The New York Times app unlocked? Everyone knows you need to subscribe to the Times to access all of the reporting. But what if you could explore the Times for a month for free without putting in a credit card? Now you can. When you download the New York Times app for the first time, your first month in the app is free. A month to go behind the paywall to see what Times subscribers get every single day. If you don't already subscribe to the New York Times, Download the Times app today and get free access for 30 days.
From The New York Times, I'm Zolan Kano-Youngs, filling in as host. This is The Daily. A growing number of cities and towns across the U.S. have reported that their water systems have been hacked. The Times found that the operation was likely perpetrated by Iran. Today, my colleague Dustin Volz on the longstanding infrastructure vulnerabilities exposed by the recent hacks and how Iran may be seeking a new kind of leverage in the war that affects something as elemental as the water we drink. It's Friday, August 7th. Dustin, my guy, we both work in the Washington bureau. We both live in the same D.C. neighborhood, and now we are together on The Daily. I'm so happy you are here. This is your first time on the show, right?
Living the dream. Yeah, first time. I'm really happy to be here.
We're both living the dream. All right. Excellent. You cover intelligence and cybersecurity. And I know that national security officials have long warned about the cyber threat from Iran. But this hack that you've been covering, impacting water systems in states across the country. This seems different. Is it?
It is different, yes. What we are living through right now is the stuff seemingly of sensationalized Hollywood thrillers.
Wow.
A suspected foreign power, which officials tell me is likely to be Iran, breaking into municipal water systems throughout the country and alarming the Trump administration and state officials in a way that we really have not seen before.
Okay, so what happened? Walk me through what we know.
So the timeline here, it really picks up first at the beginning of the war in February when federal officials, the Cybersecurity Agency at DHS and others, issued public alerts saying, "Iranian-linked hackers are targeting critical infrastructure in the United States, and here's the typical computers that they're looking at trying to break into." But these alerts sort of happen all the time. They're easy to ignore. It's sort of unclear exactly how serious it is, and even if it's occurring, what the hackers might want to be doing with it. But clearly, when the United States is at war with a foreign power, cyberattacks are something that kind of can become a more pressing concern, especially when that foreign power like Iran can't necessarily retaliate with missiles of its own that can reach the continental United States.
Right. These alerts might not be necessarily unusual, but when we are in an active war with Iran, suddenly there's a bit more of a red alert sort of vibe going on here.
Absolutely. And fast forward to mid-July when this alert from cybersecurity agency at DHS is revised to then show that these Iran-linked hackers are breaking into these critical infrastructure networks, but they're not just getting in now, they're doing really interesting kind of crafty things that we previously hadn't seen publicly reported. And that activity betrayed a level of familiarity and a level of sophistication from these hackers that not only showed that they kind of knew what they were doing, but that their intentions may be a lot more sinister than what we maybe previously realized.
Hmm.
So this warning lands July 22nd. Again, doesn't necessarily get a ton of attention, but about 4 days later—
They didn't break in through the door. They cracked the code through the internet.
We start seeing reports first out of Minnesota of widespread hacking activity activity targeting dozens of municipal water systems.
Right now, several Minnesota cities are scrambling to respond to cyberattacks targeting their water systems.
Now, in addition to Plymouth, South St. Paul, Maple Plain, and Braham— and the state and others say that it looks like it's a coordinated campaign.
Some of the systems targeted reported flooding and a loss of pressure, in some cases even shutting it down completely.
And the Minnesota disclosure turns out to really just be the tip of the spear.
Several states are seeing cyberattacks on their water systems.
Minnesota, Michigan, and Georgia are among at least 7 states.
Local authorities in New Jersey, South Dakota, and Georgia have also—
A few days after Minnesota comes forward and discloses this, we see the federal authorities say that they are seeing activity, hackers targeting water systems in at least 7 states.
Right now, the FBI and the EPA are actively warning state— to disconnect their systems from the internet, or at least use a system that has some kind of a breaker. They're also urging utilities, figure out how to revert to manual controls in the event that automated systems are somehow compromised.
And we've only seen that number continue to grow. So my latest reporting is that at least a dozen states and over 100 municipalities across the country are also identifying cyber activity that they believe could be linked to this ongoing hacking spree that's occurring.
Just to clarify, when you say water municipalities, water systems, what are we talking about here?
