The FBI Warns That Water Systems Were Hacked in Seven States This Week, as Trump Refutes the Iran Theory.

Featured Story

According to a joint public service announcement from the FBI and the Environmental Protection Agency, cyberattacks on municipal water systems were detected in at least seven states this week, with malicious activity degrading water operations in some cases. The feds declined to identify the states.
A water tower in Plymouth, Minnesota, was damaged on Thursday as a result of a cyberattack on the operating technologies of more than 30 water utilities throughout the state. Ellen Schmidt/AP Photo/Ellen Schmidt.

The warning comes just days after we reported that a “coordinated cyberattack” struck more than 30 community water systems in Minnesota on July 26-27, knocking the water plant in tiny Braham offline for a stretch, forcing Plymouth and South St. Paul to operate manually, and prompting Maple Plain to declare a local state of emergency, according to Just The News.

According to federal investigators, the plan was simple but effective: attackers remotely accessed internet-facing operational technologies, changed device IP addresses and passwords, and locked utility workers out of their own monitoring and control systems, NBC News reported. The PSA is now pleading with utilities to perform the very minimum: remove programmable logic controllers from the open internet and place them behind gateways and firewalls, use proper passwords, and limit which devices can communicate with one another.

(Yes, in 2026, a sizable proportion of the equipment managing America’s drinking water are still on the public internet, some with stupidly basic passwords.)

CISA followed up on Thursday with an advice warning that Iranian-affiliated actors are targeting key infrastructure in the United States, including water and wastewater systems – an update to guidance issued by the agency in April, which we previously covered. According to the cautionary notes, several of the larger water-sector incursions resulted in boil-water notices and forced plants to operate manually for longer periods of time. CISA’s top-line solution is the same one it has been using for years: restrict direct internet access to control systems.

Except that Washington cannot agree on who did it.

Multiple US sources have told ABC News that the Minnesota attacks could be related to Iran, and investigators’ preliminary findings apparently tilt in the same direction – with the proviso that this could change. Meanwhile, President Trump denied it. Speaking to reporters at Camp David on Friday, Trump dismissed the Iran theory – “Iran should be so lucky,” he said – and instead blamed Minnesota’s grossly incompetent and corrupt leadership under Gov. Tim Walz, claiming Tehran has bigger problems than the Gopher State’s pump stations.

Trump:

They like to remark, “Oh, this is Iran. Iran should be so fortunate.”

Iran has larger problems than worrying about Minnesota. https://t.co/4FnVLLzSmY pic.twitter.com/9HMP4RTcii — Adam Scott (@chefcascottccc) July 31, 2026

Cybersecurity Veteran Morgan Wright, creator of the National Center for Open and Unsolved Cases, told The Hill that Iran is the most likely culprit, citing the CISA advice as one indicator. Wright stated that while the United States may dominate on land and at sea, Tehran is able to punch above its weight class in cyberspace. Federal officials, for their part, warn that attribution requires thorough technical examination in conjunction with larger threat intelligence – otherwise, it appears to be the same nakedly transparent propaganda we’ve been given for decades (duh).

That being said, there is precedent, as noted in our Minnesota article, if we trust the official stories. In November 2023, the IRGC-linked CyberAv3ngers took control of a device at the Municipal Water Authority of Aliquippa in Pennsylvania. In early 2024, the Cyber Army of Russia Reborn claimed responsibility for attacks on water infrastructure in the United States and Poland, including a breach in Muleshoe, Texas that discharged tens of thousands of gallons of water. In October 2024, American Water, the country’s largest regulated water provider, shut down computer systems following a cyberattack. According to CISA, Beijing’s Volt Typhoon has stealthily pre-positioned itself inside vital infrastructure networks in the United States for several years. And only weeks ago, the Iranian MOIS-linked Handala persona claimed to have infiltrated California Water Service, which serves approximately 2 million consumers, exposing 5 terabytes of data, and then pledged via Tehran’s Press TV to continue targeting US industrial control systems.

Don't Miss

Meta Didn’t Notice Hundreds of AI-Powered Ads Involving Child Abuse. Some of the Images Contain Actual Children

By Stevie Ray

BY SRH In response to a report by WIRED, Meta removed approximately 50 advertisements from Facebook, Instagram, and Threads early last month that contained explicit…

United States Homeowners Feel the Strain of High Mortgage Rates, Leading to a 10% Surge in Foreclosures

By Stevie Ray

As high mortgage rates and high monthly payments squeezed American homeowners, foreclosure filings rose 10% in July. ATTOM data shows about 40,000 houses entered foreclosure throughout…

Nike Exits S&P 100 Following Nearly 80% Drop from Peak

By Stevie Ray

BY SRH After a precipitous fall in market value, sportswear behemoth Nike—which for years alienated conservatives by endorsing Colin Kaepernick and putting far-left politics into…

Unpredictable Spike in Chinese Oil Demand Pushes Shanghai Crude Price Over $100, Setting the Stage for Brent Prices to Follow

By Stevie Ray

One of the reasons why the price of oil failed to soar during the “actively kinetic” phase of the Iran war, when shipments through Hormuz…

When the Margins Vanish

By Stevie Ray

BY SRH Focusing on financial mechanics rather than tangible restrictions makes historical comparisons for what’s coming inaccurate. Energy and industrial capacity increased during the 1930s…

Posted in

Stevie Ray

Leave a Reply

Your email address will not be published. Required fields are marked *