The Daily - Is America’s Drinking Water the Next Front in the Iran War?
Episode Date: August 7, 2026Over the past week, a growing number of municipalities across the United States have reported that their water systems were hacked. The Times has found that the attacks were most likely perpetrated by... Iran. Today, Dustin Volz, a cybersecurity and intelligence correspondent for The New York Times, explains how the hacking exposes yearslong failed efforts to shore up vulnerabilities in U.S. infrastructure, and how Iran may be seeking a new kind of leverage that could extend the war’s reach to within U.S. borders and affect something as elemental as the water we drink. Guest: Dustin Volz, a cybersecurity and intelligence correspondent for The New York Times. Background reading: Federal and state officials are racing to address an assault on the nation’s water supply. Cyberattacks on water systems nationwide that affected Michigan and Minnesota also included at least five more states. Evidence points to Iranian involvement. Photo: Jenn Ackerman for The New York Times For more information on today’s episode, visit nytimes.com/thedaily. Transcripts of each episode will be made available by the next workday. Subscribe today at nytimes.com/podcasts or on Apple Podcasts and Spotify. You can also subscribe via your favorite podcast app here https://www.nytimes.com/activate-access/audio?source=podcatcher. For more podcasts and narrated articles, download The New York Times app at nytimes.com/app. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Transcript
Discussion (0)
From the New York Times, I'm Zolinkano-Yungs, filling in his host.
This is the Daily.
A growing number of cities and towns across the U.S. have reported that their water systems have been hacked.
The Times found that the operation was likely perpetrated by Iran.
Today, my colleague Dustin Volz on the long-standing infrastructure vulnerabilities
exposed by the recent hacks,
and how Iran may be seeking a new kind of leverage in the war
that affects something as elemental as the water we drink.
It's Friday, August 7th.
Dustin, my guy, we both work in the Washington Bureau.
We both live in the same D.C. neighborhood,
and now we are together on The Daily.
I'm so happy you are here.
This is your first time on the show, right?
Living the dream, yeah, first time.
I'm really happy to be here.
We're both living the dream. All right, excellent. You cover intelligence and cybersecurity,
and I know that national security officials have long warned about the cyber threat from Iran,
but this hack that you've been covering impacting water systems and states across the country,
this seems different, is it?
It is different, yes. What we are living through right now is the stuff seemingly of sensationalized Hollywood thrillers.
Wow.
A suspected foreign power, which officials tell me is likely to be Iran, breaking into municipal water systems throughout the country and alarming the Trump administration and state officials in a way that we really have not seen before.
Okay, so what happened? Walk me through what we know.
So the timeline here, it really picks up first at the beginning of war in February when federal officials, the cybersecurity agency at DHS and others, issued.
public alerts saying
Iranian-linked hackers are targeting
critical infrastructure in the United States
and here's the typical computers that they're
looking at trying to break into.
But these alerts sort of happen all the time.
They're easy to ignore. It's sort of unclear
exactly how serious it is and
even if it's occurring what the hackers might want
to be doing with it. But
clearly when the United States is at war
with foreign power, cyber attacks
are something that can become
a more pressing concern, especially
when that foreign power like Iran can't
necessarily retaliate with missiles of its own that can reach the continental United States.
Right. These alerts might not be necessarily unusual, but when we are in an active war with Iran,
suddenly there's a bit more of a red alert sort of vibe going on here.
Absolutely. And fast forward to mid-July, when this alert from a cybersecurity agency at DHS is
revised to then show that these Iran...
unlinked hackers are breaking into these critical infrastructure networks, but they're not just
getting in now. They're doing really interesting kind of crafty things that we previously hadn't
seen publicly reported. And that activity betrayed a level of familiarity and a level of
sophistication from these hackers that not only showed that they kind of knew what they were
doing, but that their intentions may be a lot more sinister than what we maybe previously realized.
So this warning lands July 22nd, again, doesn't necessarily get a ton of attention, but about four days later.
They didn't break in through the door. They cracked the code through the internet.
We start seeing reports first out of Minnesota of widespread hacking activity targeting dozens of municipal water systems.
Right now, several Minnesota cities are scrambling to respond to cyber attacks targeting their water systems.
Now, in addition to Plymouth, South St. Paul, Maple Plain, and Bram.
