Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
Iran-Linked Hackers Hit Water Systems in 12 States. Hackers Volunteers, Not Washington, Are Filling the Gap

Small-town water systems across America have spent the last two weeks getting hacked, and nobody in Washington has a real plan to stop it.
Since July 27, at least seven states reported cyber intrusions to the FBI, according to Business Insider. That number has since grown to roughly 12 states, including Minnesota, Michigan, Georgia and South Dakota, according to StateScoop. Minnesota got hit hardest: more than 30 community water systems saw intruders remotely access their controls, according to Minnesota IT Services. In Braham, Minnesota, a cyberattack shut down well and treatment plant controls entirely, forcing the city to rely on stored water tower reserves, Business Insider reported.
The FBI says the attackers changed IP addresses and passwords on internet-facing devices, cutting off plant operators' ability to monitor and control their own equipment. CISA said in a July 30 alert that some attacks "have degraded water operations." The targets were Rockwell Automation/Allen-Bradley programmable logic controllers, the small industrial computers that run pumps and valves, according to SmartCitiesDive. Michigan reported nine systems hit, all still operating safely. No drinking water contamination has been reported anywhere.
Nobody's Officially Blaming Iran, But Nobody's Ruling It Out Either
CISA warned back on July 22 about "ongoing Iranian-affiliated cyber targeting" of water sector operational technology. No federal agency has publicly and formally attributed the July-August attacks specifically to Iran. The FBI calls the perpetrators only "malicious cyber actors."
Paul Nakasone, who ran NSA and Cyber Command until 2024, told reporters at DEF CON that officials are being deliberately careful before naming a culprit. "I look at intent. I look at capability. I look at history," Nakasone said, according to Defense One. "They certainly have the capability, and I think there's an intent right now, we're in conflict with Iran." That's an informed assessment from a former top cyber official, not a confirmed government finding.
The Guardian's framing leans harder into the Iran theory, citing anonymous officials who told the New York Times and Washington Post that Iran is "likely" responsible. Readers should understand the difference between "officials suspect" and "officials confirmed."
Trump Blamed Minnesota. Walz Blamed Trump.
Instead of a unified federal response message, the country got a political food fight.
Trump told a cabinet meeting at Camp David, according to The Guardian: "I blame it on Minnesota because they're grossly incompetent... I would blame it on Minnesota and the governor, the corrupt governor of Minnesota... Iran's got bigger problems than worrying about Minnesota." He offered no evidence for that claim, and it directly contradicts his own administration's CISA advisory pointing at Iran-affiliated actors months earlier.
Walz fired back on X: "Trump knows exactly who is responsible for this attack, and knows that other states were hit too. This is what modern warfare looks like, and it further illustrates there's no plan to win a war with Iran."
Both men are playing politics with an ongoing security incident. Trump's "blame Minnesota" line ignores that Michigan, Georgia and South Dakota got hit too, and that his own CISA flagged Iran-linked activity in April. Walz's "no plan to win a war with Iran" line is a fair political jab, but it also sidesteps that water utility cybersecurity has been chronically underfunded for decades under administrations of both parties.
The Real Fix Isn't Coming From Washington
While politicians argued, the actual defensive work got built by a hacker convention and a rural trade group.
DEF CON Franklin, a project of the University of Chicago Harris School's Cyber Policy Initiative, teamed up with the National Rural Water Association to launch the Water Watch Center on August 7 in Las Vegas, according to SiliconAngle. The target: utilities serving fewer than 10,000 people, which make up 91% of the roughly 50,000 community water systems in the country, per SiliconAngle's reporting. Most have no chief information security officer and no budget to hire one.
Five firms, Rapid7, Defendify, Legato Security, L1 Secure and Sentinel Technologies, signed on to provide managed detection and response services, funneling threat intelligence through NRWA as a national hub. Craig Newmark, the Craigslist founder, provided seed funding. Vanderbilt University is building digital twins of water systems using Defense Advanced Research Projects Agency research to test automated defenses.
Jake Braun, DEF CON Franklin's co-founder and a former acting principal deputy national cyber director in the Biden White House, said the firms and NRWA "are architecting a scalable cyber delivery model that has eluded water industry and national security officials to date." The federal government hasn't solved this problem. A convention and a trade association are trying.
New York took its own separate swing at the problem. Governor Kathy Hochul announced more than $9 million in SECURE grants for 153 local water projects, according to StateScoop, funding cybersecurity assessments and upgrades tied to new state mandates requiring multifactor authentication and banned default passwords. StateScoop noted New York's own press releases initially cited just $2.5 million before the total jumped to $9 million, and the governor's office didn't explain the increase when asked.
CISA's bottom-line advice hasn't changed: get programmable logic controllers off the public internet. Nakasone said it plainly at DEF CON: "These PLCs should not be exposed to the internet." Most of the roughly 148,000 public water systems in the country still don't have the staff or money to make that happen fast, and there's no federal funding bill on the table to change that math nationwide.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.