The New York Times app?
Times to access all of the reporting. But what if you could explore the Times
“for a month? For free, without putting in a credit card. Now you can. When you”
download the New York Times app for the first time, your first month in the app is
free. A month to go behind the paywall, to see what Times subscribers get every single day. If you don't already subscribe to the New York Times, download the Times app today and get free access for 30 days. From the New York Times, I'm Zollincano Youngs, filling in as host. This is the Daily. A growing number of cities and towns across the U.S. have reported that their
water systems have been hacked. The Times found that the operation was likely perpetrated by Iran. Today, my colleague Dustin Fultz, on the long standing infrastructure vulnerabilities, exposed by the recent hacks, and how Iran may be seeking a new kind of leverage in the war that affects something as
“elemental as the water we drink. It's Friday, August 7th. Dustin, my”
guy. We both work in the Washington Bureau. We both live in the same DC neighborhood. And now we are together on the Daily. I'm so happy you are here. This is your first time on the show, right? Living the dream. Yeah, first time. I'm really happy to be here. We're both living the dream. All right, excellent. You cover intelligence and cybersecurity and I know that national security
officials have long warned about the cyber threat from Iran, but this hack that you've been covering impacting water systems and states across the country. This seems different, isn't it? It is different. Yes. What we are living through right now is the stuff seemingly of sensationalized Hollywood thrillers, a suspected foreign power, which officials tell me is likely to be Iran,
“breaking into municipal water systems throughout the country and alarming the”
Trump administration and state officials in a way that we really have not seen before. Okay, so what happened? Walk me through what we know. So the timeline here, it really picks up first at the beginning of war in February when federal officials, the cybersecurity agency at DHS and others issued public alerts saying
Iranian linked hackers are targeting critical infrastructure in the United
States. And here's the typical computers that they're looking at trying to break into. But these alerts sort of happen all the time. They're easy to ignore. It's sort of unclear exactly how serious it is. And even if it's occurring, what the hackers might want to be doing with it, but clearly when the United States is at war with a foreign power, cyber attacks are something that
kind of can become a more pressing concern, especially when that foreign power like Iran can't necessarily retaliate with missiles of its own that can reach to continental United States. Right, these alerts might not be necessarily unusual, but when we are in an active war with Iran, suddenly there's a bit more of a red alert sort of vibe going on here. Absolutely. And fast forward to
mid July when this alert from cybersecurity agency at DHS is revised to then show that
these Iran linked hackers are breaking into these critical infrastructure networks.
But they're not just getting in now. They're doing really interesting kind of crafty things that we previously hadn't seen publicly reported. And that activity betrayed a level of familiarity and a level of sophistication from these hackers that not only showed that they kind of knew what they were doing, but that their intentions may be a lot more sinister than what we may be previously realized.
So this warning lands July 22nd. Again, doesn't necessarily get a ton of attention, but about four days later. They didn't break into the door. They cracked the cold through the internet. We start seeing reports first out of Minnesota of widespread hacking activity targeting dozens of municipal water systems. Right, now several Minnesota cities are scrambling to respond to cyber attacks targeting their water system.
Now, in addition to Plymouth, South St. Paul, Maple Plane and Bram and the states and others say that it looks like it's a coordinated campaign. Some of the systems targeted reported flooding and a loss of pressure, in some cases, even shutting it down completely. And the Minnesota disclosure turns out to really just be the tip of the spear. Several states are seeing cyber attacks
On their water system.
Jersey, South Dakota and Georgia. A few days after Minnesota comes forward and discloses this,
we see the federal authorities say that they are seeing activity, hackers targeting water systems at least seven states. Right now, the FBI and the EPA are actively warning state officials to disconnect their systems from the internet or at least use a system that has some kind of a breaker. They're also urging utilities figure out how to revert to manual controls in the event that automated systems are somehow compromised. And we've only
seen that number to integrate. So my latest reporting is that at least a dozen states and over 100 municipalities across the country are also identifying cyber activity that they believe
could be linked to this ongoing hacking spree that's occurring.
“Just to clarify, when you say water municipalities, water systems, what are we talking about here?”
