The Daily - Is America’s Drinking Water the Next Front in the Iran War?

Episode Date: August 7, 2026

Over the past week, a growing number of municipalities across the United States have reported that their water systems were hacked. The Times has found that the attacks were most likely perpetrated by... Iran. Today, Dustin Volz, a cybersecurity and intelligence correspondent for The New York Times, explains how the hacking exposes yearslong failed efforts to shore up vulnerabilities in U.S. infrastructure, and how Iran may be seeking a new kind of leverage that could extend the war’s reach to within U.S. borders and affect something as elemental as the water we drink. Guest: Dustin Volz, a cybersecurity and intelligence correspondent for The New York Times. Background reading:  Federal and state officials are racing to address an assault on the nation’s water supply. Cyberattacks on water systems nationwide that affected Michigan and Minnesota also included at least five more states. Evidence points to Iranian involvement. Photo: Jenn Ackerman for The New York Times For more information on today’s episode, visit nytimes.com/thedaily. Transcripts of each episode will be made available by the next workday.  Subscribe today at nytimes.com/podcasts or on Apple Podcasts and Spotify. You can also subscribe via your favorite podcast app here https://www.nytimes.com/activate-access/audio?source=podcatcher. For more podcasts and narrated articles, download The New York Times app at nytimes.com/app. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Transcript
Discussion (0)
Starting point is 00:00:01 From the New York Times, I'm Zolinkano-Yungs, filling in his host. This is the Daily. A growing number of cities and towns across the U.S. have reported that their water systems have been hacked. The Times found that the operation was likely perpetrated by Iran. Today, my colleague Dustin Volz on the long-standing infrastructure vulnerabilities exposed by the recent hacks, and how Iran may be seeking a new kind of leverage in the war that affects something as elemental as the water we drink.
Starting point is 00:00:42 It's Friday, August 7th. Dustin, my guy, we both work in the Washington Bureau. We both live in the same D.C. neighborhood, and now we are together on The Daily. I'm so happy you are here. This is your first time on the show, right? Living the dream, yeah, first time. I'm really happy to be here.
Starting point is 00:01:13 We're both living the dream. All right, excellent. You cover intelligence and cybersecurity, and I know that national security officials have long warned about the cyber threat from Iran, but this hack that you've been covering impacting water systems and states across the country, this seems different, is it? It is different, yes. What we are living through right now is the stuff seemingly of sensationalized Hollywood thrillers. Wow. A suspected foreign power, which officials tell me is likely to be Iran, breaking into municipal water systems throughout the country and alarming the Trump administration and state officials in a way that we really have not seen before. Okay, so what happened? Walk me through what we know.
Starting point is 00:01:58 So the timeline here, it really picks up first at the beginning of war in February when federal officials, the cybersecurity agency at DHS and others, issued. public alerts saying Iranian-linked hackers are targeting critical infrastructure in the United States and here's the typical computers that they're looking at trying to break into. But these alerts sort of happen all the time. They're easy to ignore. It's sort of unclear
Starting point is 00:02:24 exactly how serious it is and even if it's occurring what the hackers might want to be doing with it. But clearly when the United States is at war with foreign power, cyber attacks are something that can become a more pressing concern, especially when that foreign power like Iran can't
Starting point is 00:02:40 necessarily retaliate with missiles of its own that can reach the continental United States. Right. These alerts might not be necessarily unusual, but when we are in an active war with Iran, suddenly there's a bit more of a red alert sort of vibe going on here. Absolutely. And fast forward to mid-July, when this alert from a cybersecurity agency at DHS is revised to then show that these Iran... unlinked hackers are breaking into these critical infrastructure networks, but they're not just getting in now. They're doing really interesting kind of crafty things that we previously hadn't seen publicly reported. And that activity betrayed a level of familiarity and a level of
Starting point is 00:03:28 sophistication from these hackers that not only showed that they kind of knew what they were doing, but that their intentions may be a lot more sinister than what we maybe previously realized. So this warning lands July 22nd, again, doesn't necessarily get a ton of attention, but about four days later. They didn't break in through the door. They cracked the code through the internet. We start seeing reports first out of Minnesota of widespread hacking activity targeting dozens of municipal water systems. Right now, several Minnesota cities are scrambling to respond to cyber attacks targeting their water systems. Now, in addition to Plymouth, South St. Paul, Maple Plain, and Bram. And the states and others say that it looks like it's a coordinated campaign.