And the states and others say that it looks like it's a coordinated campaign.
Some of the systems targeted reported flooding and a loss of pressure.
In some cases, even shutting it down completely.
And the Minnesota disclosure turns out to really just be the tip of the spear.
Several states are seeing cyber attacks on their water systems.
Minnesota, Michigan, and Georgia are among at least seven.
in New Jersey, South Dakota, and Georgia have all said...
A few days after Minnesota comes forward and discloses this,
we see the federal authorities say that they are seeing activity hackers targeting water systems
in at least seven states.
Right now, the FBI and the EPA are actively warning state officials to disconnect
their systems from the internet or at least use a system that has some kind of a breaker.
They're also urging utilities figure out how to revert to manual,
controls in the event that automated systems are somehow compromised.
And we've only seen that number continue to grow.
So my latest reporting is that at least a dozen states and over 100 municipalities
across the country are also identifying cyber activity that they believe could be linked
to this ongoing hacking spree that's occurring.
Just to clarify, when you say water municipalities, water systems, what are we
talking about here.
Right.
This is the part of the conversation where I feel the need to disclose, like I'm not an expert
on the sort of tens of thousands of municipal water systems across the country.
But essentially, yes, we're talking about water treatment plants, wastewater treatment facilities,
infrastructure of every sort of city and town and every municipality that operates, you know,
quietly in the background so that we're able to turn on the water in our kitchen and our
bathroom, take a hot shower with adequate water pressure and not worry about.
about our skin breaking out in a rash.
These are the systems, the water towers, the pumps,
the sanitation elements of it,
monitoring of the chemical levels inside that water
that sort of happen in the background
so we can lead our everyday lives
and not have to worry about this.
So, Dustin, walk me through this.
What did these hackers actually do?
How did they get in these systems?
They got in through very basic means,
and that is sort of what is so scary about this.
and frustrating to a lot of people that are following it.
Essentially, the hackers here scanned the open Internet
in a way that allowed them to find Internet-facing computers
that allow the water system operators
to remotely manage the water supply from home.
You can imagine a situation in which a small town might only have
one or two people who are actually working full-time
to maintain the water system.
And it might be necessary for them
to be able to access those systems
in case something occurs,
like runoff after a major storm,
to do things with the pumps
to make sure the pressure is working appropriately.
So these computers allow operators
to do their jobs.
Unfortunately, those same computers
are just as accessible in many cases
for malicious hackers
to find and break into
using very conventional hacking methods.
And you sort of see cases here where just basic cyber hygiene is being ignored or overlooked,
and that is allowing these hackers to get inside and get a toehold inside these networks.
But you suggested that these hackers were doing something that was more complex, more sophisticated as well, right?
That's right. So the breaking in is sort of any cyber burglar could maybe accomplish a lot of what they're doing to break in.
But once you're inside a network, that doesn't necessarily mean you know how to do,
things to manipulate the system or degrade the system. Now what we're seeing, according to federal
authorities, is that these hackers are manipulating the technology, the internal systems,
to quietly turn off internal safety mechanisms that would alert local operators if there were
a problem in the water supply. Okay. So they have computers at home that they use to manage the system.
that computer flags an alert when maybe a chemical level of fluoride is adjusted for some reason and they can fix it or the water pressure is off because of some pump somewhere is not working properly.
That lets them be able to remotely change it or drive over to the actual facility and do some handiwork and fix it.
And what we're seeing is these hackers on the inside are turning those systems off in a way that is basically making it seem like the water system is fine.
because it's not issuing an alert to the operators,
letting them know.
In fact, no, something's wrong.
Okay, so that seems really concerning.
So you're saying if water were to be contaminated,
the system that would alert local officials,
these hackers were able to turn that system off,
meaning some of these water systems could be contaminated
and officials would not know.
We might not even know it.
And that's why you're seeing municipalities in different states
sort of take precautionary measures, including boil water notices, to address these concerns,
because, you know, you don't want to take any risk.
I just want to clarify here, because, like, a lot of people are listening to this.
Have any of these water systems actually been compromised?
Like, has the drinking water at this point actually been impacted by this hacking scheme?
We have not seen drinking water actually contaminated as a result of a cyber attack,
at least no public disclosures of that that I am aware of.
