Throughout the country, the costs of the conflict in Iran have had wide-ranging effects, and we’re not just talking about gas prices.
Dozens of municipalities across at least seven states, including Minnesota and Michigan, have reported that their water and wastewater systems were hit with cyberattacks in the last week of July. Now we know Oregon was also hit. While federal and state officials said a preliminary investigation hasn’t confirmed Iran’s involvement, the attacks mirror those the country has waged against U.S. water systems in the past, according to The New York Times. President Donald Trump claimed, without evidence, that Minnesota was responsible for its cyberattacks, not Iran.
As of press time, no municipality has reported its water quality having been compromised by the attacks.
Yet, the question remains — gulp — how’re the City of Bend’s water and wastewater systems holding up? And how often does the city get cyberattacked?
The city’s information technology director Adam Young told the Source via email that —good news — the city’s tech infrastructure was not affected by the July cyber assault. The main reason being that its infrastructure systems are not internet-facing, unlike the aforementioned attacks that targeted internet-facing systems with known vulnerabilities, Young said.
In other words, the City of Bend’s water — which is supplied by the Bridge Creek watershed and the Deschutes Aquifer and sanitized by the Outback Water Filtration Facility — is good.
“Should a cyberattack impact operational technology systems, the City’s freshwater and wastewater treatment facilities can continue operating manually,” Young said. “That helps maintain critical services while the incident is being managed and resolved.”
Alarmingly, the City of Bend experiences daily attempts to comprise its systems through phishing, social engineering, malware and other attack methods, he added. The City of Redmond’s cybersecurity team also repels thousands of attacks daily; they were not compromised in the last week of July.
“Although some threats are specifically directed at the City, most are part of large-scale campaigns targeting organizations across the public and private sectors,” Young said of Bend. “Given the evolving threat landscape, the City maintains a robust cybersecurity program and dedicated cybersecurity professionals to protect City operations, data and essential public services.”
That cybersecurity program uses a layered approach, which includes employee cybersecurity training, security controls aligned with industry frameworks, regular third-party security assessments and cybersecurity exercises. It also involves round-the-clock threat detection and plans for business continuity and incident response, according to Young.
Those security standards are set by the National Institute of Standards and Technology, a federal agency charged with advancing measurement science, standards and tech. Notably, systems supporting critical infrastructure are isolated from both the City’s business network and the public internet, “significantly reducing their exposure to external cyber threats,” Young said.
A breach, ongoing investigation
The late-July cyberattacks did temporarily disrupt the operational technology of an Oregon drinking-water provider, Michael Hanna-Butros Meyering, chief privacy and communications officer at Enterprise Information Services, told the Source. Meyering couldn’t elaborate, owing to the ongoing investigation headed by FBI and the Cybersecurity & Infrastructure Security Agency. EIS is a company whose services include handling the state’s IT and cybersecurity controls.
“With these incidents we have to be really intentional about our execution and safeguarding, so we don’t provide bad actors an opportunity to kick us while we’re down,” Meyering said. “That doesn’t feel good.”
The state has not confirmed who or which group is responsible or whether the attacks are related to those in Minnesota, Michigan and seven other states, he added.
Cyberattacks against state government technology systems aren’t unheard of. Just last year, the Oregon Department of Environmental Quality experienced such an attack, when the agency’s servers and network were targeted in a ransomware attack. To isolate the ransomware, which encrypts devices and files pending a ransom payment, EIS shut down all DEQ activities, including bricking staff computers and freezing access to its shared network. The hackers nonetheless stole more than a million files and ransomed the agency about $2.5 million in Bitcoin to get the data back, OPB reported. The damage totaled about $2 million and investigators concluded that nearly 5,000 residents’ personal data was compromised. In this instance, the ransomware group, Rhysida, auctioned some data and leaked other material when the agency didn’t pay up.
In 2020, the Federal Bureau of Investigation sounded the alarm on a nationwide ransomware carpet bombing that struck the Sky Lakes Medical Center in Klamath Falls, The Oregonian reported.








