What we know about the alleged Iranian hacks on US water utilities

What we know about the alleged Iranian hacks on US water utilities

关于伊朗涉嫌攻击美国水务设施,我们目前了解的情况

Since the end of last month, several water utilities in the United States have been hit by cyberattacks, causing alarm in the country. For years, water utilities and other critical infrastructure facilities in the power sector, for example, have been targeted by hackers, whether government-backed or individuals. What makes these recent attacks — allegedly carried out by Iran — particularly concerning is how widespread they were, hitting targets in around a dozen states.

自上个月底以来,美国多家水务设施遭到网络攻击,引发了全国范围的恐慌。多年来,水务设施以及电力部门等其他关键基础设施一直是被黑客(无论是政府支持的还是个人)攻击的目标。而近期这些据称由伊朗发起的攻击之所以特别令人担忧,是因为其波及范围极广,袭击目标遍布十几个州。

The U.S. has more than 150,000 water systems, some of them run by local companies. In theory, that should make it harder for hackers to target several facilities at the same time. But on the flip side, the companies running these systems may not have the resources or cybersecurity expertise needed to protect themselves. Cybersecurity experts have long believed that Iranian hackers target low-hanging fruit in opportunistic isolated attacks, so this hacking campaign could be a significant escalation.

美国拥有超过 15 万个供水系统,其中一些由地方公司运营。理论上,这应该会增加黑客同时攻击多个设施的难度。但另一方面,运营这些系统的公司可能缺乏保护自身所需的资源或网络安全专业知识。网络安全专家长期以来一直认为,伊朗黑客倾向于通过机会主义的孤立攻击来针对“低垂的果实”(即易受攻击的目标),因此这次黑客行动可能标志着攻击力度的显著升级。

A lot has happened since news of the initial attacks broke two weeks ago. So we decided it was a good time to recap what we know so far, and what we don’t.

自两周前首次报道攻击事件以来,情况发生了很大变化。因此,我们认为现在是总结我们已知和未知信息的好时机。

Where have there been attacks?

哪些地方遭到了攻击?

On July 28, Minnesota authorities announced that water treatment plants in more than 30 communities were hit by coordinated cyberattacks. Two days later, the FBI said water and wastewater utility companies in “at least seven states” reported incidents, and in some cases the attacks “degraded water operations.” Since then, apart from Minnesota, there have been reported hacks against water facilities in Arkansas, Georgia, New Jersey, and Michigan.

7 月 28 日,明尼苏达州当局宣布,该州 30 多个社区的水处理厂遭到协同网络攻击。两天后,联邦调查局(FBI)表示,“至少七个州”的水务和废水处理公司报告了相关事件,在某些情况下,攻击导致了“水务运营质量下降”。此后,除明尼苏达州外,阿肯色州、佐治亚州、新泽西州和密歇根州的水务设施也报告了遭黑客攻击的情况。

Who is behind the attacks?

谁是幕后黑手?

The short answer is: we don’t know yet, but the No. 1 suspect is the Iranian government. As of today, officially, the U.S. government has yet to name the culprit behind the coordinated wave of hacks. However, the first incidents in Minnesota came days after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that Iranian hackers were targeting internet-connected devices in water systems and the energy sector, without saying where those attacks were occurring. (CISA had originally published this warning in April, and updated it before the Minnesota attacks.)

简短的回答是:我们尚不清楚,但头号嫌疑人是伊朗政府。截至目前,美国政府尚未正式点名这波协同攻击的幕后黑手。然而,明尼苏达州的首批事件发生前几天,美国网络安全与基础设施安全局(CISA)曾发出警告,称伊朗黑客正在针对水务系统和能源部门中连接互联网的设备进行攻击,但未说明攻击发生的具体地点。(CISA 最初于 4 月发布了此警告,并在明尼苏达州攻击事件发生前进行了更新。)

After the initial wave was uncovered in Minnesota, President Donald Trump said he did not think “there was an Iranian cyberattack.” Instead, he blamed the state, perhaps because it is run by democratic governor Tim Walz, who was chosen as Kamala Harris’ vice president candidate in the 2024 elections. Trump’s claim came a day after Wired reported that the Water Information Sharing and Analysis Center, or WaterISAC, a nonprofit group that distributes cybersecurity information among the water sector, told its members that the recent attacks “aligned” with the hacking campaign CISA warned of — effectively accusing the Iranian government.