But I have never, in all my years of recovering this kind of thing,
had officials and security experts talk to me with such alarm
about the possibility here of what could take place
if we don't address it quickly enough
and we aren't paying attention closely enough to what is happening right now.
What's also very notable about this
is that this is not a surprise attack.
This is something that cybersecurity and intelligence officials
have been warning about four years across Democratic and Republican administrations.
It's a known problem, and it is something that the investigators confronting it right now
are having to do with fewer resources than they've had in a very long time.
We'll be right back.
So, Dustin, tell me the story of how officials knew something like this could happen,
but they were still caught unprepared when it did.
Well, quite simply, officials knew something like this could happen because in some sense, it already has happened.
An episode that I think is particularly relevant is in 2013.
New revelations that Iranian hackers infiltrated a small dam located less than 20 miles outside New York City.
In upstate New York, there was an intrusion at a small dam that was attributed by the U.S. government to Iranian hackers.
Officials say it's a new frontier for cybercrime, attempting to take over a physical piece of U.S. infrastructure.
That means that an enemy of this country was potentially able to put American lives in danger,
all from the comfort of a theoretical computer terminal in downtown Tehran.
And in this instance, we were just lucky.
The dam actually just happened to be turned off for routine maintenance work.
Wow.
So in the event that they wanted to mess with the dam,
they basically wouldn't have been able to.
But still...
This is the first time
that individuals working for a foreign government
have been charged with a cyber attack
on U.S. infrastructure.
This was Iranian hackers
who were later named and indicted
by the Justice Department
who infiltrated this water system.
So there have been warning shots then, so to speak.
Officials knew about this.
So have there been attempts to fix it?
There have certainly been efforts.
I mean, there was a major effort in the Senate,
15 years ago by Senator Susan Collins and Senator Joe Lieberman to have major cybersecurity legislation
passed that would have specifically created cybersecurity standards for a variety of critical
infrastructure networks, including water.
That came close to passing.
It did not, though.
There was lobbying efforts through various industry groups who were concerned about creating
standards for small localities that maybe wouldn't be able to keep up.
That was the concern or one of the concerns expressed at the time.
More recently, during the Biden administration, the EPA attempted to create minimum security guidelines for water facilities specifically and were sued for it by a few Republican-led states and water industry groups.
That again said, essentially, these are difficult to adopt for especially small providers.
and we don't think the EPA necessarily has the correct authority to do this.
And this was just one of many efforts the Biden administration made
to sort of take the ball down the field on cybersecurity
in different critical infrastructure areas.
And many of them were unsuccessful or encountered resistance
and were not able to go forward.
But what about the states?
Like, can't the states take this on?
The states have made a variety of efforts.
And in fact, you just saw last week, New York said they're going to invest about $9 million for specifically water system cybersecurity.
This was an effort that was already underway, but they fast-tracked in light of these hacks that are ongoing.
But the states are also under-resourced.
They have budgets.
They need a balance.
And this is not an area that necessarily resonates with voters who are going to the polls in November.
Republican or Democrat, you know, when you think of your top issues, water cybersecurity.
is not necessarily something that anyone is thinking about.
Not exactly top of the priority for the voters in the polls
is water cybersecurity over, say, education, crime,
or filling your potholes.
No, absolutely.
And so these water systems, you know, these are public utilities.
According to the EPA, there's about 150,000 of them nationwide.
Many of them are very small, are not getting a lot of money,
and are operating aging technology and aging infrastructure.
And so you have a situation in which everybody sort of knows
this is a problem, but it's sort of a question of, you know, where's the money going to come from
and where's the help going to come from?
Right.
But we have seen one federal effort that was very specifically designed to help states address
cybersecurity threats in their infrastructure.
And that was created during the first Trump administration, the cybersecurity and infrastructure
security agency, or SISA, that agency is housed at DHS, and it is specifically tasked with
trying to ensure the physical and cybersecurity of the nation's critical infrastructure,
including energy grids, oil and gas pipelines, and, crucially, water systems.
Okay, that's a long list. How does it go about doing that?
SISA is intended to take classified intelligence, downgraded in a way that they can share with
states, and let them know about the threats they're seeing coming from, especially foreign actors,
and help them work together with federal partners and each other
to figure out ways to address the threats,
to adopt best cybersecurity practices,
and in some cases, to find pots of money that can help them do that.
