Hastings was not among the more than 30 Minnesota communities whose water systems were targeted during a coordinated cyberattack in late July, according to City Administrator Dan Wietecha. The …
This item is available in full to subscribers.
To continue reading, you will need to either log in, using the login form, below, or purchase a new subscription.
If you are a current print subscriber, you can set up a free website account and connect your subscription to it by clicking here.
Otherwise, click here to view your options for subscribing.
Please log in to continue |
Hastings was not among the more than 30 Minnesota communities whose water systems were targeted during a coordinated cyberattack in late July, according to City Administrator Dan Wietecha.
The attacks occurred July 26 and 27, when someone gained unauthorized access to operational technology used by community water systems around the state. State and federal authorities began investigating after several cities reported disruptions involving equipment used to monitor or operate their water infrastructure.
Wietecha said Hastings officials are not aware of any attempt to enter the city’s system during the incident.
When asked whether Hastings had been affected by the statewide attack, Wietecha responded, “No, it did not.”
He also said he was not aware of an unsuccessful attempt that had been stopped by the city’s security systems.
Although Hastings was not directly affected, city officials reviewed their equipment and settings after learning what had happened elsewhere.
“We do have cyber-security measures in place to reduce such vulnerabilities and to protect our infrastructure,” Wietecha said. “We also reviewed our configurations after learning of the cyber-intrusions other cities had experienced.”
The statewide attacks targeted systems involved in operating water and wastewater facilities. Minnesota officials described the incidents as a coordinated cyberattack against more than 30 community water systems.
Four communities, Braham, Maple Plain, Plymouth and South St. Paul, publicly reported being affected. Some communities temporarily asked residents to limit water use while employees worked to regain full control of their systems.
In Braham, the attack briefly shut down operating controls for the city’s well and water treatment plant. The community relied on water stored in its water tower while the problem was addressed.
Despite the disruptions, officials reported no widespread concerns about drinking water quality. State officials also said they were not aware of any active requests for Minnesotans to change their drinking water use after the initial problems were resolved.
The attacks involved operational technology, the equipment and computer systems used to monitor and control physical processes. In a water system, that can include pumps, wells, treatment equipment, pressure controls, storage tanks and other parts of the water distribution network.
Wietecha said his understanding was that someone outside the affected communities obtained access to their supervisory control and data acquisition systems.
A supervisory control and data acquisition system, commonly called SCADA, allows employees to monitor equipment and control parts of a utility system from a central location. The technology can help water departments operate efficiently, identify problems and respond quickly when equipment needs attention.
Because SCADA equipment can control physical machinery, unauthorized access can create problems beyond a typical computer outage. An intruder could potentially alter equipment settings, disable controls or interfere with the normal operation of pumps and other machinery.
Federal officials have warned that water and wastewater utilities are increasingly being targeted by hackers. Investigators have been examining attacks involving programmable logic controllers, devices that automatically direct machinery and other equipment based on programmed instructions.
The Minnesota attacks were part of a broader series of incidents involving water utilities in several states. Federal agencies have not publicly identified who was responsible for the attacks, and the investigation remains underway.
While Hastings residents were not asked to conserve water or take other precautions, the attacks offered another reminder that cybersecurity is becoming an important part of maintaining public infrastructure.
Water systems once depended largely on mechanical controls and employees working directly at treatment plants, wells and pumping stations. Modern systems often use computers and connected equipment to monitor operations, collect information and make adjustments.
Those tools can make a utility more efficient, but they also create potential entry points that must be protected.
For Hastings, the immediate result of the statewide incident was a review rather than an emergency response. City officials found no indication that the local water system had been compromised, and no service changes were reported.
The city’s cybersecurity measures are intended to reduce the possibility of unauthorized access and protect the infrastructure residents rely on each day. Wietecha did not provide specific details about those protections, which could themselves provide useful information to someone attempting to enter the system.
For now, Hastings officials say the city avoided the problems experienced elsewhere, while using the incident as an opportunity to take another look at local safeguards.