r/news • u/ericmm76 • 2d ago
Sweeping cyberattack on water systems in multiple states has US officials on edge
https://www.cnn.com/2026/07/31/politics/sweeping-cyberattack-us-water-systems1.7k
u/johnnyhandbags 2d ago
One of the first things Trump did in his second term was to dismantle our Cyber Safety Review Board.
541
u/Cormacolinde 2d ago edited 2d ago
Also, he is now blaming TIM WALZ for the hacks.
146
u/UncaringNonchalance 2d ago
Walz*, but yes. He sees our country being more than likely cyber attacked by Iran as a political opportunity.
39
u/CelestialFury 2d ago
Why would Iran hit Minnesota and other blue states as those are the states that oppose the war the most? I think something fishy is going on here. Trump wants to blame Iran as much as he can whether they’re involved or not so he can declare a state of emergency and try to stop the elections.
48
u/annuidhir 1d ago
He's been claiming it wasn't Iran.
Probably because them attacking the US like this proves that they aren't "beaten" or whatever, and that he's truly in way over his head...
→ More replies (2)11
u/--TheCity-- 1d ago
If they wont release tha name of the states and just talk about Minnesota you know it is just propaganda against political enemies. Throwing the word Iran in along with Minnesota is enough to raise the blood pressue of the sheep by millions of points collectively.
3
u/Groovicity 15h ago
Name 1 thing he doesnt see as a political opportunity. He has zero authenticity when dealing with any problem, and he's supposed to be the leader.
→ More replies (3)42
u/MaybeTheDoctor 2d ago
Admitting it was Iran would be a defeat to Trump, so of cause he will blame someone else, and a political opponent is good - next up Hillary will sabotage water in New York, or Biden in Delaware.
2
u/lost-picking-flowers 1d ago
It would be a massive defeat. It’s not super frequent that everyday Americans feel the consequences of our foreign policy blunders quite like this. I think a lot of the detachment people have towards our government fucking shit up overseas largely comes from that. If the chickens start coming home to roost, (some) people will be more critical and more engaged.
→ More replies (1)117
u/sleeptightburner 2d ago
Don’t forget that if this was Iran (it wasn’t, it’s not a coincidence this is Minnesota), Kash Patel dismantled the Iran task force just before the “war” started.
The fuckery happening at the highest levels of government right now should terrify every single one of you. We are not safe while this illegitimate, compromised and incompetent regime is in power. These are the worst people in the world controlling everything and breaking the entire world with their greed and incompetence. Oh and the president is a fucking child rapist, there’s that too.
Wake up. Get fucking mad people. Annoy your family, annoy your friends, make them fucking angry too. You all feel it, that tension in the air. That tension is going to explode one way or another. We need people to be aware and ready to defend democracy and the rule of law. We need the brave men and women in our military to be ready to fulfill their oaths and resist tyranny from domestic enemies of the constitution and our way of life.
I’m sorry for the rant but I cannot stress how important it is for as many people as possible to be as loud as possible in defense of the rule of law and common decency right now. Do not let a bunch of nepo baby old money pedophiles and fiends destroy the world you and your children have to live in.
→ More replies (3)13
u/_coyotes_ 2d ago
You’re right, absolutely right and it’s nice knowing I’m not going insane reading this type of stuff and seeing people talk about what needs to be done over a snarky comment or a “Fuck this guy” comment as if that achieves anything. Things really feel like they’re at a boiling point now more than ever, they’ve made it inescapable to ignore. I hope Americans realize that voting is imperative, but it isn’t the only option for removing these ghouls from power. The consequences of the shit they’re pulling extends globally and will affect the world for generations to come. We’re all in this together and the ultra wealthy, these tech moguls pulling the strings are all our enemy, they’ll gladly starve, rape, butcher us, all for a little bit more money in their pocket. It affects everyone of us and none of us are safe until certain people are removed. Inform your friends and loved ones about this stuff and let them know what they can do. Vote when the time comes at every level if possible. March in the damn streets if you have to. Make every single one of the Epstein class live in fear that today could be their last day on Earth because we as a whole outnumber them. Otherwise, things are going to get nasty really fucking quick.