Right. This is the part of the conversation where I feel the need to disclose, like, I'm not an expert on the sort of tens of thousands of municipal water systems across the country, but— but essentially, yes, we're talking about water Treatment plants, wastewater treatment facilities, infrastructure of every sort of city and town and every municipality that operates, you know, quietly in the background so that we're able to turn on the water in our kitchen and our bathroom.
Wow.
Take a hot shower with adequate water pressure and not worry about, you know, our skin breaking out in a rash. You know, these are the systems, the water towers, the pumps, the sanitation elements of it, monitoring of the chemical levels inside that water that sort of happen in the background so we can lead our everyday lives and not have to worry about this.
So Dustin, walk me through this. What did these hackers actually do? How did they get in these systems?
They got in through very basic means, and that is sort of what is so scary about this, uh, and frustrating to a lot of people that are following it. Essentially, the hackers here scanned the open internet in a way that allowed them to find internet-facing computers that allow the water system operators to remotely manage the water supply from home. You can imagine a situation in which a small town might only have one or two people who are actually working full-time to maintain the water system, and it might be necessary for them to be able to access those systems in case something occurs, like runoff after a major storm. To do things with the pumps to make sure the pressure is working appropriately. So these computers allow operators to do their jobs. Unfortunately, those same computers are just as accessible in many cases for malicious hackers to find and break into using very conventional hacking methods. And you sort of see cases here where, um, just basic cyber hygiene is being ignored or overlooked, and that is allowing these hackers to get inside and get a, a toehold inside these networks.
But you suggested that these hackers were doing something that was more complex, more sophisticated as well, right?
That's right. So the breaking in is sort of any cyber burglar could maybe accomplish a lot of what they're doing to break in. But once you're inside a network, that doesn't necessarily mean you know how to do things to manipulate the system or degrade the system. Now what we're seeing, according to federal authorities, is that these hackers are manipulating the technology, the internal systems, to quietly turn off internal safety mechanisms that would alert local operators if there were a problem in the water supply.
Okay.
So they have computers at home that they use to manage the system. That computer flags an alert when maybe a chemical level of fluoride is adjusted for some reason and they can't fix it, or the water pressure is off because of some pump somewhere is not working properly, that lets them be able to remotely change it or drive over to the actual facility and do some handiwork and fix it. And what we're seeing is these hackers on the inside are turning those systems off in a way that is basically making it seem like the water system's fine, 'cause it's not issuing an alert to the operators—
Whoa.
—letting them know, in fact, know something's wrong.
Okay, so that seems really concerning. So you're saying if water were to be contaminated, the system that would alert local officials, these hackers were able to turn that system off, meaning some of these water systems could be contaminated and officials would not know.
We might not even know it. And that's why you're seeing municipalities in different states sort of take precautionary measures, including boil water notices, to address these concerns because, you know, You don't want to take any risk.
I just want to clarify here, because like a lot of people are listening to this. Have any of these water systems actually been compromised? Like, has the drinking water at this point actually been impacted by this hacking scheme?
We have not seen drinking water actually contaminated as a result of a cyberattack, at least no public disclosures of that that I am aware of. But I have never in all my years of covering this kind of thing had officials and security experts talk to me with such alarm about the possibility here of what could take place if we don't address it quickly enough and we aren't paying attention and closely enough to what is happening right now. What's also very notable about this is that this is not a surprise attack. This is something that cybersecurity and intelligence officials have been warning about for years across Democratic and Republican administrations. It's a known problem, and it is something that the investigators confronting it right now are having to do with fewer resources than they've had in a very long time.
We'll be right back.
I'm Jonathan Knight, and I'm the general manager of New York Times Games. If you play our games, you probably know there's something a bit different about them. Just like there are writers behind the articles you read in the Times, there are creators behind our daily puzzles. Tracy Bennett curates the day's Wordle solution to keep it lively and varied. Wenilu creates each Connections board, including all those categories that try to stump you. Sam Azersky combs through every last letter, word, and pangram in Spelling Bee so that loyal players of all skill levels enjoy it. Our puzzles are human-made every day with the standards you'd expect from the New York Times. And this matters because when you choose to spend time with our games, it should be time well spent solving puzzles that are challenging, surprising, and joyful. Puzzles handcrafted for you. We think that's something worth investing in and something worth paying for.
Subscribe now for a special offer on all of our games at nytimes.com/join games.
So, Dustin, tell me the story of how officials knew something like this could happen, but they were still caught unprepared when it did.
Well, quite simply, officials knew something like this could happen because in some sense it already has happened. An episode that I think is particularly relevant is in 2013.
