Cyberattacks

Cyberattacks on water systems spread to 7 states

Cyberattacks have hit water systems in seven states. Photo by Sascha Steinbach/EPA

Aug. 1 (UPI) — At least seven states have suffered cyberattacks on water systems as cities and states work to keep the water supplies safe.

There has been no indication that any water supply is unsafe to drink, the New York Times reported. Minnesota first reported a cyberattack and now Michigan has also reported attacks.

The Cybersecurity & Infrastructure Security Agency said in a release that it’s “observing a significant increase in cyber threat actors targeting programmable logic controllers in the Water and Wastewater Systems sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology from the Internet as soon as possible. Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses. This activity has resulted in boil-water notices and sustained manual operations.”

Officials told The Times that Iran has increased cyberattacks on American systems, but that the water attacks haven’t been definitively declared to have come from Iran. But Iran has targeted water systems in the United States in the past. Because there’s no financial motive, an attack by hacking criminals is less likely, The Times said.

Michigan had “a small number of reports from Michigan communities indicating activity consistent with what federal agencies described,” Dale George, director of communications for Michigan’s Department of Environment, Great Lakes and Energy, told CBS News.

“All systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern,” George added.

CBS reported that more than 30 community water systems in Minnesota were affected.

On Friday, President Donald Trump blamed Minnesota and Gov. Tim Walz for the attacks.

“I think that Minnesota is behind it,” Trump said during a televised Cabinet meeting at Camp David. “You know who’s behind it? Minnesota. Because they’re grossly incompetent. I think the governor’s behind it. I don’t think there was an Iranian cyberattack. I think that Minnesota ought to get its act together.”

“They like to say, ‘Oh, it was Iran.’ Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota,” the president said.

Walz responded to the jabs from Trump in a post on X.

“DOGE took an ax to CISA and left the U.S. exposed to cyber attacks. Thankfully, our experts in Minnesota were able to identify the vulnerability quickly and work with local communities to stop it,” Walz said.

Braham, Minn., Mayor Nate George said federal and local officials don’t doubt the source.

“We’re getting bits and pieces of information from the state of Minnesota and the FBI,” George told The Times. “They are pretty sure it’s Iranian actors” but are reluctant to say so publicly.

President Donald Trump announces a program to allow veterans to expedite a career in commercial trucking on Thursday. Known as the Freedom Haulers program, the initiative would allow any veterans who drove heavy equipment to be automatically eligible for a commercial trucking license. Photo by Jim Lo Scalzo/UPI | License Photo

Source link

Michigan joins Minnesota in reporting cyberattacks, with FBI investigating | Cybercrime News

No culprit has been identified in any of the attacks, which comes after authorities warned of a possible Iranian plot.

Michigan has reported cyberattacks on nine of its water systems, days after Minnesota reported similar breaches across the state.

The United States Federal Bureau of Investigation (FBI) said it was investigating both of the attacks on Saturday. In an advisory earlier this week, it said that at least seven states have reported incidents, but so far only Minnesota and Michigan have been identified.

Recommended Stories

list of 3 itemsend of list

No culprit has yet been pinpointed. However, the breaches came after the FBI, Cybersecurity and Infrastructure Security Agency (CISA) and other agencies warned in an advisory last week that Iranian hackers have been targeting water and wastewater systems and the operational controls of other critical infrastructure sectors.

“The FBI is aware of recent public reporting around Water and Wastewater (WWS) sectors,” the agency said in a statement on Saturday. “The FBI and our interagency partners are fully engaged to protect critical infrastructure, and we remain well-equipped to protect against cyber threats of all varieties.”

Dale George, the director of communications for Michigan’s Department of Environment, Great Lakes and Energy, meanwhile, said that “all systems continued to operate safely” following the attacks.

He said Michigan received a federal cyber alert on Tuesday about attempts to tamper with operational technology in water systems.

Soon after, the state received “a small number of reports from Michigan communities indicating activity consistent with what federal agencies described”, said George.

Minnesota had earlier in the week reported attacks on 30 sites. Minnesota IT Services, the state information technology agency, said most of the confirmed attacks involved technology that water systems use to remotely monitor and control equipment.

The agency has said that impacted systems did not necessarily equate to water disruptions, noting that as of Thursday, there were no active requests for residents to modify their water usage. Some modifications had been requested earlier in the week.

Local water plants are generally more vulnerable than other infrastructure because they are more likely to have out-of-date cybersecurity. Federal law enforcement has previously indicted Iranian hackers for allegedly targeting water infrastructure.

Throughout the war, US President Donald Trump has repeatedly threatened to attack civilian infrastructure in Iran, including power and water desalination plants.

When asked about the Minnesota attacks on Friday, Trump instead pivoted to criticise the Democrat-led state government in Minnesota.

“I think Minnesota is behind it,” Trump said, without providing further evidence or clarification. “I don’t think there was an Iranian cyberattack.”

Minnesota Governor Tim Walz, meanwhile, indicated his belief that Iran was behind the attack. He further blamed Trump’s cuts to federal government employees for making the US more vulnerable to cyberattacks.

“Trump knows exactly who is responsible for this attack, and knows that other states were hit too,” Walz said.

Source link

Denmark Readies Emergency Reserve Bank to Fight Cyberattacks

To counter major cyber threats, Danmarks Nationalbank is pioneering an offline emergency payment system.

This article appears in the July/August issue of Global Finance Magazine.

Danmarks Nationalbank, the Danish central bank, has launched a financial systems security project to establish a Dormant Emergency Bank (DEB) to serve as a robust reserve bank in the event of a massive cyberattack against a large banking institution or the wider banking infrastructure in Denmark. 

The DEB proposal forms a central part of Danmarks Nationalbank’s Emergency Preparedness for Critical Financial Sector Activities in Extreme Scenarios (EP-CFSA-ES) strategic plan announced in December 2025. The plan’s bank emergency solution would enable businesses and the public to continue using payment cards, receiving salaries, and transferring money in the event of a significant cyberattack that immobilizes key financial institutions and the national banking infrastructure. 

The DEB would provide the Danish economy with an additional layer of cyber protection, according to Ulrik Nødgaard, governor of Danmarks Nationalbank. In the event of a hyper-scale cyberattack paralyzing a major Danish bank, the proposed backup DEB platform solution would activate to ensure Danish businesses and society “continued to function normally” until the cyberthreat recedes, Nødgaard said.  

Building a Contingency Net

The EP-CFSA-ES plan envisages DEB operating as a decentralized emergency bank prioritized to secure Danish society’s payment systems against a massive and prolonged AI-driven cyberattack.  

The level of threat from cybercriminals in the EP-CFSA-ES plan covers attacks that specifically result in the prolonged immobilization of banks’ IT infrastructure, a scenario that could disrupt the ability of Danish consumers and businesses to conduct normal banking transactions. 

The EP-CFSA-ES plan also includes a Card Payment Contingency (CPC) facility, enabling high street stores to keep trading during cyber-related IT outages. CPC lets consumers pay for goods and services with physical cards and mobile wallets — Vipps, Apple Pay, Google Pay, Dankort, Mastercard, and Visa — for up to seven days. Now being piloted nationwide, the system is expected to be fully operational at grocery chains and pharmacies by year-end 2026.

The CPC system works by letting store payment terminals process and store transactions offline; once reconnected, payments settle automatically with customer banks, Nødgaard said. “The technical solution developed resolves all the key issues around a significant IT outage,” he added.

Gerard O’Dwyer is a contributing writer based in Finland.

Source link