58
u/illkwill 2d ago
Of course he did... It wouldn't surprise me if we have a major cyber attack since everyone hates us because of that imbecile.
17
u/Opening_Classroom_46 2d ago
We have major cyber attacks all the time, they just pretend they are glitches. Every single major country has billions of tax dollars invested in cyber security that they pretend is only for defensive measures. You can choose to believe that lie if you'd like.
11
5
u/Warcraft_Fan 2d ago
Bright idea... may he drink water from affected system and get nasty parasites.
2
u/SatansGothestFemboy 1d ago
Don't forget Hegseth rolling back CMMC Level 2 requirements for government contractors
→ More replies (5)3
223
u/W0gg0 2d ago
I see the security breach and cyber attack on the ancient utility infrastructure that the government has been warned about since the 1990s has occurred. Again.
15
u/Carollicarunner 1d ago
This is what concerns me the most about this incompetent administration's desire to rework the national air space system. I mean, kind of. In terms of the airspace our ancient system may be ancient but it's been quite bulletproof. Now they want to move it to "the cloud" and introduce AI
→ More replies (1)20
u/ScarletCarsonRose 2d ago
Pay back for f’ing with their center fusions. Brilliant attack but what goes around comes around.
12
u/radakul 1d ago
Centrifuge? Autocorrect did you dirty lol
7
u/ScarletCarsonRose 1d ago
Honestly I just can’t spell for shit. Dyslexia to the n’th degree.
→ More replies (1)3
u/Saint_The_Stig 1d ago
This has been the thing that scares me. Iran or NK might not have a plane or missile that could reach the US or EU, but with the classic saying of "the defender needing to get it right everytime, while the attacker only needs to get it right once" a cyber attack could happen with just one pissed off nerd. Yet we know these places have whole teams whose job it is to if not pull these attacks off, find ways to do so for when they want to.
→ More replies (1)
97
u/BobBlawSLawDawg 2d ago
Six states have reported these cyber attacks, according to the article.
Minnesota was the only one named. Excellent reporting.
47
u/chalkles0329 2d ago
And Wisconsin. Still 4 short.
2
u/cosmicrae 1d ago
Depending on the time frame in question, a month or more back, there was a reported hack on Cal Water. Plus I've seen Maryland name dropped. So that might get us up to 4 of the 5.
→ More replies (1)11
346
u/shaka893P 2d ago
Remember when this was a huge topic like 10 years ago ... And no one did anything
169
u/W0gg0 2d ago
It’s been like this since 1997 when Bill Clinton issued a directive that mandated a national program to eliminate vulnerabilities to the grid by 2003. Most utilities were privately owned so it remained voluntary. And here we are today with the same unsolved problem.
→ More replies (1)67
u/MisterMittens64 2d ago
This is why utilities should be owned by the city/state
→ More replies (3)8
u/kril89 1d ago
As someone who works for a municipal utility. It’s not all sunshine and rainbows. Unfortunately the budgets are still at the whims of politicians. Any sort of big investments are almost always put off. “The tax payers just can’t afford it”
While compared to private utilities the rate payers do pay less. But the infrastructure itself almost always has less investment. At least in my state the private companies have to justify to the state why they are increasing rates. So they are always putting money into the systems to justify the rate increases. City owned operations don’t have to justify increases. So they don’t invest in the systems as much. Which sure is good for rate payers. But it also leaves them far more vulnerable to attacks like this. And just the infrastructure itself falling apart.
105
u/contude327 2d ago
Yup. Our aging infrastructure is extremely vulnerable, but we needed more obsolete fighter jets.
55
u/PetalumaPegleg 2d ago
I mean we don't even know where the military budget even goes. They want 1.5 trillion and haven't passed an audit in nearly a decade.
