Tangle - The cyberattacks on U.S. water systems.
Episode Date: August 4, 2026On Thursday, the Cybersecurity and Infrastructure Security Agency (CISA) issued an alert about potential cyber threats to water systems after approximately 36 sites in Minnesota reported cyb...erattacks. Then, on Saturday, Michigan reported cyberattacks on nine water systems; both states say their water supplies are not actively threatened. Separately, the Federal Bureau of Investigation (FBI) said that attacks have been reported in at least seven states. Federal authorities are investigating the source of the threat, which U.S. investigators believe bears the hallmarks of cyberterrorist groups linked to Iran.Ad-free podcasts are here!Get 20% off your first year of ad-free episodes, exclusive interviews, and deep dives with Tangle’s podcast membership!Following up on wildfires.Two weeks ago, Managing Editor Ari Weitzman wrote a take on the Canadian wildfires, arguing that climate change was the lead driver of the increased fires but that Canada could still do more to mitigate them. Some Tangle readers pushed back on both claims, so Ari put their questions to climate scientist (and author of the newsletter The Climate Brink) Zeke Haufather. Zeke weighed in on the science and the policy, as well as the role data centers will play in climate change in the coming years. You can listen here.You can read today's podcast here and today’s “Have a nice day” story here.You can subscribe to Tangle by clicking here or drop something in our tip jar by clicking here. Take the survey: How worried are you by these attacks? Let us know.Our Executive Editor and Founder is Isaac Saul. Our Executive Producer is Jon Lall.This podcast written by: Ari Weitzman and audio engineered and edited by Dewey Thomas. Music for the podcast was produced by Diet 75.Our newsletter is edited by Managing Editor Ari Weitzman, Senior Editor Will Kaback, Bailey Saul, Audrey Moorehead, and Carina Pacheco. Hosted on Acast. See acast.com/privacy for more information.
Transcript
Discussion (0)
From executive producer Isaac Saul, this is Tangle.
Good morning, good afternoon, and good evening, and welcome to the Tangle podcast,
the place where you get views from across the political spectrum, some independent thinking,
and a little bit of RATIC. This is Tangle's managing editor Ari Weitzman. It's Tuesday,
and that can only mean one thing. This is the part where you say what the thing is,
because I honestly don't really know.
I mean, for me, Tuesdays always kind of lacked an identity.
It's not the weekend.
It's not the beginning of the week, really,
and it's not the midweek either.
It's just kind of there, like a rock and a stream.
And when you think about it, days of the week are all kind of weird.
We've got the 365 numbered days to track the solar cycle
and Roman months to track the lunar cycle, more or less.
So why do we need another cycle of days named after the North
gods to also poorly tracked lunar cycle. I'm going to actually stop there. I have a lot to say
about calendars, as you probably could have guessed, but today we're talking about these water
system hacks. We're also going to give a look at the history of attacks on municipal systems like
these and a story about an upstanding restaurateur. It's going to be a jam-packed, quick
edition that should please tear the one-handed Norse God of Justice after him Tuesday is named.
Enough about that. I'm going to send it over to John to get a start.
Thanks, Ari, and welcome, everybody. Here are your quick hits for today.
First up, the House Ethics Committee recommended that Representative Chuck Edwards
be censured after finding substantial reason to believe that he made inappropriate
sexual advancements toward two female House staffers. Number two, President Donald Trump,
said U.S. Attorney Janine Piro choked in deciding to drop charges against a man accused of vandalizing
the reflecting pool in Washington, D.C. Piro said contractors were responsible for damage to the pool.
Number three, police arrested a man in connection with the wildfires in Spokane County, Washington,
which have destroyed over 700 structures and forced approximately 65,000 people to evacuate.
Number four, 25 Democratic-led state sued the Trump administration over its new tariffs on 60 U.S.
trading partners, alleging the president did not have the authority to impose the duties.
And number five, Michigan health officials reported two deaths linked to the ongoing cyclospora outbreak
in the state, the first confirmed deaths in the U.S. related to the outbreak.