Starting point is 00:04:16 Some of the systems targeted reported flooding and a loss of pressure. In some cases, even shutting it down completely. And the Minnesota disclosure turns out to really just be the tip of the spear. Several states are seeing cyber attacks on their water systems. Minnesota, Michigan, and Georgia are among at least seven. in New Jersey, South Dakota, and Georgia have all said... A few days after Minnesota comes forward and discloses this, we see the federal authorities say that they are seeing activity hackers targeting water systems
Starting point is 00:04:48 in at least seven states. Right now, the FBI and the EPA are actively warning state officials to disconnect their systems from the internet or at least use a system that has some kind of a breaker. They're also urging utilities figure out how to revert to manual, controls in the event that automated systems are somehow compromised. And we've only seen that number continue to grow. So my latest reporting is that at least a dozen states and over 100 municipalities across the country are also identifying cyber activity that they believe could be linked
Starting point is 00:05:24 to this ongoing hacking spree that's occurring. Just to clarify, when you say water municipalities, water systems, what are we talking about here. Right. This is the part of the conversation where I feel the need to disclose, like I'm not an expert on the sort of tens of thousands of municipal water systems across the country. But essentially, yes, we're talking about water treatment plants, wastewater treatment facilities, infrastructure of every sort of city and town and every municipality that operates, you know,
Starting point is 00:05:58 quietly in the background so that we're able to turn on the water in our kitchen and our bathroom, take a hot shower with adequate water pressure and not worry about. about our skin breaking out in a rash. These are the systems, the water towers, the pumps, the sanitation elements of it, monitoring of the chemical levels inside that water that sort of happen in the background so we can lead our everyday lives
Starting point is 00:06:23 and not have to worry about this. So, Dustin, walk me through this. What did these hackers actually do? How did they get in these systems? They got in through very basic means, and that is sort of what is so scary about this. and frustrating to a lot of people that are following it. Essentially, the hackers here scanned the open Internet
Starting point is 00:06:44 in a way that allowed them to find Internet-facing computers that allow the water system operators to remotely manage the water supply from home. You can imagine a situation in which a small town might only have one or two people who are actually working full-time to maintain the water system. And it might be necessary for them to be able to access those systems
Starting point is 00:07:12 in case something occurs, like runoff after a major storm, to do things with the pumps to make sure the pressure is working appropriately. So these computers allow operators to do their jobs. Unfortunately, those same computers are just as accessible in many cases
Starting point is 00:07:28 for malicious hackers to find and break into using very conventional hacking methods. And you sort of see cases here where just basic cyber hygiene is being ignored or overlooked, and that is allowing these hackers to get inside and get a toehold inside these networks. But you suggested that these hackers were doing something that was more complex, more sophisticated as well, right? That's right. So the breaking in is sort of any cyber burglar could maybe accomplish a lot of what they're doing to break in. But once you're inside a network, that doesn't necessarily mean you know how to do,
Starting point is 00:08:05 things to manipulate the system or degrade the system. Now what we're seeing, according to federal authorities, is that these hackers are manipulating the technology, the internal systems, to quietly turn off internal safety mechanisms that would alert local operators if there were a problem in the water supply. Okay. So they have computers at home that they use to manage the system. that computer flags an alert when maybe a chemical level of fluoride is adjusted for some reason and they can fix it or the water pressure is off because of some pump somewhere is not working properly. That lets them be able to remotely change it or drive over to the actual facility and do some handiwork and fix it. And what we're seeing is these hackers on the inside are turning those systems off in a way that is basically making it seem like the water system is fine. because it's not issuing an alert to the operators,
Starting point is 00:09:07 letting them know. In fact, no, something's wrong. Okay, so that seems really concerning. So you're saying if water were to be contaminated, the system that would alert local officials, these hackers were able to turn that system off, meaning some of these water systems could be contaminated and officials would not know.
Starting point is 00:09:28 We might not even know it. And that's why you're seeing municipalities in different states sort of take precautionary measures, including boil water notices, to address these concerns, because, you know, you don't want to take any risk. I just want to clarify here, because, like, a lot of people are listening to this. Have any of these water systems actually been compromised? Like, has the drinking water at this point actually been impacted by this hacking scheme? We have not seen drinking water actually contaminated as a result of a cyber attack,
Starting point is 00:09:58 at least no public disclosures of that that I am aware of. But I have never, in all my years of recovering this kind of thing, had officials and security experts talk to me with such alarm about the possibility here of what could take place if we don't address it quickly enough and we aren't paying attention closely enough to what is happening right now. What's also very notable about this is that this is not a surprise attack.
