifically had carried out similar targeting of PLCs.
Tenable 在关于明尼苏达州水务网络攻击的报告中提到了 CISA 最初于四月发布、上周更新的一份公告。该公告警告称,与伊朗有关联的行为者正在针对关键基础设施中用于自动化和协调的可编程逻辑控制器(PLC)进行攻击,以造成“运营中断和经济损失”。该公告明确指向一个“伊朗关联”黑客组织,并指出 CyberAv3ngers 曾专门针对 PLC 进行过类似攻击。
The updated advisory, however, still doesn’t mention the Minnesota attacks—only the timing of its update on July 22 suggests a connection to the more recent hacking of the state’s water utilities. The WaterISAC memo is the first official document to explicitly draw that connection, tying the attack to Iran.
然而,更新后的公告仍未提及明尼苏达州的攻击事件——只是其 7 月 22 日的更新时间暗示了与近期该州水务设施遭黑客攻击的关联。WaterISAC 的备忘录是第一份明确建立这种联系并将攻击指向伊朗的官方文件。
The WaterISAC memo states that, according to the Minnesota Fusion Center, the hackers who targeted the water utilities compromised remotely accessible PLCs, just as in the earlier hacking campaign described by CISA, “with the likely desired impact to cause loss of system pressure and potential contamination of the water supply.” The memo adds that the facilities “were able to mitigate further compromise, but the full impact is still being assessed.”
WaterISAC 的备忘录指出,据明尼苏达州融合中心称,针对水务设施的黑客入侵了可远程访问的 PLC,正如 CISA 此前描述的黑客行动一样,“其可能的意图是导致系统压力损失和潜在的供水污染。”备忘录补充说,这些设施“已能够减轻进一步的损害,但全面影响仍在评估中。”
In the wake of the cyberattacks earlier this week, Minnesota officials said that all drinking water is still safe, and statements from multiple targeted municipalities emphasized that failsafes had protected the systems. “While the incident affected certain automated controls, established contingency procedures were immediately implemented, allowing Public Works staff to maintain normal water and wastewater operations,” South St. Paul officials wrote in a statement.
在本周早些时候的网络攻击发生后,明尼苏达州官员表示所有饮用水仍然安全,多个受影响的市政当局发表声明强调,故障安全机制保护了系统。“虽然此次事件影响了某些自动化控制,但已立即实施了既定的应急程序,使公共工程人员能够维持正常的水务和废水处理运营,”南圣保罗市官员在一份声明中写道。