Tonight, the FBI warning cities across the country about cyber attacks to municipal water systems,
writing utility companies in at least seven states have reported incidents to the FBI,
and some of that activity degraded water operations. In Minnesota,
alone, more than 30 municipal water systems have been targeted, and a senior law enforcement official
has told NBC News that attack bears all the hallmarks of Iranian-backed hackers. Though today, President Trump
denied Iran was behind it. On Thursday, the cybersecurity and infrastructure security agency issued
an alert about potential cyber threats to water systems after approximately 36 sites in Minnesota
reported cyber attacks. Then on Saturday, Michigan reported cyber attacks on nine water systems. Both
states say their water supplies are not actively threatened. Separately, the Federal Bureau of
Investigation said that attacks have been reported in at least seven states. Federal authorities are
investigating the source of the threat, which U.S. investigators believe bears the hallmarks of cyberterrorist
groups linked to Iran. According to Minnesota IT services, the attacks primarily targeted technology
to remotely monitor and control water systems equipment. In one of the most serious cases,
attackers shut down the operating controls for the well and water treatment plant in the city
Bram, prompting officials to ask residents to minimize water use. The request was lifted after a few
hours. As of Thursday, the state had no active requests for communities to modify their water use.
In Michigan, a spokesman for the Department of Environment, Great Lakes, and Energy said that a small
number of reports from Michigan communities indicated activity consistent with what federal agencies
described, but all water systems were operating safely. The FBI has not disclosed the other five
states where attacks were reported. In the wake of the attacks, U.S. officials said the source
or sources of the threat are still under investigation, but the incidents resemble past attacks
by Iranian hackers. Furthermore, no financial motive has been uncovered, reducing the likelihood
that criminal groups were behind the hacks. Bram Mayor Nate George told the New York Times that
the state and FBI had relayed to him that they are pretty sure it's Iranian actors, but were not
ready to say so publicly. However, President Donald Trump suggested Minnesota was at fault for the attacks
telling reporters on Friday, they blame it on Iran. I don't think so. I think I blame it on Minnesota
because they're grossly incompetent. Minnesota Governor Tim Walsh responded,
Trump knows exactly who is responsible for this attack, adding, this is what modern warfare
looks like, and it further illustrates there's no plan to win a war with Iran.
Today, we'll share views from the left and the right on the cyber attacks, and then managing
editor Ari Weitzman will give his tape.
We'll be right back after this quick break.
All right, first up, let's start with what the left is saying.
Many on the left say the federal government is responsible for defending against these threats.
Some criticize Trump's response to the attacks.
Others say the incidents should spark improvements in cyber safety.
In the New York Times, Jen Easterly argued small towns shouldn't have to defend America's water supply from Iran.
The attacks tentatively attributed to Iran expose a dangerous mismatch at the heart of American cybersecurity.
The threat is geopolitical, while the defense is municipal.
We are asking small towns, many with no dedicated cybersecurity staff members and little money
despair, to protect essential infrastructure against hackers linked to other nations, Easterly wrote.
Non-state hackers do not respect the jurisdictional line separating federal, state, and local
responsibility. They search for the most vulnerable way to disrupt American life, and too often
they find it in small communities that lack the resources to defend themselves.
Cuts to federal cyber defense support are weakening America's cyber defenses, and Washington
should reverse course. Congress should restore federal support for the multi-state information
sharing center and commit at least $3 billion in new multi-year funding to the state and local
cybersecurity grant program, Easterly said. Cyber attacks will continue and some will succeed.
The task is to ensure that a digital intrusion does not become a public health disaster.
In an era of nation-state cyber conflict, the ultimate measure of resilience is brutally simple.
When attackers get in, clean water must still come out.
In MS now, Steve Bannon said the Democrats' criticism is rooted in fact.
Even for a president who increasingly treats Democratic-led states as undeserving of federal support and resources,
Trump's eagerness to blame Americans for cyber attacks that appear to have come from Iran was quite bonkers, Benin wrote.
