🛡 VULNERABILIDADES 🛡

Trump culpa a Minnesota por ciberataques al sector del agua, generando rechazo en el mundo cibernético.

🛡CyberObservatorio
Idioma

Trump culpa a Minnesota por ciberataques al sector del agua, generando rechazo en el mundo cibernético.

Fuente: CyberScoop

**Introducción Contextual**

El reciente conflicto de ciberseguridad que ha afectado a los sistemas de agua en Minnesota ha puesto de relieve no solo la vulnerabilidad de la infraestructura crítica en Estados Unidos, sino también la complejidad de las dinámicas políticas que rodean estos incidentes. En medio de estas preocupaciones, el expresidente Donald Trump ha señalado a Minnesota como responsable de los ciberataques, sugiriendo que la incompetencia del estado es la causa, una afirmación que ha generado reacciones enérgicas entre expertos en ciberseguridad. Este tipo de acusaciones no solo desvían la atención de las amenazas reales que enfrentan las infraestructuras críticas, sino que también pueden tener implicaciones significativas para la percepción pública y la respuesta gubernamental ante ataques cibernéticos atribuidos a actores estatales, particularmente Irán.

**Detalles Técnicos**

Los ciberataques que han afectado a los sistemas de agua en Minnesota han sido atribuidos por investigadores estadounidenses a actores cibernéticos iraníes. Este tipo de ataques se clasifica como ciberespionaje, donde los atacantes buscan infiltrarse en sistemas críticos para obtener información sensible, manipular infraestructuras o causar desestabilización. En este caso, las advertencias emitidas por la Agencia de Seguridad Cibernética e Infraestructura (CISA) de EE. UU. han subrayado la naturaleza grave de la amenaza, indicando que los atacantes han estado apuntando a controladores lógicos programables (PLC) que son fundamentales en la gestión de sistemas de agua.

El uso de PLC en la infraestructura de agua es común, y su explotación puede llevar a consecuencias devastadoras, como interrupciones en el suministro de agua o la contaminación de fuentes de agua. Las recientes alertas de CISA han indicado que los grupos alineados con Irán han intensificado sus esfuerzos en este ámbito, alineándose con la actividad cibernética observada en el contexto de la guerra en curso entre Estados Unidos e Irán.

**Datos Factuales**

El expresidente Trump, en declaraciones efectuadas el pasado viernes, afirmó que "Minnesota está detrás de esto", sugiriendo que la incompetencia del estado era la raíz del problema. Sin embargo, esta afirmación fue rápidamente cuestionada por expertos en ciberseguridad, quienes señalaron que las propias agencias de inteligencia de EE. UU. atribuyen estos incidentes a Irán. Personalidades como Chris Wysopal, cofundador de Veracode, y Jake Williams, miembro de la facultad de IANS, criticaron la tendencia de culpar a las víctimas en el ámbito cibernético, señalando que el enfoque de Trump no refleja la realidad de la situación.

El gobernador de Minnesota, Tim Walz, también respondió a Trump, indicando que el ataque cibernético es un ejemplo de guerra moderna. Walz afirmó que Trump conoce la verdadera naturaleza de estos ataques y que otros estados también han sido afectados. La respuesta de Walz fue clara: "Esta es la cara de la guerra moderna, y muestra que no hay un plan para ganar una guerra con Irán".

**Impacto y Consecuencias**

Las declaraciones de Trump y la discusión en torno a los ciberataques tienen implicaciones significativas no solo para Minnesota, sino para la percepción pública de la seguridad cibernética en todo el país. La falta de un enfoque coherente y basado en hechos por parte de los líderes políticos puede socavar la confianza pública en las instituciones encargadas de la protección de la infraestructura crítica. Además, la tendencia a culpar a las víctimas puede llevar a una falta de acción adecuada y a una respuesta ineficaz ante futuras amenazas.

El sector del agua, considerado uno de los más vulnerables entre las infraestructuras críticas, enfrenta un desafío considerable. La organización WaterISAC ha expresado su preocupación por la falta de financiación y apoyo para mejorar la ciberseguridad en este sector, lo que podría dejarlo aún más expuesto a futuros ataques. La necesidad de inversión en ciberseguridad es urgente y debe ser una prioridad para el Congreso.

**Contexto Histórico**

Históricamente, Estados Unidos ha enfrentado una serie de ciberataques de diversos orígenes, incluidos ataques atribuibles a actores estatales de países como China y Rusia. Trump ha mostrado cierta indiferencia hacia estos incidentes, minimizando su gravedad en ocasiones. Su enfoque ha llevado a confusiones sobre la naturaleza de las amenazas cibernéticas y quiénes son los responsables reales. El caso de SolarWinds, donde Trump sugirió que China era el culpable en lugar de Rusia, es un claro ejemplo de esta falta de claridad.

**Recomendaciones**

Es crucial que tanto los gobiernos estatales como la administración federal adopten medidas proactivas para fortalecer la ciberseguridad en sectores críticos. Esto incluye la implementación de protocolos de seguridad más robustos, la inversión en tecnología de defensa cibernética y la capacitación continua de los empleados en el reconocimiento de amenazas cibernéticas. Además, es fundamental que las administraciones trabajen en conjunto con expertos en ciberseguridad para asegurar que las infraestructuras críticas estén protegidas contra futuras agresiones.