New revelations that Iranian hackers infiltrated a small dam located less than 20 miles outside New York City.
In upstate New York, there was an intrusion at a small dam that was attributed by the U.S. government to Iranian hackers.
Officials say it's a new frontier for cybercrime, attempting to take over a physical piece of U.S. infrastructure. That means that an enemy of this country was potentially able to put American lives in danger, all from the comfort of a theoretical computer terminal in downtown Tehran.
And in this instance, we were just lucky. The dam actually just happened to be turned off for routine maintenance work. Wow. So in the event that they wanted to mess with the dam, they basically wouldn't have been able to. But still— This is the first time that individuals working for a foreign government have been charged with a cyberattack on U.S. infrastructure. This was Iranian hackers who were later named and indicted by the Justice Department who infiltrated this water system.
So there have been warning shots then, so to speak. Officials knew about this. So have there been attempts to fix it?
There have certainly been efforts. I mean, there was a major effort in the Senate 15 years ago by Senator Susan Collins and Senator Joe Lieberman to have major cybersecurity legislation passed that would have specifically created cybersecurity standards for a variety of critical infrastructure networks, including water. That came close to passing. It did not, though. Hmm. There was lobbying efforts through various industry groups who were concerned about creating standards for small localities that maybe wouldn't be able to keep up. That was the concern, or one of the concerns expressed at the time. More recently, during the Biden administration, the EPA attempted to create minimum security guidelines for water facilities specifically, and were sued for it by a few Republican-led states and water industry groups. That again said essentially these are difficult to adopt for especially small providers, and we don't think the EPA necessarily has the correct authority to do this. Hmm. And this was just one of many efforts the Biden administration made to sort of take the ball down the field on cybersecurity in different critical infrastructure areas. And many of them were unsuccessful or encountered resistance and were not able to go forward.
But what about the states?
Like, can't the states take this on?
The states have made a variety of efforts, and in fact, you just saw last week New York said they're going to invest about $9 million for specifically water system cybersecurity. This was an effort that was already underway, but they fast-tracked in light of these hacks that are ongoing. But the states are also under-resourced. Right. They have budgets they need to balance, and this is not an area that necessarily resonates with voters who are going to the polls in November. Republican or Democrat, you know, when you think of your top issues, water, cybersecurity is not necessarily something that anyone is thinking about.
Not exactly top of the priority for the voters in the polls is water, cybersecurity over, say, education, crime, or filling your potholes.
No, absolutely. And so these water systems, you know, these are public utilities. According to the EPA, there's about 150,000 of them nationwide. Many of them are very small, are not getting a lot of money, and are operating aging technology and aging infrastructure. And So you have a situation in which everybody sort of knows this is a problem, but it's sort of a question of, you know, where's the money gonna come from and where's the help gonna come from? Right. But we have seen one federal effort that was very specifically designed to help states address cybersecurity threats in their infrastructure, and that was created during the first Trump administration, the Cybersecurity and Infrastructure Security Agency, or CISA. That agency is housed at DHS, and it is specifically tasked with trying to ensure the physical and cybersecurity of the nation's critical infrastructure, including energy grids, oil and gas pipelines, and crucially, water systems.
Okay, that's a long list. How's it go about doing that?
CISA is intended to take classified intelligence, downgrade it in a way that they can share with states and let them know about the threats they're seeing coming from especially foreign actors. And help them work together with federal partners and each other to figure out ways to address the threats, to adopt best cybersecurity practices, and in some cases, to find pots of money that can help them do that.
Interesting. So this is almost like the federal government's geek squad coming and saying, we're gonna fix your systems, or at least raise a flag and let you know what might be coming.
That's right. And it's not just the water systems that they work on. They also do have a number of other areas of focus, including, at least historically, election security and helping states make sure that their voting machines are safeguarded from any tampering as well.
Election security. Okay. That would seem to be an issue that might put you in shaky waters with President Trump.
That is an understatement. CISA was in many ways one of the strongest accomplishments of the first Trump term. He signed it into law. He signed it into law. It was part of his legacy, and it was something that people had been clamoring for for years. You have to remember, this was in the wake of Russian meddling in the 2016 election, when Democrats and many Republicans thought election security was a very, very serious, paramount issue that we needed to focus on. And that's something that its first director, Chris Krebs, did focus on at CISA. And he had a lot of runway to do a lot of things in that environment. Until after the 2020 election, when he said that the election had in fact been secure from manipulation. And that's when he got crossways with President Trump. Right.