To hear the president tell it, Minnesota hacked itself, which is every bit as absurd as it sounds.
Time will tell whether Trump continues to blame Americans for this and again questions the existence of the cyber attacks.
but as the story unfolds, several Democratic officials are increasingly raising difficult questions
about the Republican administration and its record. For example, Minnesota Governor Tim Walz,
whom the president appeared desperate to condemn on Friday, responded to the president by noting
the Trump administration's cybersecurity cuts, Benin said. The president, who blamed Americans for
the cyber attacks, is the same president who, just a few months into his second term,
fired a series of national security officials. Ten months later, at least seven states are dealing with
cyber attacks on domestic water systems? Is the president trying to deflect blame out of petty partisanship,
or is he trying to deflect attention away from his own record? In Forbes, Steve Weissman asked if the
cyber attacks will be a wake-up call. Water systems have long been particularly attractive targets for
our adversaries, as these utilities provide essential services, but often use outdated industrial control
systems with many water systems lacking even basic cybersecurity precautions, Weissman wrote.
According to the EPA, 70% of federally inspected water utilities failed to meet necessary cybersecurity standards.
The attack against the Minnesota water facilities occurred only four days after SISA issued a warning that Iranian-backed hackers were targeting critical infrastructure,
including water systems through attacking internet-connected automated devices used to manage infrastructure systems.
There are specific steps that can be taken to reduce the threat of similar attacks, Weissman said,
removing internet exposure of industrial control systems, using complex passwords,
requiring multi-factor authentication for remote access,
continuous vulnerability scanning and monitoring,
replacement of out-of-date equipment and regular software updating of software programs with security patches,
cybersecurity training for personnel,
increased federal funding to small utilities that lack proper cybersecurity personnel.
We've long been warned for years about this problem and the fixes,
many of which are easily achievable and are long overdue.
All right, that is it for what the left is saying, which brings us to what the right is saying.
Many on the right argue that local leaders need to do a better job of defending against cyber attacks.
Others say the incidents underscore the need for strengthened infrastructure.
Some question Trump's response to the attacks.
In PJ media, David Mani suggested that the attacks raise a hard question for every mayor.
The FBI says hackers have already reached municipal water controls in at least seven states, Mani wrote.
Federal inspectors have warned about weak municipal defenses for,
years. More than 70% of the water systems inspected since September
2023 violated basic federal risk and emergency planning
requirements. Inspectors found default passwords, shared staff
logins, and accounts that remained active after employees left.
Mayors and city councils should demand a current inventory of every
internet-connected control device, the date of the last
independent assessment, proof that default passwords are gone and a
tested plan for manual operation, Mani said. We're left with a binary
choice that every mayor owns now. Either the water system has been secured or the town is waiting for
a hacker to discover what local leaders failed to fix. The Washington Post editorial board said the
breaches showed the vulnerability of U.S. infrastructure. The episode is a frightening reminder of the urgent
need to harden critical infrastructure, the board wrote. The United States has around 170,000 water
and wastewater systems, which are increasingly automated and vulnerable to attack. Such dispersed
infrastructure is a strength in that no single attack can bring down the country's water sector.
But it is also a weakness as smaller utilities with aging operational and IT systems
often have limited resources or technical capacity to protect themselves.
Hopefully, the recent attacks jolt utilities into taking their defenses more seriously.
Even a little can go a long way, the board said.
The government accountability office found that many systems lack basic cyber hygiene,
such as changing default passwords or updating operating systems.
the federal government can also help streamline the overlapping government regulations that hinder utilities defenses.
As artificial intelligence supercharges the cyber capabilities of nefarious actors,
Americans cannot afford operators to be asleep at the pump.
In National Review, Jim Garrity wrote about the cyber attacks that President Trump doesn't want to acknowledge.
Considering the importance of what it does, the U.S. Department of Homeland Security's cybersecurity and infrastructure security agency is surprisingly low-profile, Garrity said.