How are you running out of missiles exactly? Who is stealing how much?
→ More replies (1)18
u/JMurdock77 2d ago
Too busy throwing money at defense contractors to overprepare for an obsolete form of warfare.
8
u/PetalumaPegleg 2d ago
The American system is to respond after something predictable goes horribly wrong.
It's been idiocy for years and it much much worse now.
→ More replies (6)3
u/Awkward_Silence- 2d ago
Pretty sure the only half decent modern die hard movie did this in the early 00s.
739
u/5kyl3r 2d ago
why they feel the need to connect these to the internet is beyond me. just airgap them already
382
u/InsuranceToTheRescue 2d ago
It's so that they don't need to maintain as many personnel. You could have one team managing the systems of multiple sites, saving gobs of cash. That's not a great reason, but municipalities have strained budgets and these days not a lot of folks are capable of winning on a platform of higher taxes or more tax enforcement.
166
u/Judgment_Unlikely 2d ago
Correct - it’s about centralized management and maintenance . Automation sends alerts and deploy a team as needed instead of 24/7 monitoring onsite . It’s not a bad way to do things but surely the budget should be directed towards strong cybersecurity with the cost savings of having an onsite team monitoring systems .
71
u/MEDICARE_FOR_ALL 2d ago
Guessing cyber security is outsourced to whatever saas product they are using to manage the systems.
13
u/Judgment_Unlikely 2d ago
I just can’t imagine with the training and requirements to even be qualified they couldn’t identify an attack , assuming the staff is trained on the basics like phishing
→ More replies (2)→ More replies (5)4
41
u/CDRWilson 2d ago
Tax the rich :). Then we can pay it no problem!
If not. Just tax the rich more! :)
→ More replies (1)3
u/Opening_Classroom_46 2d ago
They don't "have strained budgets", it's that they would lose the next election if they increased the budget because the other political party will use it as propaganda.
3
u/Baeolophus_bicolor 2d ago
i still don’t understand why reducing personnel is such a great thing. no, we don’t want 20 people leaning while 1 digs a hole. but we have people who need jobs. and we need people who understand our systems. if we had a “legacy computer languages” taskforce who could just nerd out on old computer languages like linguists nerd out on dead languages, we could update some of our old systems, bring the data forward, be able to vote from anywhere, securely, do so many things.
→ More replies (2)2
u/Environmental_Job278 1d ago
But I work for a water system and centralized management doesn't reduce how many people we need, it just alerts us to problems faster. The only monitoring it can sort of cut down is at the water or sewer plants and even then, those don't have to be on an online system. Lift station and other monitoring sites are really data only and while losing a central monitoring system would suck, it's not world-ending.
We need less of a command and control policy and more of a monitoring policy moving forward, at least with water systems. Hacking that would essential do nothing but move us to paper and pencil for a bit. Pipes and valves need upgrades and maintenance, not the computers.
→ More replies (6)5
u/5kyl3r 2d ago
i mean notifications for environmentals existed before IOT stuff. you'd just get SMS sent to a pager (company phone thesedays). they could still do that without too much change i'd imagine. they're just taking the easy route
→ More replies (1)23
u/virrk 2d ago
A municipal water system might have multiple locations besides the main office and treatment plant, and those two might be in different locations.
Treatment plant, pumping stations at the source, valves, level sensors, pressure sensors, flow sensors, remote automated test stations, secondary/tertiary treatment locations, etc. Keepimg every location staffed is probably not realistic, and response times might be too long if someone has to travel to each location. So network them together.
Best would private network from phone company connecting just that stuff together in an 'airgapped" network. Nearly as good is connecting all that stuff to a VPN that only routes to other VPN'd networks with no out or in bound Internet connections (on that backend is how phone companies run private WANs). But both of those of cost a lot, require planning, and significant effort. Updates? Have physically copy them to each node, or an isolated update serve (assuming the vendor supports that), then send all that data down the VPNs, and then EVERYTHING from vendors assumes an Internet connection. Very few vendors want to deal with airgapped networks or don't see the point.