This is something we've seen on the White House beat. President Trump has really gone after and targeted Chris Krebs in his second term. His administration has even investigated him. That's correct.
And collateral damage for the wrath that Chris Krebs has endured since Trump came back to the White House has been his former agency, CISA itself. And so during the second Trump administration, you've seen a severe downsizing and a pared-back mission at CISA. Over 1,000 staffers have been let go. Wow. You've seen efforts more recently by DHS Secretary Mullen to potentially look at hiring back some of those people. But CISA, as it stands now, has less funding than it once had, has way fewer officials working on cybersecurity issues across all of critical infrastructure issues, including water. And during the entire second Trump term, it has not had a Senate-confirmed leader.
So how do these cuts factor into the hack that we have been discussing? Like, how is this being felt on the ground?
Well, it's hard to draw a direct line to the cuts and how a agency is dealing with a specific response, but CISA is a lead agency investigating this intrusion and trying to help the states. And By all accounts, the states that I've been speaking to are very grateful for that help. But it is a different CISA than we have seen previously. It is one that does not have the same clout within the administration. It does not have the same resources. And we are at the same time seeing a bit of an unusual reaction from the federal government or a confusing one. The president of the United States himself was asked about these attacks last week.
And they blame it on Iran. I don't think so. I think I blame it on Minnesota because they're grossly incompetent.
And basically said, I don't think it's Iran. I think the governor's behind it.
I don't think there was an Iranian cyberattack. I think that Minnesota ought to get its act together.
And blamed Minnesota Governor Tim Walz, the Democrat there, for the intrusions.
He blamed the governor of Minnesota for water systems in Minnesota getting hacked.
That's right. I mean, it's no secret that the president does not like the governor of Minnesota who ran as vice president in 2024. There have been a number of clashes in that state over immigration enforcement issues, and this is just seemingly the latest flashpoint between Minnesota and the Trump administration. And what it really drives home is how hard it is to keep even these sort of national security threats, these very complicated cyber issues divorced from politics because you have this sort of awkward-fitting cybersecurity agency housed at DHS, the same area of government that is tasked with leading these aggressive immigration raids in Minnesota and elsewhere. Yeah. That, due to those issues, was unfunded for many months recently. And that included CISA. You had a CISA that had a lot of people furloughed and not working even as the war started.
This is fascinating. The agency that actually could help address some of these issues when it comes to cybersecurity also happens to be sitting in one of the more polarizing departments in the federal government. And by the way, it's at a time where it would seem like the stakes are high because we're at war right now. Absolutely.
In some ways, the stakes have never been higher when we're in an active conflict with Iran.
Dustin, hearing you talk about this, The question I have in my mind is the US seems vulnerable. Iran has this ability. Why aren't they actually taking advantage of this? What's keeping Iran from using this leverage? That's a million-dollar question.
I think there are a few things to consider here. First of all, if a foreign power, even one that's currently already at war with the United States, decided to contaminate drinking water, I think that would provoke an enormous response, both from the Trump administration and potentially also internationally. You know, right now the Iran war is not very popular with— well, it's not popular in America with most Americans, but it's also not popular among our allies. You could see a situation in which if Iran actually tried to do that to harm civilians, that could be treated very seriously. Yeah. And that could provoke goodwill toward the United States and lead to more of a unity against this regime.
This is interesting. What you're saying is what has been up until this point an unpopular military campaign by the United States, they could suddenly gain some support if Iran starts taking action that impacts people inside US borders?
I mean, I think that's certainly a possibility. I mean, I'm not inside the head of the Iranian hackers who are believed to be responsible here, but that is one thing to consider. I mean, I think another thing is you want to keep your options open. This sort of option of contaminating drinking water hypothetically might not be something they feel like they need to do yet, or they're not cornered enough where they feel like that's a step they, they need to take. They want to keep that in their back pocket potentially. And that's not a crazy notion because we've seen it with another foreign adversary, China. Hmm. China for years has in fact been infiltrating critical infrastructure networks throughout the United States, including water systems, in what officials have said is a prepositioning effort to burrow inside these systems to potentially one day later on cause massive disruptions that would occur potentially in the event of a major conflict with the US. For example, a fight over Taiwan. This is something that the officials that I speak to say is sort of a top-of-mind concern, and it's something that no one has been able to figure out how to address.
So even if it's unclear as of now when Iran might take advantage of this, whether Iran could take advantage of this vulnerability. It is a vulnerability that is still unaddressed when it comes to US national security.