Attacks to hack into critical infrastructure are widespread.
In 2024, checkpoint research documented 1,162 cyber attacks on U.S. utilities,
a 75% year-over-year increase.
Given those numbers, perhaps it's good that we hear about C-Soso rarely,
but the agency regularly puts out new alerts about foreign cyber threats.
Here's our president on Friday.
Today, I just want to mention that we heard in Minnesota there was a cyber attack
and they blamed it on Iran.
I don't think so. I think, I blame it on Minnesota because they're grossly incompetent.
How about the attacks on water systems in those six other states, Mr. President?
Do you think the governor's behind it for all those too, Garrity wrote?
Our critical systems are under attack and are rambling, erratic, living in his own world president,
doesn't want to acknowledge it. If he did publicly recognize that Iran is trying to harm Americans
through their water systems, the public might rather be upset by the latest cancellation of
massive military response against the Iranian regime.
All right, let's head over to Ari for his take.
All right, that's it for what the left and right is saying, which brings me to my take.
So to me, this is one of those stories that starts out sounding scary, then it starts to sound
actually kind of silly, the more you learn about it, and then it ultimately feels kind of like
nothing at all.
Earlier this year, I wrote about Ukraine's advancements in its war against Russia, saying it's
quadcopter drones were terrifying to behold and provided a glimpse into a potential future
of automated warfare that were simply not ready for.
When reading headlines about these cyber attacks in Michigan and Minnesota,
it's easy for visions of Ukrainian slaughter bots to come to mind.
A country we're currently in a war with half a world away,
whose military we are punishing into submission,
is still somehow managing to hit us at home with only a few well-placed low-cost attacks.
If the future of war is coming to your kitchen sink, that's a pretty terrifying prospect.
But actually, the real story is a little less scary and a lot more assonide.
For years, hackers backed by Iran with names like Pioneer Kitten, Cyber Avengers,
which is spelled very cool with a three instead of an E.
And the Hendala hack team, I think I'm pronouncing that, right?
I've been claiming credit for significant data breaches and performing scary-sounding hacks like these ones.
Before the U.S. attacked Iran, these efforts mainly focused on Israel, and at first, they were mainly blustered.
Between 2023 and 2025, Handa Hack infiltrated an Israeli alert system to sound emergency alarms in kindergartens
and to send threatening messages to civilians. It sent messages to about 500,000 Israelis,
claiming to have breached the country's Iron Dome missile defense system, warning,
You have only a few hours to fix the system.
But that was a lie, designed to make Israelis feel vulnerable.
And during the same period, Cyber Avengers, the one with a very edgy 3 for an E, hacked small digital components called PLCs, or programmable logic controllers made by the Israeli company Unitronics.
These PLCs, they're little rugged mini computers that are connected to the internet and are frequently used in manufacturing processes to automate mechanical tasks or monitor equipment.
The Iran back group would access them through vulnerabilities, like not changing the default password,
and display the message on monitors, you have been hacked, down with Israel.
This exact hack hit a water authority in Al-Qua, Pennsylvania in 2023, causing its services to be taken offline for a brief period.
And over time, these groups have evolved in their scope of target and the impact of their hacks.
But their approach has remained relatively the same.
And Dala hacked a Michigan medical technology company.
and FBI director Cash Patel earlier this year,
warning that they would release private information.
Cyber Avengers expanded its reach
to target PLCs produced not only by Unitronics,
but also by an American and German supplier.
Then, over the past week,
coordinated cyber attack hit 30 municipalities in Minnesota,
as well as towns and six other states,
causing temporary loss of service.
Some of these vulnerabilities are as simple
as just not changing the device's default password,
from 1-1-1-1. Seriously, that's what happened in Al-Qua.
There's also not a surprise.
Cisa has been aware of these vulnerabilities and warning about these hacks since 2020.
CZE even issued a warning about this general vulnerability,
unconfigured PLCs in municipal water systems, in 2023.
