Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
Michigan Joins Minnesota, Georgia and South Dakota in Water System Cyberattack Wave, FBI Still Won't Name Iran

Since Minnesota's IT services department first flagged the intrusions on its water systems earlier last week, the list of affected states has grown to at least seven, with Michigan the latest to confirm it.
Michigan's Department of Environment, Great Lakes, and Energy said Saturday it received what spokesperson Dale George called "a small number of reports from Michigan communities indicating activity consistent with what federal agencies described." George said all systems kept operating safely and there were no known impacts to public health.
A smaller-scale version of what hit Minnesota, where more than 30 community water systems were targeted, according to Minnesota IT Services (MNIT). Georgia and South Dakota have also been named as victims. Federal officials have identified at least seven states total but haven't publicly named the other three.
The FBI and the Environmental Protection Agency said Thursday that some of the attacks have "degraded water operations." The Cybersecurity and Infrastructure Security Agency (CISA) said that degradation has led some communities to issue boil water notices and switch to manual operations, according to Global News.
What the hackers are actually doing
This isn't a generic ransomware shakedown. According to CISA's advisory, the attackers are going after programmable logic controllers, the industrial devices that let operators remotely run dams, pumping stations and treatment plants from a central office.
CISA says the hackers are using third-party programming software to gain remote access to specific PLCs, extract program data, and manipulate it so water systems can enter unsafe conditions without notifying operators, bypassing the shutdown and alarm procedures that are supposed to catch exactly this kind of problem.
The agency's advisory isn't new speculation. It's a July 22 update to an earlier warning that Iranian-affiliated cyber actors were exploiting these same PLCs across U.S. critical infrastructure, water systems included, according to Global News. CISA and other agencies are telling water facilities nationwide to disconnect vulnerable PLCs from the internet, period, even organizations that think their cybersecurity is solid.
The FBI still won't say the word "Iran"
CISA's own advisory ties the exact attack technique to Iranian-affiliated hackers, but the FBI's public statement on the water system incidents only refers to "malicious cyber actors" and doesn't name a specific country or group.
"The FBI is aware of recent public reporting around Water and Wastewater (WWS) sectors," the bureau said in a Saturday statement. "The FBI is actively engaged with victims . . . This guidance emphasizes our joint commitment to support critical infrastructure entities against malicious cyber actors attempting to harm the United States."
The distinction matters. CISA flagging the Iranian-linked technique in a general advisory is not the same as the FBI formally attributing this specific wave of attacks to Tehran. Attribution in cyberattacks is notoriously hard to nail down fast, and officials pointing that out aren't necessarily covering for anyone.
Trump blames Minnesota, not Iran
President Trump rejected the Iran theory outright at a Cabinet meeting last week. "I just want to mention that we heard in Minnesota there was a cyberattack, and they blame it on Iran," Trump said. "I don't think so. I think I blame it on Minnesota because they're grossly incompetent . . . They like to say, oh, it was Iran. Iran should be so lucky. Iran's got bigger problems than worrying about Minnesota."
Governor Tim Walz pushed back hard on social media. "Trump knows exactly who is responsible for this attack, and knows that other states were hit too," Walz posted, according to The Center Square. "This is what modern warfare looks like, and it further illustrates there's no plan to win a war with Iran."
Both men are making claims the public record doesn't fully back up. Trump's blaming Minnesota's competence for an attack that's now hit at least seven states including several with no connection to Walz's administration. Walz is asserting Trump has certain knowledge of Iranian responsibility that no federal agency has confirmed on the record.
Minnesota, for its part, says its defenses worked. "This incident demonstrates why Minnesota has invested in strong cybersecurity capabilities and partnerships," said John Israel, MNIT's Assistant Commissioner and the state's Chief Information Security Officer. "Our response worked as intended, enabling agencies at every level of government to rapidly coordinate, contain the incident, and help prevent more serious impacts to critical services."
The open question is straightforward: does the FBI ever formally attribute this campaign to a specific actor, and if the answer turns out to be Iran, whether that arrives before or after the political fight over who's at fault has already hardened into partisan concrete. The three unnamed states hit alongside Minnesota, Michigan, Georgia and South Dakota also remain unidentified, and neither CISA nor the FBI has said when, or whether, that list will be made public.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.