It's a huge vulnerability and it's a huge one that I think people can understand. I mean, this is not sort of an abstract theoretical thing. This is your drinking water. This is, you know, the tap coming out of your kitchen sink. This is something that we take for granted every day in a developed country. That is hugely vulnerable and has been for decades and continues to get more vulnerable in some respects as these systems become more and more digitized, more and more accessible in some ways. And if that doesn't wake people up to the very severe risks here, I don't know what else will.
Well, Dustin, I appreciate your reporting.
Thank you. Thank you for having me.
We'll be right back. Here's what else you need to know today. Clerk will call the roll. Senator Johnson. Yes. Senator Lankford. All right. On Thursday, a Senate committee voted along party lines to hold Dr. Anthony Fauci, the face of the government's COVID response, in contempt of Congress. Fauci invoked the Fifth Amendment and refused to answer questions during a hearing last week about the origins of the coronavirus. Dr.
Fauci faced no risk of federal prosecution. All he had to do was tell the truth. More than 100 times, though, he refused. That is what we are voting on today.
The resolution, spearheaded by the Senate committee's Republican chairman, Rand Paul, highlighted the deep partisan divisions over Fauci and his legacy. Paul and other Republicans have argued that a pardon President Joe Biden gave Fauci made Fauci ineligible for Fifth Amendment protections. Biden was moved to issue the pardon before he left office because of Republican threats to imprison voting to imprison Fauci. Fauci's attorney called the Senate vote a political stunt. And President Trump signed a pair of executive orders aimed at restricting birthright citizenship after the Supreme Court ruled that a similar effort by the administration was unconstitutional.
A very, very unfortunate decision. So we're making adjustments because it's very unfair.
It was not immediately clear unclear how the orders would be enforced, but any renewed effort to prevent babies born in the U.S. from automatically gaining citizenship would likely be met with legal challenges. Today's episode was produced by Stella Tan, Lexi Diao, and Olivia Natt. It was edited by Annie Minoff and Michael Benoit and contains music by Marian Lozano, Diane Wong, and Rowan Nymisto. Our theme music is by Wonderly. This episode was engineered by Alyssa Moxley. The Daily Studio support team is Maddie Maciello, Nick Pittman, Kyle Grandillo, Efim Shapiro, and Samantha Winter. Our radio team is Jody Becker, Rowan Nymisto, Diane Wong, and Katherine Anderson. Alexandra Lee Young is our deputy executive producer. Michael Benoit is our deputy editor. Paige Cowett is the editor of The Daily. Ben Calhoun is our executive producer. Special thanks to Sam Dolnick and the founding editor of the show, Lisa Tobin. That's it for The Daily. I'm Zolan Kano-Youngs. See you on Sunday.
I'm Gilbert Cruz, and this week on the Book Review Podcast, the 50 best thrillers of the 21st century.
Police procedurals, private detective novels, cozy mysteries, action thrillers, science fiction thrillers.
Who did it? What happened to the person? What is the twist?
You're racing through, but you're like, stop, it's so good. And then you just go back and read the whole thing again.
A lot of people die by poison.
Arsenic is a good method. Yeah. Listen to The Book Review wherever you get your podcasts.
Over the past week, a growing number of municipalities across the United States have reported that their water systems were hacked. The Times has found that the attacks were most likely perpetrated by Iran.
Today, Dustin Volz, a cybersecurity and intelligence correspondent for The New York Times, explains how the hacking exposes yearslong failed efforts to shore up vulnerabilities in U.S. infrastructure, and how Iran may be seeking a new kind of leverage that could extend the war’s reach to within U.S. borders and affect something as elemental as the water we drink.
Guest: Dustin Volz, a cybersecurity and intelligence correspondent for The New York Times.
Background reading:
Federal and state officials are racing to address an assault on the nation’s water supply.
Cyberattacks on water systems nationwide that affected Michigan and Minnesota also included at least five more states. Evidence points to Iranian involvement.
Photo: Jenn Ackerman for The New York Times
For more information on today’s episode, visit nytimes.com/thedaily. Transcripts of each episode will be made available by the next workday.
Subscribe today at nytimes.com/podcasts or on Apple Podcasts and Spotify. You can also subscribe via your favorite podcast app here https://www.nytimes.com/activate-access/audio?source=podcatcher. For more podcasts and narrated articles, download The New York Times app at nytimes.com/app. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.