Interesting.
So this is almost like the federal government's geek squad coming and saying,
we're going to fix your systems,
or at least raise a flag and let you know what might be coming.
That's right.
And it's not just the water systems that they work on.
And they also do have a number of other areas of focus, including, at least historically,
election security and helping states make sure that their voting machines are safeguarded
from any tampering as well.
Election security.
Okay.
That would seem to be an issue that might put you in shaky waters with President Trump.
That is an understatement.
Sissau was in many ways one of the strongest accomplishments of the first Trump term.
He signed it into law.
He signed it into law.
It was part of his legacy, and it was something that people had been clamoring for for years.
You have to remember, this was in the wake of Russian meddling in the 2016 election
when Democrats and many Republicans thought election security was a very, very serious, paramount
issue that we needed to focus on.
And that's something that its first director, Chris Krebs, did focus on at Sessa,
and he had a lot of runway to do a lot of things in that environment
until after the 2020 election when he said that,
the election had, in fact, been secure from manipulation, and that's when he got crossways with
President Trump.
Right. This is something we've seen on the White House speed. President Trump has really gone
after and targeted Chris Krebs. In his second term, his administration has even investigated him.
That's correct. And collateral damage for the wrath that Chris Krebs has endured since Trump
came back to the White House has been his former agency, SISA itself. And so during the second
Trump administration, you've seen a severe downsizing and a paired back mission at SISA.
Over a thousand staffers have been let go.
You've seen efforts more recently by DHS Secretary Mullen to potentially look at hiring back
some of those people.
But SISA, as it stands now, has less funding than it once had, has way fewer officials
working on cybersecurity issues across all of these critical infrastructure issues,
including water, and during the entire second Trump term,
it has not had a Senate-confirmed leader.
So how do these cuts factor into the hack
that we have been discussing?
Like, how is this being felt on the ground?
Well, it's hard to draw a direct line to cuts
and how a agency is dealing with a specific response.
But SISA is a lead agency
investigating this intrusion and trying to help the states.
And by all accounts, the states that I've been speaking to
are very grateful for that.
help, but it is a different SISA than we have seen previously. It is one that does not have
the same clout within the administration. It does not have the same resources. And we are at the same
time seeing a bit of an unusual reaction from the federal government or a confusing one. The
President of the United States himself was asked about these attacks last week.
And they blame it on Iran. I don't think so. I think I blame it on Minnesota because they're
grossly incompetent. And basically said, I don't think it's Iran.
I think the governor's behind it.
I don't think there was an Iranian soccer attack.
I think that Minnesota would get its act together.
And blamed Minnesota Governor Tim Walts, the Democrat there, for the intrusions.
He blamed the governor of Minnesota for water systems in Minnesota getting hacked.
That's right.
I mean, it's no secret that the president does not like the governor of Minnesota, who ran as vice president in 2024.
There have been a number of clashes in that state over immigration enforcement issues,
and this is just seemingly the latest flashpoint between Minnesota and the Trump administration.
And what it really drives home is how hard it is to keep even these sort of national security threats,
these very complicated cyber issues, divorced from politics,
because you have this sort of awkward-fitting cybersecurity agency housed at DHS,
the same area of government that is tasked with leading these aggressive immigration raids in Minnesota and elsewhere,
that due to those issues, was unfunded for many months recently.
And that included SISA.
You had a SISA that had a lot of people furloughed and not working, even as the war started.
This is fascinating.
The agency that actually could help address some of these issues when it comes to cybersecurity also happens to be sitting in one of the more polarized
departments in the federal government. And by the way, it's at a time where it would seem like the stakes are high because we're at war right now.
Absolutely. In some ways, the stakes have never been higher when we're in an act of conflict with Iran.
Dustin, hearing you talk about this, the question I have in my mind is, the U.S. seems vulnerable.
Iran has this ability. Why aren't they actually taking advantage of this? What's keeping Iran from using this leverage?
That's a million dollar question. I think there are a few things to consider here. First of all, if a foreign power, even one that's currently already at war with the United States, decided to contaminate drinking water, I think that would provoke an enormous response, both from the Trump administration and potentially also internationally. Right now, the Iran war is not very popular with, well, it's not popular in America with most Americans, but it's also not popular among our allies. You could see a situation in which if Iran actually
tried to do that to harm civilians, that could be treated very seriously.