Starting point is 00:10:27 This is something that cybersecurity and intelligence officials have been warning about four years across Democratic and Republican administrations. It's a known problem, and it is something that the investigators confronting it right now are having to do with fewer resources than they've had in a very long time. We'll be right back. So, Dustin, tell me the story of how officials knew something like this could happen, but they were still caught unprepared when it did. Well, quite simply, officials knew something like this could happen because in some sense, it already has happened.
Starting point is 00:11:16 An episode that I think is particularly relevant is in 2013. New revelations that Iranian hackers infiltrated a small dam located less than 20 miles outside New York City. In upstate New York, there was an intrusion at a small dam that was attributed by the U.S. government to Iranian hackers. Officials say it's a new frontier for cybercrime, attempting to take over a physical piece of U.S. infrastructure. That means that an enemy of this country was potentially able to put American lives in danger, all from the comfort of a theoretical computer terminal in downtown Tehran. And in this instance, we were just lucky. The dam actually just happened to be turned off for routine maintenance work.
Starting point is 00:12:02 Wow. So in the event that they wanted to mess with the dam, they basically wouldn't have been able to. But still... This is the first time that individuals working for a foreign government have been charged with a cyber attack on U.S. infrastructure.
Starting point is 00:12:16 This was Iranian hackers who were later named and indicted by the Justice Department who infiltrated this water system. So there have been warning shots then, so to speak. Officials knew about this. So have there been attempts to fix it? There have certainly been efforts.
Starting point is 00:12:34 I mean, there was a major effort in the Senate, 15 years ago by Senator Susan Collins and Senator Joe Lieberman to have major cybersecurity legislation passed that would have specifically created cybersecurity standards for a variety of critical infrastructure networks, including water. That came close to passing. It did not, though. There was lobbying efforts through various industry groups who were concerned about creating standards for small localities that maybe wouldn't be able to keep up.
Starting point is 00:13:05 That was the concern or one of the concerns expressed at the time. More recently, during the Biden administration, the EPA attempted to create minimum security guidelines for water facilities specifically and were sued for it by a few Republican-led states and water industry groups. That again said, essentially, these are difficult to adopt for especially small providers. and we don't think the EPA necessarily has the correct authority to do this. And this was just one of many efforts the Biden administration made to sort of take the ball down the field on cybersecurity in different critical infrastructure areas. And many of them were unsuccessful or encountered resistance
Starting point is 00:13:52 and were not able to go forward. But what about the states? Like, can't the states take this on? The states have made a variety of efforts. And in fact, you just saw last week, New York said they're going to invest about $9 million for specifically water system cybersecurity. This was an effort that was already underway, but they fast-tracked in light of these hacks that are ongoing. But the states are also under-resourced. They have budgets.
Starting point is 00:14:19 They need a balance. And this is not an area that necessarily resonates with voters who are going to the polls in November. Republican or Democrat, you know, when you think of your top issues, water cybersecurity. is not necessarily something that anyone is thinking about. Not exactly top of the priority for the voters in the polls is water cybersecurity over, say, education, crime, or filling your potholes. No, absolutely.
Starting point is 00:14:44 And so these water systems, you know, these are public utilities. According to the EPA, there's about 150,000 of them nationwide. Many of them are very small, are not getting a lot of money, and are operating aging technology and aging infrastructure. And so you have a situation in which everybody sort of knows this is a problem, but it's sort of a question of, you know, where's the money going to come from and where's the help going to come from? Right.
Starting point is 00:15:07 But we have seen one federal effort that was very specifically designed to help states address cybersecurity threats in their infrastructure. And that was created during the first Trump administration, the cybersecurity and infrastructure security agency, or SISA, that agency is housed at DHS, and it is specifically tasked with trying to ensure the physical and cybersecurity of the nation's critical infrastructure, including energy grids, oil and gas pipelines, and, crucially, water systems. Okay, that's a long list. How does it go about doing that? SISA is intended to take classified intelligence, downgraded in a way that they can share with
Starting point is 00:15:50 states, and let them know about the threats they're seeing coming from, especially foreign actors, and help them work together with federal partners and each other to figure out ways to address the threats, to adopt best cybersecurity practices, and in some cases, to find pots of money that can help them do that. Interesting. So this is almost like the federal government's geek squad coming and saying, we're going to fix your systems,
Starting point is 00:16:17 or at least raise a flag and let you know what might be coming. That's right. And it's not just the water systems that they work on. And they also do have a number of other areas of focus, including, at least historically, election security and helping states make sure that their voting machines are safeguarded from any tampering as well. Election security. Okay.
