Daily Tech Briefing
AI 科技速览

每天 5 分钟内学习 AI。获取最新的人工智能新闻,理解其重要性,并学习如何将其应用于您的工作。

AI 快讯
Wired AI · 2026/7/30 21:20:00
A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran

A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran

AI 中文解读
一份泄露的备忘录证实,今年2月美国对伊朗开战后,伊朗黑客发动了报复性攻击,这次他们把目标对准了明尼苏达州数十家水务和污水处理设施。这不仅是自战争开始以来伊朗对美国最大规模的网络破坏行动,也是罕见地针对民用基础设施的国家级黑客攻击,此前同类行为只在俄乌战争中见过。 简单来说,这些黑客并非偷数据,而是直接远程操控供水系统的核心控制器——PLC(可编程逻辑控制器),甚至修改了“安全与保护参数”。这就好比有人闯进了供水厂的控制室,乱拧阀门、改压力值,可能导致水压异常、水质污染甚至设备损坏。由于全美还有很多供水设施使用相同技术,威胁远未结束。 对普通人而言,最直接的担忧是自来水服务可能突然中断,或者接到“暂时别喝自来水”的通知。虽然目前受损范围限于明尼苏达,但专家警告这种攻击手法很可能扩散。你家的水厂是否做好防护?呼吁断开PLC与互联网连接、改用强密码等建议正在紧急下发,但普通居民能做的,是留意当地水务局的安全公告,并支持关键基础设施加大网络安全投入。
Andy GreenbergSecurityJul 30, 2026 5:20 PMA Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to IranA memo obtained by WIRED, issued by the water utilities information sharing group WaterISAC, links dozens of cyberattacks against Minnesota water utilities to Tehran.Photograph: Sir Francis Canker/Getty ImagesCommentLoaderSave StorySave this storyCommentLoaderSave StorySave this storySince the US launched its war against Iran in late February, the country’s hackers have struck back with retaliatory intrusions that have ranged from paralyzing medical supplies company Stryker to breaching the personal email of FBI director Kash Patel. Now, after an unprecedented wave of disruptive cyberattacks hit water utilities in Minnesota, a memo circulated within the water industry ties those attacks to Iran, too, in the widest and most disruptive strike yet inflicted by the country’s hackers against the US since the war began.A communication obtained by WIRED on Thursday and sent to members of the Water Information Sharing and Analysis Center, or WaterISAC, an industry group for water utilities to share cybersecurity information, links to Iran a series of cyberattacks that targeted dozens of Minnesota water and wastewater utilities.The WaterISAC note states that the Minnesota Fusion Center, a state-level intelligence-sharing entity, issued an alert “regarding ongoing malicious cyber activity impacting public drinking water systems across Minnesota” and adds that the fusion center has found that those attacks were “aligned” with a hacking campaign first described in April by the US Cybersecurity and Infrastructure Security Agency (CISA) as having been carried out by “Iran-affiliated” hackers. (Both the WaterISAC and Minnesota Fusion Center reports were marked as unclassified but “for official use only.”)Confirmation of Iran’s responsibility for hacking the water utilities represents a kind of state-sponsored targeting of civilian infrastructure that has rarely been seen outside of Russia’s war against Ukraine, says Joe Slowik, a former Los Alamos National Labs cybersecurity researcher working on contract for the Department of Energy. “Now we have documented disruption and even modification of safety and protection parameters in critical infrastructure,” Slowik says. “Seeing this sort of tradecraft expand to Iran, and seeing it across multiple sites, it should really be making people concerned right now.”Slowik adds that there’s no reason to believe that the attacks would stop with the incidents in Minnesota. “There are plenty of other sites that have the same targeted technology,” he says. “There’s plenty of areas for this to still be executed by an adversary that has shown a willingness to do so.”A new CISA advisory related to the attacks released Thursday warns that “these threat actors are targeting water entities of all sizes” and warns utilities to disconnect PLCs from the internet, password-protect access with strong passwords, and “allow-list” only trusted devices to connect to them.Earlier this week, Minnesota state officials revealed that more than 30 municipal water and wastewater systems had been targeted in hacker breaches that had in some cases disabled telecommunications between the industrial control system technologies and water utility equipment. In at least one municipality, the 1,700-person city of Braham, the hacking reportedly led to a brief outage of the city’s water plant, though there’s not yet evidence of any resulting water shortages or a threat to the safety of Minnesota’s water supply. The latest CISA advisory notes that the attacks have, however, “resulted in boil-water notices”—suggesting fears of water contamination— and “sustained manual operations.”In the days since that wave of incidents became public, Iran has emerged as the leading suspect behind the attacks, despite the lack of any official confirmation of the country’s involvement or any statement from an Iranian hacker group claiming responsibi
分享
阅读原文