Then in April of this year, it issued another warning about this exact vulnerability in these
exact components. It's no exaggeration to say that the federal government has been aware of security
vulnerabilities in municipal water components for quite some time. It is, however, an exaggeration
to say this was some kind of huge danger to the public welfare. In Minnesota, none of the targeted
municipalities issued a boil water advisory. There was no public contamination of water and no
health hazards. As cybersecurity expert, Pierre Luigi Paganani wrote,
in security affairs, the actors changed IP addresses and passwords resulting in loss of monitoring
and control functionality. That's it. Default are weak credentials on internet exposed hardware,
and suddenly operators are locked out of their own systems. Obviously, this wasn't the most
confidence-inspiring week for our national logistics. If these municipal systems are this easy to hack,
what other vulnerabilities could exist in other systems? This should provide a wake-up called
local governments across the country. But let's also be honest here. We've been at war with Iran for
months, and we've been aware of these hacking groups for years. If this is the closest the American
public has gotten to even feeling unsafe, then I think we're in a pretty good spot. Some group
that could be connected to Iran, and almost definitely is, but maybe it isn't, but it is,
took a crack at one of our largest national cybersecurity vulnerabilities, decentralized across an array of
towns, and we pretty much took it in stride. I'm actually feeling less concerned about terrorist
cyber attacks now than I felt last week before any of this happened. If I were the president of
the United States, I'd be taking this moment to reassure the public and probably send backslaps down
the chain of command. My cybersecurity agency, despite its recent cuts, detected this threat
well ahead of time and issued amply advanced notice to municipalities across the country. Officials in
Minnesota, alertly caught the concerted attack and communicated with the public honestly and
transparently. Meanwhile, operators at water and wastewater authorities and towns across the country
acted quickly and got their services back online with only minimal disruption. It's not like our
entire national infrastructure needs to be completely overhauled. All we have to do is reset some
passwords or reassign support numbers or put remote access behind a VPN to patch this hole. Outwardly,
during the course of an international conflict,
I'd project confidence and security.
Behind the scenes, though, I'd be much more demanding.
Why should any American town ever accept employees
putting internet-connected devices onto water services
without following even the most basic security protocols?
In what world is having only 30% of our water systems
prepared to respond to an emergency,
even remotely acceptable?
How are state governments not enforcing better guidance about this?
And then, truly entering fantasy world here for a second, I deny the Pentagon a modest 0.3% of its latest budget request to fund a $3 billion information sharing program at Siza, which would be a direct response to the actions from Iran most likely to impact American citizens at home.
Now, back in the real world, where my office is pretty far from 1600 Pennsylvania Avenue, President Trump decided to take pot shots at Minnesota and its governor, which is something of a favorite past.
time for him. Now, the state isn't totally blameless here, but can we be serious? Minnesota was one
of at least seven states hit. It was the first to report what it experienced, and CISA itself has
been warning about a potential Iranian cyber attack exactly like this for years. This didn't happen
because of Governor Walsh. Slinging jabs at a state led by a guy who ran against him in the last
election is technically a way for the president to respond, but I can't say Trump's message makes me feel
any more secure about our government's ability to address and adapt to these threats moving forward.
Luckily, though, I don't have to base my feeling of security based on messaging.
Instead, if I look at how ultimately low impact this insanely open exploit turned out to be,
I'm left feeling pretty secure.
I'll put it like this.
A few months ago, I stopped at a taco about in New Hampshire halfway through a road trip from Vermont to Massachusetts.
I used the bathroom while waiting for my food, and when I went to wash my hands, I found the
faucet dripping and spraying oddly. After taking a moment to pat myself a little bit drier, I gave the
faucet a closer inspection and discovered that someone had fitted a perforated condom up and around
the entire fixture. Personally, if you're more terrorized by the possibility of getting
hydrologically assaulted by another fast food bathroom prophylactic among other threats you might
find in a fast food bathroom, then I do the prospect of my town's water supply.
being made unsafe.