Starting point is 00:16:38 That would seem to be an issue that might put you in shaky waters with President Trump. That is an understatement. Sissau was in many ways one of the strongest accomplishments of the first Trump term. He signed it into law. He signed it into law. It was part of his legacy, and it was something that people had been clamoring for for years. You have to remember, this was in the wake of Russian meddling in the 2016 election when Democrats and many Republicans thought election security was a very, very serious, paramount
Starting point is 00:17:09 issue that we needed to focus on. And that's something that its first director, Chris Krebs, did focus on at Sessa, and he had a lot of runway to do a lot of things in that environment until after the 2020 election when he said that, the election had, in fact, been secure from manipulation, and that's when he got crossways with President Trump. Right. This is something we've seen on the White House speed. President Trump has really gone after and targeted Chris Krebs. In his second term, his administration has even investigated him.
Starting point is 00:17:40 That's correct. And collateral damage for the wrath that Chris Krebs has endured since Trump came back to the White House has been his former agency, SISA itself. And so during the second Trump administration, you've seen a severe downsizing and a paired back mission at SISA. Over a thousand staffers have been let go. You've seen efforts more recently by DHS Secretary Mullen to potentially look at hiring back some of those people. But SISA, as it stands now, has less funding than it once had, has way fewer officials working on cybersecurity issues across all of these critical infrastructure issues,
Starting point is 00:18:22 including water, and during the entire second Trump term, it has not had a Senate-confirmed leader. So how do these cuts factor into the hack that we have been discussing? Like, how is this being felt on the ground? Well, it's hard to draw a direct line to cuts and how a agency is dealing with a specific response. But SISA is a lead agency
Starting point is 00:18:45 investigating this intrusion and trying to help the states. And by all accounts, the states that I've been speaking to are very grateful for that. help, but it is a different SISA than we have seen previously. It is one that does not have the same clout within the administration. It does not have the same resources. And we are at the same time seeing a bit of an unusual reaction from the federal government or a confusing one. The President of the United States himself was asked about these attacks last week. And they blame it on Iran. I don't think so. I think I blame it on Minnesota because they're
Starting point is 00:19:17 grossly incompetent. And basically said, I don't think it's Iran. I think the governor's behind it. I don't think there was an Iranian soccer attack. I think that Minnesota would get its act together. And blamed Minnesota Governor Tim Walts, the Democrat there, for the intrusions. He blamed the governor of Minnesota for water systems in Minnesota getting hacked. That's right. I mean, it's no secret that the president does not like the governor of Minnesota, who ran as vice president in 2024.
Starting point is 00:19:51 There have been a number of clashes in that state over immigration enforcement issues, and this is just seemingly the latest flashpoint between Minnesota and the Trump administration. And what it really drives home is how hard it is to keep even these sort of national security threats, these very complicated cyber issues, divorced from politics, because you have this sort of awkward-fitting cybersecurity agency housed at DHS, the same area of government that is tasked with leading these aggressive immigration raids in Minnesota and elsewhere, that due to those issues, was unfunded for many months recently. And that included SISA.
Starting point is 00:20:35 You had a SISA that had a lot of people furloughed and not working, even as the war started. This is fascinating. The agency that actually could help address some of these issues when it comes to cybersecurity also happens to be sitting in one of the more polarized departments in the federal government. And by the way, it's at a time where it would seem like the stakes are high because we're at war right now. Absolutely. In some ways, the stakes have never been higher when we're in an act of conflict with Iran. Dustin, hearing you talk about this, the question I have in my mind is, the U.S. seems vulnerable. Iran has this ability. Why aren't they actually taking advantage of this? What's keeping Iran from using this leverage? That's a million dollar question. I think there are a few things to consider here. First of all, if a foreign power, even one that's currently already at war with the United States, decided to contaminate drinking water, I think that would provoke an enormous response, both from the Trump administration and potentially also internationally. Right now, the Iran war is not very popular with, well, it's not popular in America with most Americans, but it's also not popular among our allies. You could see a situation in which if Iran actually
Starting point is 00:21:48 tried to do that to harm civilians, that could be treated very seriously. Yeah. And that could provoke goodwill toward the United States and lead to more of a unity against this regime. This is interesting. What you're saying is what has been up until this point, an unpopular military campaign by the United States, they could suddenly gain some support if Iran starts taking action that impacts people inside U.S. borders.
