Hackers have breached water systems in at least seven states — some attacks degraded operations — while more than half of America's water utilities operate without basic email security, according to a new industry analysis that exposes just how little Washington has done to protect the tap water Americans drink every day.

The FBI and EPA issued a joint public service announcement warning water and wastewater utilities nationwide that malicious cyber actors are attempting to disrupt critical infrastructure. Some attacks have degraded water operations. The Cybersecurity and Infrastructure Security Agency had already flagged the threat a week earlier, issuing an advisory about Iranian-linked cyber actors exploiting internet-connected critical infrastructure. Intelligence officials view Iran as the likely perpetrator, according to Baltimore News. Breitbart noted that the FBI and EPA did not publicly attribute the attacks to a specific actor — the federal advisory focused on tactics, not attribution.

The numbers are damning. Cybersecurity firm Red Sift analyzed more than 800 utility companies across water, chemical, and energy sectors. Forty-two percent lacked strong email authentication protocols. In the water and waste sector alone, 52 percent were unprotected — meaning a phishing email is often all it takes.

"If they can't get access into like devices or physical machines, the best way to get access into the organization is a person and the way you get access to people is still through emails," said Brian Westnedge, Red Sift's director of alliances and partnerships. Once inside, hackers lock out legitimate operators. If the attacker is a nation-state, ransom isn't the goal — disruption is. "Our adversaries, whether they're Iran or potentially someone like a North Korea or China, they're always looking to inflict some type of pain," Westnedge said.

In Minnesota, hackers targeted more than 30 municipal water facilities. Emily Zimmer, spokesperson for Minnesota's IT services agency, said there was no indication water supplies were contaminated. But CISA said some larger attacks nationwide led to boil water notices and sustained manual operations, though it did not disclose locations.

Wisconsin's Department of Natural Resources sent its own bulletin warning that state systems might be susceptible, citing Minnesota's report that hackers reduced system pressures — a claim Zimmer disputed. "Minnesota has not reported that threat actors lowered pressure across multiple water systems or that pressure changes prompted a law enforcement response," she said.

The political response was predictable. President Trump blamed Minnesota's leadership. "I think I blame it on Minnesota because they're grossly incompetent," he said at Camp David. "Iran should be so lucky. Iran's got bigger problems than worrying about Minnesota." Gov. Tim Walz fired back: "Trump knows exactly who is responsible for this attack, and knows that other states were hit too. This is what modern warfare looks like, and it further illustrates there's no plan to win a war with Iran."

Baltimore News framed the story around the cybersecurity failure and the Iran threat with expert analysis. Breitbart led with the FBI warning and played up the Trump-Walz political fight — and omitted the Red Sift analysis showing just how exposed these systems are.

Rep. Mike Turner, R-Ohio, a member of the House Armed Services Committee, said adversaries view civilian infrastructure as legitimate military targets. "Iran certainly has been doing this well before the conflict and this is something we certainly need to be aware of, be diligent," he said.

Homeland Security Secretary Markwayne Mullin told governors at a National Governors Association meeting that too many municipalities ignore federal warnings. "You'd be surprised how many municipalities don't pay attention to it. You'd be surprised how many states don't pay attention to it," Mullin said.

The agencies tasked with protecting this infrastructure — EPA, CISA, DHS — have known about these vulnerabilities. They've issued advisories. What they haven't done is secure the systems. The EPA regulates water safety. CISA is the nation's cybersecurity agency. DHS oversees both. And still, more than half of water utilities can't block a phishing email.

Washington can find billions for foreign aid and overseas commitments overnight. Securing the systems that keep American water flowing apparently wasn't on the list. That's not a glitch in the system. It's a choice — and Americans are the ones who'll drink the consequences.