Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran

Posted by jbegley 8 hours ago

Counter61Comment68OpenOriginal

Comments

Comment by londons_explore 6 hours ago

People use 1000x more water than they need to drink.

If a water supply chain attack happened, we would just distribute bottled water for drinking, and people would go without washing for a few days whilst the issue was sorted.

Bottled water production is already big enough that delivering a bottle a day per person in new York is within the scale of the current production and retail networks scope.

It wouldn't cause the mass casualties an enemy might assume.

Comment by halJordan 6 hours ago

It's actually insane to me that the nation convulsed over the inability to get water to flint Michigan and people are still over here doing "no one actually deserves water, you use too much of it anyway"

Comment by nvme0n1p1 5 hours ago

And let's not forget:

> Agriculture accounts for about 80 percent of consumptive use in the United States

https://www.nifa.usda.gov/topics/water

Maybe if we're worried about running out of water, we should prioritize getting the water we do have to actual people. Could the problem be that we're trying to grow avocados in a literal desert? Nah, it's the dang citizens taking too many showers again.

Comment by applicative 4 hours ago

Are you one of these broadminded people who are about to destroy the Peruvian economy and genocide their people because you heard on tiktok that an avocado in the Peruvian desert takes eight gallons etc etc ... while the alternative is applying the half ton of fungicide it takes everywhere else. This is by the way the first desert irrigated, ~5000 years ago, with the same water, by the earliest state in the Americas, growing cotton for export.

Comment by nvme0n1p1 3 hours ago

I'm not sure what Peru has to do with anything. TFA is about the USA, and usda.gov is an American site.

But I bet if the average ancient Peruvian had to choose between their avocados dying or their next-door neighbors dying, they'd choose to save their neighbors. Unfortunately in modern times, I'm not so sure anymore.

Comment by pibaker 3 hours ago

Apple to oranges. The problem with Flint was lead in municipal pipes, and it has been fixed since forever ago. The majority of US water usage is agricultural and that is only really an issue west of the Mississippi. They are completely separate concerns supported by completely separate infrastructures.

Comment by nerevarthelame 6 hours ago

Iran doesn't need to cause mass casualties. They just need to make US citizens hate the war in Iran.

Comment by genocidicbunny 6 hours ago

Trouble is, there's a good chance that a large portion of the population will then be in favour of ending the war by escalating it to the point of flattening Iran. And that portion of the population has somewhat of a correlation with the political base of the current administration.

Comment by applicative 4 hours ago

It is impossible to affect the Persian empire by such means. They might as well have tried to take the Soviet Union or China by like means. There is no such thing as 'flattening' China or Iran

Comment by ChoGGi 4 hours ago

What's he gonna do? Nuke Iran?

You know, I said that as a joke, but...

It's getting hard to tell jokes from reality with this administration (excluding roasts at the WHCD).

Comment by swat535 4 hours ago

How are you going to flatten Iran? A country twice the size of Texas with 90M people.

You would have to fire your entire nuclear arsenal and commit mass genocide.

Even then, you may not be able to destroy the missile cities, many of them were built to be nuclear resistant.

Comment by applicative 4 hours ago

Dunno, Trump's war didn't make them give up on 'Death to America', but just gave it new life.

Comment by BigTTYGothGF 6 hours ago

Exactly how big do you think those bottles would be?

Comment by mindslight 6 hours ago

Who exactly is this "we" in 2026 ?

The only thing I can see is some political crony company getting a big payment from the federal budget to take on the "burden" of doing so. But then not actually distributing enough water so they can still price-gouge individuals because we wouldn't want people to become entitled, right?

Comment by firefax 7 hours ago

Wasn't there a Defcon or Derby talk about this years back? (The insecurity, not the Persian angle)

Struggling for a source.

Guy had the energy of that one Simcity 2000 character who bugs out if you cut back on funding that you'll regret it. Early twenty aughts IIRC?

Comment by bradly 7 hours ago

Not sure about defcon, but Buckminster Fuller wrote waay back in the sixties about the New York's vulnerability to a fresh water supply attack.

If you haven't read it Operating Manual For Spaceship Earth is one of my favorite books.

https://archive.org/details/operatingmanualforspaceshipearth...

Comment by firefax 6 hours ago

I'll throw it on my list, I've got a pretty big backlog right now.

Comment by mikewarot 5 hours ago

>state and local officials throughout the country were on high alert for potential problems in vulnerable computers that are commonly used to monitor and adjust water quality, including chemical-treatment levels and water pressure.

You don't need a full bidirectional internet connection for remote monitoring, and data diodes are a relatively cheap way to monitor them in complete safety.