Starting point is 00:22:13 I mean, I think that's certainly a possibility. I mean, I'm not inside the head of the Iranian hackers who are. believe to be responsible here, but that is one thing to consider. I mean, I think another thing is you want to keep your options open. This sort of option of contaminating drinking water, hypothetically, might not be something they feel like they need to do yet, or they're not cornered enough where they feel like that's a step they need to take. They want to keep that in their back pocket potentially. And that's not a crazy notion because we've seen it with another foreign adversary, China. China for years has, in fact, been
Starting point is 00:22:48 infiltrating critical infrastructure networks throughout the United States, including water systems, in what officials have said is a prepositioning effort to burrow inside these systems to potentially one day later on cause massive disruptions that would occur potentially in the event of a major conflict with the U.S. For example, a fight over Taiwan. This is something that the officials that I speak to, say, is sort of a top-of-mind concern, and it's something that no one has been able to figure out how to address. So even if it's unclear as of now, when Iran might take advantage of this, whether Iran could take advantage of this vulnerability, it is a vulnerability that is still unaddressed when it comes to U.S. national security. It's a huge vulnerability,
Starting point is 00:23:42 and it's a huge one that I think people can understand. I mean, this is not sort of an abstract theoretical thing. This is your drinking water. This is, you know, the tap coming out of your kitchen sink. This is something that we take for granted every day in a developed country that is hugely vulnerable and has been for decades and continues to get more vulnerable in some respects as these systems become more and more digitized,
Starting point is 00:24:12 more and more accessible in some ways. And if that doesn't, doesn't wake people up to the very severe risks here. I don't know what else will. Well, Dustin, I appreciate your reporting. Thank you. Thank you for having me. We'll be right back. Here's what else you need to know today.
Starting point is 00:24:50 Clerk will call the roll. Senator Johnson. Yes. Senator Langford. All right. On Thursday, a Senate committee voted along party lines to hold Dr. Anthony Fauci, the face of the government's COVID response, in contempt of Congress. Fauci invoked the Fifth Amendment and refused to answer questions during a hearing last
Starting point is 00:25:08 week about the origins of the coronavirus. Dr. Fauci faced no risk of federal prosecution. All he had to do is tell the truth. More than 100 times, though, he refused. That is what we are voting on today. The resolution, spearheaded by the Senate Committee's Republican chairman, Ram Paul, highlighted the deep partisan divisions over Fauci and his legacy. Paul and other Republicans have argued that a pardon President Joe Biden gave Fauci made Fauci ineligible for Fifth Amendment protections. Biden was moved to issue the pardon before he left office because of Republican threats to imprison Fauci. Fauci's attorney called the Senate vote a political stunt. And President Trump signed a pair of executive orders aimed at restricting birthright citizenship
Starting point is 00:25:56 after the Supreme Court ruled that a similar effort by the administration was unconstitutional. A very, very unfortunate decision. So we're making adjustments because it's very unfair. It was not immediately clear how the orders would be enforced, but any renewed effort to prevent babies born in the U.S. from automatically gaining citizenship would likely be met with legal challenges. Today's episode was produced by Stella Tan, Lexi D.A.O. and Olivia Nett.
Starting point is 00:26:30 It was edited by Annie Minoff and Michael Benoit, and contains music by Marion Lazzano, Diane Wong, and Rowan Nemisto. Our theme music is by Wonderly. This episode was engineered by Alyssa Moxley. The Daily Studio support team is Maddie Masiello, Nick Pittman, Kyle Grandillo, Afim Shapiro, and Samantha Winter.
Starting point is 00:26:55 Our radio team is Jody Becker, Rowan Neimisto, Diane Wong, and Catherine Anderson. Alexandra Lee Young is our deputy executive producer. Michael Benoit is our deputy editor. Paige Cowitt is the editor of the Daily. Ben Calhoun is our executive producer. Special thanks to Sam Dolnik
Starting point is 00:27:15 and the founding editor of the show, Lisa Tobin. That's it for the Daily. I'm Zolinkano Young's. See you on Sunday.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.