I'm personally not going to be losing any sleep over Cyber Avengers with a three,
but I am going to continue to keep a few gallons of distilled water handy,
as he probably should be doing generally anyway.
But that's it for my take, so I'm going to send it over to our executive editor, Isaac Saul,
for a dissent.
Okay, Isaac, what you got?
Thanks, Ari.
Isaac here with my staff dissent today.
Unlike Ari, I find these cyber attacks quite worrisome.
Hundreds, if not thousands of local municipalities being vulnerable to hacks like this seems both obvious and alarming.
Of course, they don't have security teams or the resources to respond.
And of course, that is a huge opportunity for a state actor who wants to sow chaos.
If these were actually Iranian hackers, who's to say this was the maximum damage they could do
and not just a shot across the bow?
And what of China, Russia, or other state actors
who might be more capable in cyber warfare?
Nothing I've seen or read gives me confidence
these vulnerabilities will be fixed at scale anytime soon.
Given how underfunded and under-resourced
so many municipal governments in America are,
I have a hard time imagining this becoming
a level one priority that gets addressed.
The situation, to me, looks more like this.
Iran just found an easily exploitable way,
to upend life for Americans thousands of miles away,
and our president responded by blaming domestic political opponents
while we lack any clear strategy on how to quickly fund or implement any long-term fixes.
All right, I'm going to send it back to Ari and John for the rest of the pod,
and I'll see you guys tomorrow.
Peace.
We'll be right back after this quick break.
Thanks, Ari, and now for a deeper look.
Among civilian infrastructure, water systems are particularly vulnerable to cyber
attacks because they are decentralized and often rely on older technology, and have been since
the dawn of the 21st century.
In early 2000, an Australian man successfully hacked into the wastewater system in Marucci Shire,
Queensland, and caused sewage to spill into nearby areas.
This is thought to be the world's first known hacking attack against civilian infrastructure
to cause physical damage.
There were several attempted attacks against U.S. water systems, but the first to cause
physical damage occurred in 2007, when a California man was accused of insubilant.
installing unauthorized software on a canal system's computer typically used to divert water from the
Sacramento River. The man had been an employee of the canal system before carrying out the attack,
which caused over $5,000 in damage to the computer. Since then, several more cyber attacks have
been carried out, often in the form of either ransomware or remote access. In 2021, WSSC Water in Maryland
experienced a ransomware attack in which cybercriminals gained access to internal files. In 2024,
Or a hack against American water, the largest publicly traded water utility in the U.S.,
forced it to shut down key systems, including customer billing, until the exploit was under control.
No group took responsibility for either attack, and water treatment was not affected.
And last but not least, our have a nice day story.
Sakh Ian Jun Tuk bought a restaurant space in April 2025, and it was a bit of a fixer upper.
A fire at a business next door had knocked out power to the restaurant, forcing it to call.
closed for several months. While cleaning in preparation for the reopening,
Ian Jung took him across an old cabinet containing $12,000, some of a hidden inside a
sunglasses case. He realized the cabinet belonged to the previous owner and set off to track him
down. After several tries to get in touch, he finally reached the man and returned the money.
I feel like this was the right thing to do, Yan Jun took said. Honesty, integrity, is very important
in life. WLBT3 has this story and there's a link in today's episode description.
All right, everybody, that is it for today's episode.
As always, if you'd like to support our work, please go to retangle.com,
where you can sign up for a newsletter membership,
podcast membership, or a bundled membership that gets you a discount on both.
We'll be right back here tomorrow.
For Isaac Ari and the rest of the crew, this is John Law signing off.
Have a great day, y'all.
Peace.
Our executive editor and founder is me.
Isaac Saul and our executive producer is John Wall.
Today's episode was edited and engineer.
by Dewey Thomas. Our editorial staff is led by managing editor Ari Weitzman with senior editor Will
Kaback and associate editors Audrey Moorhead, Lindsay Canuth, and Bailey Saul. Music for the podcast was produced
by Diet 75. To learn more about Tangle and to sign up for a membership, please visit our website
at retangle.com.