Completely stopping ingress of control (using above mentioned data diodes) is relatively easy, and should be legislated into being the norm.

Comment by mindslight 1 hour ago

Please expound upon this "data diodes are a relatively cheap way to monitor them in complete safety". I'm familiar with the concept, but do not know they are in widespread use, and off-the-shelfish enough to be considered "cheap". To me, the fundamental problem is that our protocol stacks are all built on an assumption of bidirectional interaction, making "data diodes" require bespoke engineering to define the correct data structures of a type that can be thrown over a wall. Like sure it's easy to cut one ethernet pair, or one serial line wire, but building up a software stack that can use that for one-way communication still seems like a hassle.

Comment by BoardsOfCanada 7 hours ago

Comment by cineticdaffodil 7 hours ago

I think this landscape is littered with simulated systems as honeypot. Once you have it a normal adversary would stop searching, besides regular checks that the gun still works.

Comment by lysace 8 hours ago

The Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) are issuing this Public Service Announcement (PSA) to warn critical infrastructure asset owners and operators that malicious cyber actors (MCAs) are conducting cyber attacks targeting Operational Technology (OT) devices, including Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs), specifically MicroLogix 1100 and 1400 series. Since 27 July 2026, Water and Wastewater Sector (WWS) utility companies in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations. While the FBI has only observed this behavior with the referenced Rockwell PLCs, similar considerations should also be made with other branded PLCs.

After remotely accessing internet-facing devices, the actors changed the IP addresses and passwords, resulting in a loss of monitoring and control functionality. To reduce the risk of compromise, the FBI and EPA recommend removing PLCs from direct internet exposure via secure gateway and firewalls, setting up strong, unique passwords, and utilizing an access control list (ACL) to allow only authorized communication between expected control system devices.

https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-...

Comment by radicality 7 hours ago

Did they literally just leave the water supply plant management software out available on the open internet? Hard to even call this a hack!

Comment by hubbahubbahubba 7 hours ago

Does anyone recall the Colonial Pipeline outage? They had their IT and OT networks segregated but without billing capacity nothing else mattered. You didn’t expect them to let the petrol flow for free, didja? All that it takes is for a “jump box” that spans or bridges supposedly segregated networks to be p0wned to permit compromise of the soft and chewy center.

Comment by alwa 7 hours ago

I mean

Some of these municipal water plants in the US are independently operated by municipalities of awfully few people and even fewer resources to spare, often serving relatively vast areas…

It’s probably not how you or I would set things up—especially after many years of warnings and slick best practices guides-but I can sympathize with “if it’s not broken…”-style maintenance, especially at the local level.

These things have lifespans measured in decades, and budgetary cycles to match… and for all of CISA’s good work (on limited budgets, and with power that’s more persuasive than fearsome) [0], it seems hard to get all 148,000 [1] system operators to afford to care, much less to afford to fix things—much less to check their work.

[0] https://www.cisa.gov/topics/industrial-control-systems , and https://www.gao.gov/assets/d24106576.pdf for an idea of the staffing they’re doing it with…

[1] https://www.epa.gov/dwreginfo/information-about-public-water...

Comment by zahlman 6 hours ago

Who connected the systems to the Internet in the first place?

Why?

Comment by M95D 5 hours ago

Most likely to cut costs and have one person remote-admin all pumps, valves, etc. instead of a crew for each location.

Why didn't they have firewalls, admin accounts, access rights, you know, proper security? They were glad it barely worked at all.

Comment by toomuchtodo 7 hours ago

Yes. The last federal administration attempted to use CISA to encourage better cyber outcomes for water supply systems, and the water industry and Republican states sued over it. There is no will to fix this, only to push the liability elsewhere.

https://news.ycombinator.com/item?id=39243560

https://web.archive.org/web/20240409155326/https://www.awwa....

(cybersecurity practitioner is a component of my professional persona)

Comment by mmooss 6 hours ago

When will the public figure out that many IT exploits are the result of malpractice by developers and network adminstrators, and the businesses employing them? We're building and operating bridges that we know will collapse. Our products are nearly indefensible, literally - they can't realistically be secured except at great expense. We talk about the imbalance between costs of attack and defense; we made that imbalance.

The big LLM security threat is arguably just a revelation of the sh-ty work our field has accepted. Maybe we need to become actual engineers and invest in building proper, reliable, safe systems (which includes not being a dangerous risk for fraud, surveillance, and addiction). The 'anything goes' extreme disruption of many current SV corporate leaders and their technology is, in a way, a culmination of what they've always done.

The good news is that LLMs used properly might make proper engineering less expensive. The LLMs will more likely be used to make sh-t cheaper, so we can make more of it. Unless of course we take action.

