Every episode of The Daily, briefed the morning after, with up to nine more shows in one daily email.
Free for 30 days. No card needed. $4.99 a month after.
Is America’s Drinking Water the Next Front in the Iran War?
What was discussed
Overview of the water system hacks
A growing number of U.S. cities and towns have reported that their water systems were hacked, with the operation likely perpetrated by Iran. The hacks began amid the U.S.-Iran war and represent a new kind of infrastructure vulnerability affecting drinking water.
Timeline of the hacking campaign
Federal alerts about Iranian-linked hackers targeting U.S. critical infrastructure began in February at the start of the war, but escalated in mid-July when a DHS cybersecurity alert revealed hackers had gained sophisticated access to infrastructure networks. Days later, Minnesota reported widespread hacking of dozens of municipal water systems causing flooding and pressure loss, followed by similar reports in Michigan, Georgia, New Jersey, South Dakota, and eventually at least a dozen states and over 100 municipalities.
How the hackers gained access
Hackers exploited basic cybersecurity weaknesses by scanning the open internet for computers that water system operators use to remotely manage supply systems, often from home. Once inside, they showed sophistication by manipulating internal safety mechanisms that alert operators to problems like contamination or pressure issues, effectively disabling warning systems while making everything appear normal.
Current status of drinking water safety
No public disclosures confirm that drinking water has actually been contaminated as a result of these cyberattacks. However, security experts and officials express unprecedented alarm about the potential risks, noting municipalities have issued precautionary boil-water notices.
Historical precedent: 2013 dam hack
In 2013, Iranian hackers infiltrated a small dam near New York City, marking one of the first instances of a foreign government-linked cyberattack on U.S. infrastructure. The dam was fortunately offline for maintenance at the time, and the incident led to the first indictment of individuals for a foreign cyberattack on U.S. infrastructure.
Past legislative and regulatory efforts on water cybersecurity
Efforts to address water system cybersecurity include a failed 2010 Senate bill by Senators Susan Collins and Joe Lieberman that would have created cybersecurity standards for critical infrastructure. The Biden administration's EPA also attempted to set minimum security guidelines for water facilities but was sued by Republican-led states and industry groups. States have made some independent efforts, such as New York's recent $9 million investment in water cybersecurity, though funding remains a broader challenge across the roughly 150,000 water utilities nationwide.
CISA's role and its decline under the second Trump administration
The Cybersecurity and Infrastructure Security Agency (CISA), created during Trump's first term, is tasked with protecting critical infrastructure including water systems by sharing intelligence and helping states adopt cybersecurity practices. CISA also historically worked on election security, which led to conflict when its first director, Chris Krebs, affirmed the 2020 election's security, angering Trump. Under the second Trump administration, CISA has lost over 1,000 staffers, has reduced funding, and has lacked a Senate-confirmed leader throughout the term.
Political dynamics affecting the federal response
CISA, which is investigating the water system intrusions, operates with fewer resources and less influence than before, and was affected by funding lapses tied to DHS immigration enforcement disputes. President Trump publicly dismissed the Iran connection to the hacks, instead blaming Minnesota Governor Tim Walz and calling the state government incompetent, highlighting how political tensions have become intertwined with the cybersecurity response.
Why Iran has not escalated further
Despite demonstrated access to U.S. water systems, Iran has not used this capability to contaminate drinking water, possibly because doing so could provoke a severe international response and unify American and allied opinion against Iran. Another possibility is that Iran, like China's pre-positioning efforts in U.S. infrastructure, is preserving this capability as leverage for a future, more critical moment rather than an immediate escalation.
Every episode of The Daily, briefed the morning after, with up to nine more shows in one daily email.
Free for 30 days. No card needed. $4.99 a month after.
More from The Daily
Automated summaries of what was said on each show — not claims by DailyDossier and not independently verified.