U.S. Water Attacks: Blame Game and Cybersecurity Flaws Unveiled
(SeaPRwire) - By: Gavin Thorne Malicious cyber activity hit U.S. water systems in at least seven states last week. Minnesota IT Services said over 30 municipal facilities were targeted July 26-27. Michigan reported nine attacks over the weekend. Hackers remotely accessed controls, changed passwords, and caused operational disruptions, as FBI and EPA warned. FBI and EPA joint statement detailed hackers' tactics: accessing internet-connected systems, leading to issues like flooding. EPA had long flagged vulnerabilities in local water systems: outdated software, poor network security, weak access controls. Responsibility for cybersecurity is split between local operators and federal bodies, with funding from both complicating upgrades. Attacks came days after federal agencies updated warnings about Iranian cyber threats targeting critical infrastructure. The 2023 Pittsburgh attack, linked to CyberAv3ngers affiliated with Iran’s IRGC, added context. Escalating U.S.-Iran tensions, marked by near-daily strikes and Strait of Hormuz standoff, fueled speculation. President Trump dismissed Iranian involvement, blaming Minnesota’s incompetence. Gov. Tim Walz fired back, citing Trump’s Department of Governmental Efficiency (DOGE) slashing CISA’s workforce in 2025. Trita Parsi, Quincy Institute VP, noted Iran’s capable cyber capabilities, suggesting retaliation for U.S. strikes. The attacks expose fragmentation in U.S. critical infrastructure defense. Responsibility split and funding issues leave gaps. Geopolitical tensions further complicate an already fragile cybersecurity posture. Without unified action, vulnerabilities remain. Author bio: Gavin Thorne, investigative journalist tracking special interests and legislative affairs based in Washington, D.C.
More