Comment by 1vuio0pswjnm7 1 hour ago

28 Jul 2026 22:47:42 UTC

Coordinated cyberattack disrupts water utilities in 30 Minnesota communities

https://statescoop.com/coordinated-cyberattack-disrupts-wate...

https://news.ycombinator.com/item?id=49091021

[ok]

29 Jul 2026 07:47:11 UTC

Cyberattack targeted 30 Minnesota water systems

https://mn.gov/mnit/media/blog/?id=38-761869

https://news.ycombinator.com/item?id=49094533

[ok]

30 Jul 2026 17:08:40 UTC

U.S. Sees Iran as Likely Behind Cyberattack on Minnesota Water Systems

https://www.nytimes.com/2026/07/30/us/politics/minnesota-wat...

https://news.ycombinator.com/item?id=49112788

[ok]

30 Jul 2026 23:12:21 UTC

A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran

https://www.wired.com/story/a-leaked-memo-ties-cyberattacks-...

https://news.ycombinator.com/item?id=49117018

[ok]

31 Jul 2026 13:35:38 UTC

US investigating if Iran was behind cyberattack on water systems in seven states

https://www.cbsnews.com/news/us-investigating-iran-cyberatta...

https://news.ycombinator.com/item?id=49122974

[ok]

31 Jul 2026 18:17:17 UTC

Iranian hackers likely behind Minnesota municipal water cyberattack

https://www.axios.com/local/twin-cities/2026/07/30/report-ir...

https://news.ycombinator.com/item?id=49126761

[ok]

31 Jul 2026 23:55:10 UTC

Cyberattack on water systems in multiple states has US officials on edge

https://www.cnn.com/2026/07/31/politics/sweeping-cyberattack...

https://news.ycombinator.com/item?id=49129814

[ok]

Comment by OutOfHere 6 hours ago

Why are water systems still on the internet? They should be completely cut off. If necessary, remote access must be from dedicated devices only, only to a mirrored view, and never for remote control.

Comment by lorreyfum 6 hours ago

Where does all the money go? Not to cyber apparently.

Comment by nerevarthelame 6 hours ago

DOGE eliminated 1/3 of CISA staff in 2025. Trump reduced the 2026 CISA budget by $491 million (17%). Trump intends to slash their budget by an additional $707 million in 2027.

The ICE budget was just increased by $70 BILLION, bringing its total to >$200 billion.

Comment by lorreyfum 6 hours ago

CISA staff doesn’t do security patches and updates on local water supplies. You’re mixing a lot of stuff around there, none of it relevant to the discussion.

Comment by halJordan 6 hours ago

CISA is the one who mandates these controls and who manages the public/private relationship. Who issues the active exploration warnings. Who suggests legislation to prevent this in the future, including mandatory software updates.

If your question was only a trite recitation of the fact that private enterprise consistently refuses to practice cybersecurity then you've added nothing.

If your question was about who watches the watchers and what we're doing about the fact that private enterprise refuses to practice cybersecurity then it was an incredibly relevant statement.

Comment by lorreyfum 3 hours ago

A public water authority needs to step it up, at least to the level of other public water authorities who don’t have the problem. Simple matter of disconnecting it from the internet and running security patches, c’mon man!

Comment by newfriend 4 hours ago

Good, we need to bolster our immigration enforcement. We have millions of illegal aliens who all need to be removed.

Comment by neves 7 hours ago

In this war initiated by USA and Israel, it isn't Iran who's attacking civil targets.

Comment by applicative 4 hours ago

The existing Iran state entity has killed about a quarter the population of Syria. It has killed basically unlimited numbers of Arabs. It is a killing machine with few parallels in history. The present war is nuts, but the ridiculous fawning over the sick mullahs who dumped the children of Syria in acid baths is literal demonic possession.

Comment by 6 hours ago

Comment by phendrenad2 7 hours ago

Is this the true reason for the cyclosporasis outbreaks?

Comment by jfengel 7 hours ago

Nah. Cyclospora is a parasite, not a virus.

[Riffing on the gag, not an actual misunderstanding, just to be clear.]

Comment by hubbahubbahubba 7 hours ago

Can we still blame Mexico, Taylor Farms and Taco Bell as well?

Comment by xvxvx 6 hours ago

Taco Bell is secretly funded by Iran and North Korea and invented covid…

Comment by krautburglar 7 hours ago

They always point to a state actor to skirt liability for their own shitty IT work. Then the dim evil journalists swallow it whole, later regurgitating it for their eager little baby bird subscribers.

If there were actual penalties for rawdogging a PLC (or any other control system) on the internet, shit like this wouldn’t happen.

