Hackers breached municipal water systems across at least seven states this week, locking operators out of their own equipment and forcing some communities onto manual operations and boil-water notices — all while the federal government's vast surveillance apparatus remains trained on Americans' speech instead of securing the systems that keep the country running.
The FBI and EPA issued a public advisory Thursday confirming that water and wastewater utilities have reported cyber incidents, with some attacks degrading actual water operations. Hackers remotely accessed internet-facing devices, changed IP addresses and passwords, and stripped utilities of monitoring and control capabilities, according to the agencies. The advisory does not name the seven states.
The most significant breach hit Minnesota, where more than 30 community water systems faced what the state's IT agency called a "coordinated cyberattack" on July 26 and 27. Minnesota's chief information security officer, John Israel, said in a statement that the state has "provided relevant information to the federal government, which is evaluating this activity in the broader national context and leading efforts to determine whether it can be attributed to a specific threat actor."
Law enforcement sources told NBC News the Minnesota attack bore hallmarks of Iranian meddling. That assessment remains preliminary. CISA would not confirm any Iranian connection when contacted by the BBC. President Trump dismissed the Iran angle entirely, telling reporters at Camp David: "I think I blame it on Minnesota because they're grossly incompetent. Iran should be so lucky. Iran's got bigger problems than worrying about Minnesota."
NBC framed the attacks in the context of "the conflict in Iran" and the U.S. being "unable to find a way out of the war it started along with Israel." BBC similarly tied the incidents to "the US-Israel war in Iran and on-and-off negotiations to halt the constant stream of strikes in the region." Both outlets buried the core vulnerability: the hackers targeted specific brands of programmable logic controllers — the automated computers that run water systems — that were sitting exposed to the open internet.
Minnesota officials confirmed there were no indications the breaches contaminated any water supply. But the fact that foreign actors — or any actors — can remotely seize control of a city's water infrastructure reveals a failure that starts in Washington. The same federal government that has spent years building censorship pipelines with Big Tech, pressuring platforms to remove dissenting speech, and expanding surveillance of domestic communications somehow cannot ensure that municipal water controllers aren't dangling on the open internet with default passwords.
The federal advisory now urges operators to do what should have been mandated years ago: put controllers behind firewalls, use strong passwords, and restrict device communications through access control lists. Basic hygiene — not regime-change adventures abroad — is what actually protects Americans' water. The U.S. has 152,000 public drinking water systems and more than 16,000 wastewater systems, according to CISA, nearly all of them vulnerable to the same cheap tricks.
The question isn't whether Iran or some other actor is probing these systems. The question is why, after two decades of a federal security state that consumes trillions, the controllers that keep water flowing to American homes are still one compromised password away from shutdown.