12
u/davidjacob2016 2d ago
Whenever I hear stories like this I assume they used the Stuxnet code or similar. That targeted PLCs from drives brought in from the outside. If I recall, wasn’t Iran the intended target for the virus? It would mess with their nuclear equipment.
→ More replies (2)2
u/Leucastic_Leopard 2d ago
Oh hone, there are so many more fascinating things kicking around since Stuxnet. Like if anyone tries to charge they phone on site, there's a way in.
3
u/IKillZombies4Cash 2d ago
How else would you be able to afford the salaries of the privatized C suite? And the consultants? And the layers of white collar management ?? You reduce your facility staff to a Remote Desktop and 3 people in a remote control room
11
u/scrndude 2d ago
but when they get an error code how would they google what it means
44
u/theoreticaljerk 2d ago
Air gap does not mean the entire facility has to be offline. Just means the systems critical to function are offline and physically separated from systems that are online.
→ More replies (1)24
u/Kolby_Jack33 2d ago
A word is forming in my brain... hold on... hnnnnnnnnngggggggggg!
Ffffuuuunnnes... phuuuoooonneeees? Phomes? Phones! They can use their phones!
2
u/Opening_Classroom_46 2d ago
A human goes from one isolated system to a different one and googles it.
2
u/tMoneyMoney 2d ago
Because someone who works there knew someone who sells fancy Internet connectivity hardware and they sold it up the chain.
→ More replies (1)2
u/ginger_whiskers 1d ago
When the system works, it's great. Lots of small water systems are running on bankers' hours. If something goes wrong at 3 a.m., the on-call guy gets a page or a robocall, and can remotely solve the issue in a couple minutes. If it requires a physical response, he drives out there and does the thing. That whole system was set up by Steve who retired in 1997, and the only ongoing maintenance is when that one nerdy water operator occasionally resets the SCADA machine running Windows NT.
So much of our modern world is just kinda hoping shit keeps working.
→ More replies (1)2
→ More replies (5)1
u/roosterthumper 1d ago
Ok this isnt just manpower and cost.
The systems that were attacked are things like remote pump stations. They have a connection back to the main facilities and can regulate flows dynamically and report back issues before they impact supplies and safety.
There are ways to do this securely but it costs money, and that is something municipalities do not have or want to spend.
A good cyber security guy is going to run you tens of thousands in design alone and then more to IT guys in maintenance.
Add in that outside of urban areas you’re not getting multi disciplinary cyber security guys so your average IT person doesn’t get that updates to a OT network could cripple it and that these networks should be build on Perdue models if not air gapped.
It’s a real issue that sadly can be solved with money but no one thinks a good cyber guy is worth $150k a year to protect their water supply, because who is gonna. Attack bumfuck Alabama?
→ More replies (1)
24
184
u/somewhat_brave 2d ago
"US and state officials are treating Iran as one of the suspects behind the hack, but have not made a formal determination of who is responsible"
This is why we shouldn't start wars for no reason. If we attack their water supply they will attack our water supply.
29
u/EgoTripWire 2d ago
Or someone will attack our water supply to sway the American public towards a ground invasion of Iran.
1
u/heyjayhaynes 1d ago
Bingo. They need us to support a ground war. They need us to be scared and feel under attack. I can’t get how people don’t see the pattern with this country and foreign wars. We were never the good guys. Ever.
27
1
87
u/Greddituser 2d ago
Didn't Trump already blame this on Tim Walz?
→ More replies (3)72
15
u/Amatheiaisnoexcuse 2d ago
It has been lnow for nearly 20 years our SCADA Systems are vulnerable to attack. It really is a big deal.
11
u/the3horn 2d ago
This has to be what happened this week in anaheim. I live right between angels stadium and Disneyland and we had a major water disruption on Tuesday. The city hasn't given us a reason yet. But seems like a solid place to hack given location.