La colaboración entre el sector privado y las agencias gubernamentales es igualmente esencial para compartir información sobre amenazas y desarrollar estrategias efectivas de mitigación. En un mundo cada vez más interconectado, la seguridad cibernética debe ser vista como una responsabilidad compartida que requiere atención constante y recursos adecuados.

Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world

Source: CyberScoop

President Donald Trump blamed Minnesota Friday for the cyberattacks its water systems have suffered in recent days, saying the state was “behind it.” Trump said the state being “incompetent” was the issue, but it wasn’t clear whom he thought actually conducted cyberattacks that U.S. investigators haveattributed to Iran— if, perhaps, somehow Minnesota incompetently cyberattacked itself. The White House referred a request for clarification back to Trump’s remarks. “I think that Minnesota is behind it,” Trumptold reportersFriday. “Because they’re grossly incompetent. I don’t think there was an Iranian cyberattack. I think Minnesota ought to get its act together.” The White House also didn’t clarify whom the president believed was behindsimilar attacksin other states, when asked for comment. Trump has repeatedlyusedfederalpoweraggressively in Minnesota, a state led by Gov. Tim Walz, a Democrat who was on the ticket that ran against him in 2024 as the vice presidential nominee. Trump also has downplayed Iranian attacks amid the war he launched against the nation with Israel in February. A number of cyber experts quickly pushed back on Trump’s comments after he made them. “Victim blaming in cyber is so 2000 and late,” cybersecurity pioneer Chris Wysopal, Veracode co-founder and chief security evangelist, said on theBluesky social media platform.SaidJake Williams, a member of the IANS faculty: “His own intelligence services are attributing this to Iran.” Andy Jabbour — founder and CEO of Gate 15, a cybersecurity firm which provides support to the water sector — told CyberScoop that, “speaking candidly, I’m not even sure what he was actually saying or suggesting Minnesota’s government did or didn’t do.” “Attribution is tricky business,” he continued, referencingrecent alertsfrom the Cybersecurity and Infrastructure Security Agency and others. “But logically, given an ongoing war with Iran, recent statements made by Iran-aligned threat groups, with assessments that the recent activity is aligned with recent CISA warnings, given yesterday’s statements from CISA and the FBI, random unsubstantiated allegations aimed at political opponents seem reckless and are a disservice to the American people.” Walz struck back at Trump in a Facebook post, noting steps from his Department of Government Efficiency to slash federal funding. CISA has shrunken considerably under Trump, and his administration has pushed states to defend against cyberattacks that feds once countered. “Trump knows exactly who is responsible for this attack, and knows that other states were hit too,”Walz said. “This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran.” “DOGE took an axe to CISA and left the U.S. exposed to cyber attacks,” he continued. “Thankfully, our experts in Minnesota were able to identify the vulnerability quickly and work with local communities to stop it.” A spokesperson for Minnesota IT Services, a state agency that has been responding to the water cyberattacks, declined to address Trump’s remarks. “We remain focused on supporting affected communities, securing critical infrastructure and coordinating with local partners and federal officials as the investigation continues,” the spokesperson, Emily Zimmer, told CyberScoop. “We will not comment on political statements or speculate about attribution.” Other cyber professionals declined to comment directly on Trump’s remarks, but offered thoughts on who was behind the attacks and their motives. Bryson Bort, CEO and founder of Scythe said the evidence supports the attribution with Iran, and that it looks like hackers there found something they could exploit on the internet and seized the chance. “This was a target of opportunity,” said Bort, co-founder of the ICS Village, a non-profit advancing awareness of industrial control system security; such systems are common in the water sector. “It wasn’t that Minnesota did something as a state to raise Iran’s ire.” Cynthia Kaiser, a former top FBI cyber official, said that when the bureau conducts attributions, it looks at technical indicators but also who has the capability, who has conducted similar attacks in the past and what the purpose of the attacks is. “Iran ticks all these kinds of things,” Kaiser, now senior vice president at cybersecurity firm Halcyon, told CyberScoop. “My view is, if it walks like a duck, if it talks like a duck, I strongly suspect it’s a duck. I’d be shocked if we found out it wasn’t Iran.” Just last week, CISA updated an advisory about how Iranian hackers were targeting programmable logic controllers in the water sector and other sectors, a warning that the water industry’s information sharing and analysis center said it believed. “WaterISAC is confident in our government partners’ assessment that the confirmed activity is aligned with the joint Cybersecurity Advisory (CSA) AA26-097A ‘Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across U.S. Critical Infrastructure’ published and recently updated by CISA,” Tom Dobbins, executive director, WaterISAC, told CyberScoop. “We have evidence of earlier attacks from Iran even before this current conflict. Cyber attacks are the most viable way that Iran can directly attack our homeland, and it is logical that they would do so, especially given the challenges of absolute attribution.” The water sector is often viewed as one of the most vulnerable critical infrastructure sectors, and Dobbins called on Congress to provide funding to provide funding for the ISAC. Trump has previously displayed a laissez-faire view toward other cyberattacks on the United States, such as when he’s been asked about Chinese and Russian cyberattacks and Trumpshrugs them offas something America does, too. He also has cast doubt before on his government officials’ assessments of who’s responsible for cyberattacks on the United States, such as when heasserted China rather than Russiawas behind the landmark SolarWinds breach. The postTrump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber worldappeared first onCyberScoop.