Yeah.
And that could provoke goodwill toward the United States and lead to more of a unity against
this regime.
This is interesting.
What you're saying is what has been up until this point, an unpopular military campaign
by the United States, they could suddenly gain some support if Iran starts taking action
that impacts people inside U.S. borders.
I mean, I think that's certainly a possibility.
I mean, I'm not inside the head of the Iranian hackers who are.
believe to be responsible here, but that is one thing to consider. I mean, I think another thing is
you want to keep your options open. This sort of option of contaminating drinking water,
hypothetically, might not be something they feel like they need to do yet, or they're not
cornered enough where they feel like that's a step they need to take. They want to keep that
in their back pocket potentially. And that's not a crazy notion because we've seen it with another
foreign adversary, China. China for years has, in fact, been
infiltrating critical infrastructure networks throughout the United States, including water systems,
in what officials have said is a prepositioning effort to burrow inside these systems
to potentially one day later on cause massive disruptions that would occur potentially in the event
of a major conflict with the U.S. For example, a fight over Taiwan. This is something that the
officials that I speak to, say, is sort of a top-of-mind concern, and it's something that no one has
been able to figure out how to address. So even if it's unclear as of now, when Iran might take
advantage of this, whether Iran could take advantage of this vulnerability, it is a vulnerability
that is still unaddressed when it comes to U.S. national security. It's a huge vulnerability,
and it's a huge one that I think people can understand.
I mean, this is not sort of an abstract theoretical thing.
This is your drinking water.
This is, you know, the tap coming out of your kitchen sink.
This is something that we take for granted every day in a developed country
that is hugely vulnerable and has been for decades
and continues to get more vulnerable in some respects
as these systems become more and more digitized,
more and more accessible in some ways.
And if that doesn't,
doesn't wake people up to the very severe risks here.
I don't know what else will.
Well, Dustin, I appreciate your reporting.
Thank you. Thank you for having me.
We'll be right back.
Here's what else you need to know today.
Clerk will call the roll.
Senator Johnson.
Yes.
Senator Langford.
All right.
On Thursday, a Senate committee voted along party lines to hold Dr. Anthony Fauci,
the face of the government's COVID response, in contempt of
Congress. Fauci invoked the Fifth Amendment and refused to answer questions during a hearing last
week about the origins of the coronavirus. Dr. Fauci faced no risk of federal prosecution.
All he had to do is tell the truth. More than 100 times, though, he refused. That is what we
are voting on today. The resolution, spearheaded by the Senate Committee's Republican chairman,
Ram Paul, highlighted the deep partisan divisions over Fauci and his legacy. Paul and other
Republicans have argued that a pardon President Joe Biden gave Fauci made Fauci ineligible for
Fifth Amendment protections. Biden was moved to issue the pardon before he left office because of
Republican threats to imprison Fauci. Fauci's attorney called the Senate vote a political stunt.
And President Trump signed a pair of executive orders aimed at restricting birthright citizenship
after the Supreme Court ruled that a similar effort by the administration was unconstitutional.
A very, very unfortunate decision.
So we're making adjustments because it's very unfair.
It was not immediately clear how the orders would be enforced,
but any renewed effort to prevent babies born in the U.S.
from automatically gaining citizenship
would likely be met with legal challenges.
Today's episode was produced by Stella Tan, Lexi D.A.O. and Olivia Nett.
It was edited by Annie Minoff and Michael Benoit,
and contains music by Marion Lazzano,
Diane Wong, and Rowan Nemisto.
Our theme music is by Wonderly.
This episode was engineered by Alyssa Moxley.
The Daily Studio support team is Maddie Masiello,
Nick Pittman, Kyle Grandillo,
Afim Shapiro, and Samantha Winter.
Our radio team is Jody Becker,
Rowan Neimisto, Diane Wong, and Catherine Anderson.
Alexandra Lee Young
is our deputy executive producer.
Michael Benoit is our deputy editor.
Paige Cowitt is the editor of the Daily.
Ben Calhoun is our executive producer.
Special thanks to Sam Dolnik
and the founding editor of the show, Lisa Tobin.
That's it for the Daily.
I'm Zolinkano Young's.
See you on Sunday.