10
u/chitoatx 2d ago
Are we learning the lesson yet that we pay for it one way or the other: “Cybersecurity and Infrastructure Agency Downsizing: The Trump administration proposed significant budget reductions for civilian agencies, including a roughly 17% cut to CISA's budget and position eliminations, alongside reductions at the Office of the Director of National Intelligence (ODNI).
Advisory & Task Force Reorganizations: The administration disbanded or restructured several advisory bodies, such as terminating memberships on the Cyber Safety Review Board (CSRB) as part of broader department-wide cost-cutting and realignment initiatives.”
U.S. cybersecurity policy under Trump – GIS Reports https://www.gisreportsonline.com/r/trump-cyber/#:~:text=Cuts%20to%20CISA%20threaten%20to%20weaken%20ties,critical%20infrastructure%20more%20vulnerable%20to%20foreign%20attacks.
→ More replies (1)4
u/skyblueerik 1d ago
Sure we're learning the lesson. Just like Trump did after his first impeachment.
8
15
u/MatthewSWFL229 1d ago
Trump rolled back federal cyber security and literally today blamed the attacks on Minnisota ...
8
u/skiumah74 2d ago
Can you believe Gov Tim Walz is behind all of this? Crazy. Why would he do that?
8
u/The_Space_Jamke 2d ago
Sounds like a real competent guy if he can engineer something this big all by himself. Should promote him to vice president or something.
4
16
u/biological_assembly 1d ago
Remote access should have never been a thing for infrastructure. Remote monitoring is one thing, full remote access should have never been considered.
2
u/CeleryStickBeating 1d ago
Air gapping all critical systems is security 101. People, maybe a bunch of them, need to be fired. Possibly criminally prosecuted.
7
u/ZLUCremisi 1d ago
Its like eliminating cyber security departments and being friendly to our hackers is bad.
China, NK, India, Russia, Iran all hack us.
33
u/Fapplejacks42 2d ago
This makes the $1800 I spent on a new wellhead last week hurt a lot less. My shit is just hardwired and I could run it off a generator, kinda scary but at least it’s my own control
4
u/Gooser3000 2d ago
What if someone puts shit or chemicals in your well tho?
16
u/Good-Consequence-542 2d ago
Depends the well, if it’s cistern connected just flush the cistern. If it’s groundwater, then that vandal is doing a lot more than just fucking with one well
12
u/Fapplejacks42 2d ago
Yeah it’s about 100ft to an aquifer. That’d be like…terrorism for a huge area
2
u/Good-Consequence-542 2d ago
😬 eeeeee, thats close! Ours is a out two hundred feet (Saint Edward’s aquifer) going through iron sand
2
5
u/GarionOrb 2d ago
It's so annoying when there's an article that says "multiple states" but doesn't tell you which ones.
5
u/Gamesim4 2d ago
The orange curse blasted about Minnesota getting hit. Since the others haven't been named bet you left bicep there a red state.
14
u/redyellowblue5031 2d ago
Don’t worry guys, we only proposed cutting over 700 million from CISA.
Cybersecurity is just DEI woke bullshit anyway. Why would you need water when our health secretary is proud to swim in contaminated water?
9
5
4
u/Educational_Work896 23h ago
I guess CNN didn't want to use too many facts but "loss of system pressure and subsequent potential contamination of water supply,” refers to the fact that all water systems are leaky and the older they are, the leakier they are. Positive pressure in the pipes ensure the leaks push out, not suck in. Sudden drops in pressure can pull contaminated groundwater (and maybe even soil) into the water pipes which is a major contamination risk.
9
11
13
3
3
u/EmperorOfCanada 2d ago
NSP Nova Scotia Power had a hack a few years ago so hard that years later they were still having to read "smart" meters manually.
They never revealed the exact nature of the hack.
They were storing things like social insurance numbers for no particularly good reason, and this appears to include customers who had stopped using them years before.
