A recent spate of cyberattacks targeting American water systems has triggered alarm across federal and state levels, with U.S. authorities reportedly suspecting Iranian-backed hackers. The FBI disclosed Thursday that "malicious cyber actors" struck water and wastewater utilities in at least seven states over a four-day period, causing a "loss of monitoring and control functionality." Officials in Michigan, Minnesota, and New Jersey have confirmed incidents.

While the precise origin of the disruptions has not been definitively established, The New York Times reported that federal investigators believe Iran-linked operatives are responsible. Security experts interviewed by The Hill note that many water treatment facilities rely on outdated technology and minimal cybersecurity measures, making them "vulnerable" to such intrusions. They caution that even if Iran's involvement is confirmed, the tactics align with Tehran's known operational patterns.

Read also
Politics
Judge Sanctions DHS for Slow-Walking Cellphone Data in L.A. Raid Case
A federal judge found DHS in contempt for delaying the release of cellphone data from over 800 immigration agents, imposing fines and legal fees after months of stalling.

Dr. Lennart Maschmeyer, an assistant professor at Georgia Tech University who studies the intersection of emerging technologies and international security, characterized the campaign as targeting "low-hanging fruit"—organizations lacking basic security protocols. He pointed to the programmable logic controllers used at the affected sites, manufactured by Allen-Bradley of Rockwell Automation, which are "highly specialized" but aging. If these systems are connected to the internet, they become susceptible to remote exploitation. "They are not equipped for dealing with state-sponsored cyberattacks," Maschmeyer said, referring to local utilities. "That's not really their job, and they cannot be realistically assumed to be prepared for all this."

The political fallout was immediate. On Friday, President Trump blamed Minnesota Governor Tim Walz for the attacks in his state, calling the 2024 Democratic vice presidential nominee "corrupt" and dismissing Iran's involvement. "They like to say, 'Oh, it was Iran.' Iran should be so lucky. Iran's got bigger problems than worrying about Minnesota," Trump told reporters at Camp David. Walz fired back, saying the attacks illustrate "what modern warfare looks like" and accusing the president of having "no plan to win" the broader conflict with Iran.

The Cybersecurity and Infrastructure Security Agency (CISA), FBI, and other agencies had issued a warning on July 22 about "ongoing Iranian-affiliated" cyber operations against water facilities, just days before the latest wave. The nation has roughly 150,000 public water systems, according to the Environmental Protection Agency, many of which operate with limited staff and legacy infrastructure.

Alex Jones, chair of the Electrical Engineering and Computer Science Department at Syracuse University, noted that the diversity of systems across different sites offers some protection. "Maybe there's some commonalities between the ones that have been targeted here... and as a result, they're taking advantage of that, but the fact that things are relatively different... for different sites does provide some benefit," Jones said.

Jeff Greene, who served in CISA during the Biden administration, highlighted that many water utilities employ only a handful of people, limiting their security capacity. While these systems "were not built with security in mind," he emphasized their resilience. "They still have a lot of manual systems, so if they need to, they can disconnect and continue to operate in a manual state," said Greene, now a principal at Civira Partners. "And to me, resilience is the ultimate and only complete defense to a cyberattack."

The incident underscores a growing threat of cyberattacks on critical infrastructure, though their wartime effectiveness remains limited. Maschmeyer referenced a 2015 Russian cyberattack on Ukraine's power grid that caused a six-hour outage, but noted no comparable high-profile cyberattacks have occurred since Russia's full-scale invasion began over four years ago. Under Trump, the U.S. military used cyberweapons to cut power in Caracas during a raid to capture former Venezuelan President Nicolás Maduro in January. U.S. forces have also targeted Iranian infrastructure with aerial strikes during the ongoing war, which surpassed the six-month mark last week.

Caitlin Durkovich, who served on the Biden White House's National Security Council, argued that the Trump administration is "normalizing" attacks on infrastructure, thereby exposing the nation to retaliation. "There was always kind of nibbling around the edges of infrastructure, it was something that was seen as off limits," said Durkovich, also a principal at Civira and a former assistant Homeland Security secretary for infrastructure protection during the Obama administration. "We have normalized it, and so I think we have increasingly placed our infrastructure on the front lines, especially in moments of geopolitical tensions and crisis."

As federal agencies continue to investigate, the attacks highlight the urgent need for improved cybersecurity across the nation's water systems. For more on the FBI's confirmation of these incidents, see the FBI's report. The political blame game has also intensified, with Trump's remarks drawing sharp rebukes from state officials. Meanwhile, experts stress that the vulnerability of these facilities is a systemic issue that requires federal attention and investment, not just partisan rhetoric.