Comment by dylan604 7 hours ago

<adjustsTinFoilHat> The Trump plan in Iran is not working. Gotta make them look like the evil bogeyman to get people to support further action.

Comment by Aurornis 7 hours ago

This conspiracy theory would make more sense if he wasn’t working so hard to divert blame away from Iran: https://www.politico.com/news/2026/07/31/trump-minnesota-wat...

> “I blame it on Minnesota because they are grossly incompetent,” Trump said at a cabinet meeting at Camp David on Friday, adding that Walz is “corrupt” and “Iran has bigger problems than worrying about Minnesota.” Asked later if he could rule out Iranian responsibility, Trump said, “ I don’t think there was an Iranian cyberattack. I think Minnesota ought to get its act together.”

Comment by garciasn 7 hours ago

As if it were only Minnesota. But his base doesn’t pay attention to details.

Comment by zahlman 6 hours ago

The rest of the thread demonstrates well enough that flagging would have been a better response than trying to engage with it factually.

But I do appreciate the attempt anyway.

Comment by krautburglar 7 hours ago

Iran is beside the point. There is always a convenient bogeyman: China, Russia, North Korea… They sow discord between peoples to cover-up the ineptitude of domestic institutional assholes.

Comment by garciasn 7 hours ago

Blacks.

Homosexuals.

Communists.

Islamics.

Hispanics.

Liberals.

Intellectuals.

There’s always an other. That’s what the Republicans have been doing for decades.

Comment by zahlman 6 hours ago

> There’s always an other. That’s what the [group I definitely don't belong to] have been doing for decades.

Please reconsider your logic. And:

> Please don't use Hacker News for political or ideological battle. It tramples curiosity.

Comment by garciasn 2 hours ago

This isn’t any such thing; it’s a statement of fact.

Comment by malcolmgreaves 8 hours ago

> “I think Minnesota is behind it,” Mr. Trump said on Friday in response to a reporter’s question about Iran’s possible involvement,

What a coward and a traitor to the American people.

Comment by baron816 7 hours ago

He knows he brought these attacks with his war, but he doesn’t take the blame for anything.

Comment by AnimalMuppet 7 hours ago

Either he knows and doesn't want to take the blame, or he doesn't know. I'm not sure which one is worse.

Comment by jeroenhd 7 hours ago

He stopped going to security briefings before, maybe he simply doesn't care to know.

Comment by puttycat 7 hours ago

> he brought these attacks with his war

I'm no Trump supporter and this war was a big mistake, but justifying a nation poisoning another's civilian water supply is a bit upside down.

Comment by mplanchard 7 hours ago

Yeah, what could we possibly have done[0] to justify an attack on our water supply?

[0]: https://www.commondreams.org/news/iran-water-desalination-pl...

Comment by throw1234567891 7 hours ago

Ask the people of Flint, Michigan?

Comment by krapp 7 hours ago

We don't follow "rules" in war anymore, according to "Secretary of War" Pete Hegseth. We show no quarter and take no prisoners, we pursue "maximum lethality, not tepid legality."

That's American policy now. The gloves are off, no holds barred, everything and everyone is on the table. So I guess we reap what we sow.

Comment by iwontberude 7 hours ago

I hope it gets bad enough people wake tf up and do something with me about it.

Comment by 8 hours ago

Comment by vjvjvjvjghv 7 hours ago

It was probably the same (imaginary) people who damaged the lining of the Reflecting Pool.

I think we should think about making blatant lies by politicians a crime.

Comment by dylan604 7 hours ago

What's one more crime compared to all of the ones they've already committed?

Comment by rozal 8 hours ago

[dead]

Comment by mannanj 7 hours ago

If I was in a power position, I could theoretically channel this water into my own private reservoirs and locations like private land, bunkers, etc to weather a disruption, and blame Iran and it would be really hard to validate.

I mean if I was in a power position I would have also disrupted those in positions who would be validating me, made journalism much harder and have algorithms with LLM-enhanced astroturf accounts running to label any questioning of the official narrative as conspiratorial or tin-foil hat.

I would probably be on sites like this downvoting people who said things like this. Yes. That's how I would do it. edit: Oh I might even consider channeling that water to my data center friends!

Comment by maxerickson 7 hours ago

You know water is kind of big right?

Comment by irishcoffee 7 hours ago

I understand being mad, I also get mad.

This is a bit unhinged.

Comment by throw1234567891 7 hours ago

We used to say that about some things before Snowden. And then there was Snowden.

Comment by krapp 7 hours ago

But they wouldn't need to false-flag an excuse to capture and privatize resources, they could and would just do that openly. The government can just take whatever it wants through eminent domain.

Comment by 7 hours ago

Comment by aaron695 7 hours ago

[dead]