在明尼苏达州发现首波攻击后,唐纳德·特朗普总统表示,他不认为“存在伊朗网络攻击”。相反,他指责该州,这可能是因为该州由民主党州长蒂姆·沃尔兹(Tim Walz)管理,而沃尔兹已被选为 2024 年大选中卡玛拉·哈里斯的副总统候选人。特朗普发表此言论的前一天,《连线》(Wired)杂志报道称,水务信息共享与分析中心(WaterISAC,一个在水务行业分发网络安全信息的非营利组织)告知其成员,近期的攻击与 CISA 警告的黑客行动“一致”,实际上指控了伊朗政府。

Earlier this week, The Washington Post reported that U.S. intelligence agencies “are confident” that Iran, and in particular the Islamic Revolutionary Guard Corps (IRGC), is responsible. The attribution isn’t public yet, according to the paper’s sources, because the agencies are not sure which specific unit within the IRGC was responsible, and also because officials may be reluctant to contradict Trump’s claim.

本周早些时候,《华盛顿邮报》报道称,美国情报机构“确信”伊朗,特别是伊斯兰革命卫队(IRGC)对此负责。据该报消息来源称,这一归因尚未公开,因为情报机构尚不确定伊斯兰革命卫队内部具体是哪个部门负责,同时也因为官员们可能不愿反驳特朗普的说法。

Iranian government hackers have a history of targeting critical infrastructure in the U.S., and it’s possible that these attacks are part of its strategy to retaliate against the country because of the six-month war. Until now, Iranian hackers had only limited success in their cyberattacks against U.S. targets. In March, a hacktivist group called Handala disrupted the operations of medical tech giant Stryker. The U.S. government later accused Handala of being operated by Iran’s Ministry of Intelligence and Security (MOIS). Then, the group claimed responsibility for hacking the personal Gmail account of FBI director Kash Patel.

伊朗政府黑客有针对美国关键基础设施进行攻击的历史,这些攻击很可能是其因六个月战争而对美采取报复策略的一部分。到目前为止,伊朗黑客针对美国目标的网络攻击仅取得了有限的成功。今年 3 月,一个名为 Handala 的黑客行动主义组织扰乱了医疗技术巨头史赛克(Stryker)的运营。美国政府随后指控 Handala 由伊朗情报与安全部(MOIS)操控。随后,该组织声称对入侵 FBI 局长卡什·帕特尔(Kash Patel)的个人 Gmail 账户负责。

What effects have the attacks had?

攻击造成了什么影响?

The reality is that some systems inside critical infrastructure facilities are exposed to the internet and relatively easy to find. Earlier this month, cybersecurity firm Forescout reported finding more than 2,800 controllers in U.S. water systems exposed online. If a system is exposed, it doesn’t automatically mean hackers can take over control and cause real-world effects. But that has happened in some isolated cases in recent attacks.

现实情况是,关键基础设施内部的一些系统暴露在互联网上,且相对容易被发现。本月早些时候,网络安全公司 Forescout 报告称,在美国水务系统中发现了超过 2,800 个暴露在网上的控制器。如果系统暴露,并不自动意味着黑客可以夺取控制权并造成现实影响。但在近期的攻击中,在一些孤立的案例中确实发生了这种情况。

The FBI said some of the cyberattacks around the country caused loss of pressure, which “could potentially allow untreated groundwater to seep into pipes,” and flooding. The town of Braham in Minnesota, one of the first to report an incident, had to take its water plant offline for a few hours, urging its around 1,700 residents to conserve water. The city of Maple Plain, also in Minnesota, briefly declared a state of emergency. In a county outside Atlanta, Georgia, local officials briefly told residents to boil water before using it as a precautionary measure.

FBI 表示,全国范围内的一些网络攻击导致了压力损失,这“可能导致未经处理的地下水渗入管道”,并引发洪水。明尼苏达州的布拉汉姆(Braham)镇是首批报告事件的地区之一,该镇不得不将其水厂离线数小时,并敦促其约 1,700 名居民节约用水。同样位于明尼苏达州的枫树平原市(Maple Plain)短暂宣布进入紧急状态。在佐治亚州亚特兰大郊外的一个县,当地官员曾短暂要求居民在用水前先将水烧开,作为预防措施。

The worst effect, however, may be psychological. These attacks have been widely covered in national and local press, causing people to worry about the safety of a fundamental and basic need like water. That may very well be part of the hackers’ goals: to spread panic and fear.

然而,最糟糕的影响可能是心理层面的。这些攻击在全国和地方媒体上被广泛报道,导致人们担心水这一基本生活需求的安全。这很可能就是黑客的目标之一:散布恐慌和恐惧。