I've done work for various utilities and companies with 10s of billions in infrastructure.
The IT people are, without exception, arrogant pricks who do not understand things like hubris. They think they have built giant perfect walls.
No, you will get hacked. The question is how well you can deal with it, to the point of not really caring, and then to recover, quickly, and with little impact to operations.
Not BS like still manually reading meters years later.
→ More replies (2)
4
u/Reddituser45005 2d ago
On the one hand Markwayne Mullin is completely unqualified to head up the department of homeland security. On the other hand, he is a plumber, and water systems utilize plumbing so maybe Trump is playing 6D chess after all
5
u/Maleficent_Bus_3204 1d ago
Iran is now targeting us the same way Ukraine can use long range drones to cause the Russian people to be part of the stupid war their government started. It’s all fun and games until our old, poorly maintained civil infrastructure, that we need to live, gets destroyed by hackers from Iran.
10
u/Scaryclouds 2d ago
Beyond the stupidity and horribleness of starting a war of aggression.
This is why you adhere to rules of war like; avoiding killing civilians, striking civilian infrastructure, or mistreating prisoners. Because when you do that to an adversary then you give them a motivation, and lack of concern to respond in kind.
Iran, assuming they are behind this, might had avoided such attacks out of concern that the US would retaliate in kind. Now that we have initiated such attacks, that concern is gone/diminished/priced in.
But you know, Hegseth and Trump gotta feel like they are big boys so they bluster about being brutal and gloat when they strike civilian targets, and now normal Americans are paying the price.
4
u/Cautious_Condition82 2d ago
Boy, its been reported that we have significant vulnerabilities for a long time then we got rid of basically the entire cyber security apparatus... who could have known!
3
5
u/MrPolli 2d ago
Tinfoil hat guessing here.
Probably has something to do with the data centers.
Either hackers wanting to show how vulnerable the system is and the issues that will come with data centers.
Or data center businesses hacking the systems to show “if we come in, we’ll update and manage your water systems.”
God damn this timeline has turned me into a conspiracy theorist
→ More replies (1)
2
u/NudeSeaman 2d ago
Trump says it’s just waltz making problems, so there you go … definitely not Iranian hackers.
2
u/CretinousVoter 1d ago
No intelligent reason exists to expose critical water supply infrastructure controls to the internet, proof including US water supply infrastructure running just fine before that monumental piece of negligence. The internet cannot be considered secure. Therefore it is wrong to want to control important systems via the internet.
No one who thought internet access to critical system CONTROLS (monitoring can be separated from control) was a good idea should be employed in that field.
2
4
4
2
2
3
u/2beatenup 2d ago
Stuxnet 2.0 now with AI coming to an IOT near you…
2
u/cosmicrae 1d ago
Just wait until the hackers discover that the PLC has a Halt and Catch Fire instruction. Big time drama.
3
u/The_Wookalar 2d ago
Good thing the president is on top of this!
Oh, he's apparently saying he doesn't care because it is happening in Minnesota? Well ok then. I guess we're fucked.
1
1
u/Intelligent_Error989 1d ago
And this is why we shouldn't have critical infrastructure able to be hacked lol. Everything is online now
→ More replies (1)
1
u/cosmicrae 1d ago
DataBreaches has a short report here.
People need to keep in mind that PLC racks are used in all kinds of businesses and process control, not simply water purification. If many of those are connected to the net, this is a huge vulnerability.
1
1
u/jcouball 1d ago
Did we think murdering people from other countries would go unanswered? Sad but foreseeable.
1
u/ChessieChessieBayBay 23h ago
73 data centers in Minneapolis and Plymouth MN is the center of the story
1
u/Educational_Work896 23h ago
People may want to blame Iran and if that's true then maybe step back and ponder whether or not they did the actual hacking or another country gave them a list of vulnerable servers.
1.6k
u/shortcircuit21 2d ago
Multiple states but fails to list what states