Right. This is a part of the conversation where I feel the need to disclose like I'm not an expert on the sort of tens of thousands of municipal water systems across the country. But essentially, yes, we're talking about water treatment plants, wastewater treatment facilities, infrastructure of every sort of city in town and every municipality that operates, you know, quietly in the background so that we're able to turn on the water in our kitchen and our bathroom.
Wow, take a hot shower with adequate water pressure and not worry about our skin breaking out in a rash. You know, these are the systems, the water towers, the pumps, the sanitation elements of it, monitoring of the chemical levels inside that water, the sort of happen in the background so we can lead our everyday lives and not have to worry about this. So Dustin,
“walk me through this. What did these hackers actually do? How did they get in these systems?”
They got in through very basic means and that is sort of what is so scary about this and frustrating to a lot of people that are following it. Essentially, the hackers here scanned the open internet in a way that allowed them to find internet facing computers that allow the water system operators to remotely manage the water supply from the home. You can imagine a situation in which a small town might only have one or two people who are actually working full time to
maintain the water system and it might be necessary for them to be able to access those systems in case something occurs like run-off after a major storm to do things with the pumps to make sure the pressure is working appropriately. So these computers allow operators to do their jobs. Unfortunately, those same computers are just as accessible in many cases for malicious hackers to find and break into using very conventional hacking methods and you sort of see cases here
where just basic cyber hygiene is being ignored or overlooked and that is allowing these hackers to get inside and get a to hold inside these networks. But you suggested that these hackers were doing something that was more complex, more sophisticated. That's right. So the breaking in is sort of any cyber burglar could maybe accomplish a lot of what they're doing to break in. But once you're inside a network that doesn't necessarily mean you know how to do things to manipulate the system
or degrade the system. Now what we're seeing according to federal authorities is that these hackers are manipulating the technology, the internal systems to quietly turn off internal safety mechanisms that would alert local operators if there were a problem in the water supply. So they have computers at home that they use to manage the system, that computer flags on alert when maybe a chemical level of fluoride is adjusted for some reason and they can fix it or the water pressure is off because
of some pump somewhere is not working properly. That lets them be able to remotely change it or drive over to the actual facility and do some hand-ywork and fix it. And what we're seeing is these
hackers on the inside are turning those systems off in a way that is basically making it seem
like the water system fine because it's not issuing an alert to the operators. Well, letting them know, in fact, know something's wrong. Okay. So that seems really concerning. So you're saying if water were to be contaminated the system that would alert local officials, these hackers were able to turn that system off, meaning some of these water systems could be contaminated and
“officials would not know. We might not even know it. And that's why you're seeing municipalities”
in different states sort of take precautionary measures, including boil water notices to address
These concerns because you don't want to take any risk.
like a lot of people are listening to this, have any of these water systems actually been
“compromised? Like has the drinking water at this point actually been impacted by this hacking”
scheme? We have not seen drinking water actually contaminated as a result of a cyber attack,
at least no public disclosure is of that that I am aware of. But I have never in all my years of
covering this kind of thing had officials and security experts talked to me with such a alarm about the possibility here of what could take place if we don't address it quickly about and we aren't paying attention and closely enough to what is happening right now. What's also very notable about this is that this is not a surprise attack. This is something that cybersecurity and intelligence officials have been warning about four years across
Democratic and Republican administrations. It's a known problem and it is something that the investigators confronting it right now are having to do with fewer resources than they've had in a very long time.
“We'll be right back. I'm Jonathan Knight and I'm the general manager of New York Times Games.”
If you play our games, you probably know there's something a bit different about them.
Just like there are writers behind the articles you read in the times, there are creators behind our daily puzzles. Tracy Bennett curates the day's world of solution to keep it lively and varied. When a Lou creates each connections board including all those categories that try to stump you. Sam Azarski comes through every last letter, word and pangram and spelling bee so that loyal players of all skill levels enjoy it.
Our puzzles are human-made every day with the standards you'd expect from the New York Times and this matters because when you choose to spend time with our games, it should be time well spent solving puzzles that are challenging, surprising, and joyful. Puzzles handcrafted for you. We think that's something worth investing in and something worth paying for. Subscribe now for a special offer on all of our games at nytimes.com/joingames.
So Dustin, tell me the story of how officials knew something like this could happen, but they were still caught unprepared when it did. Well quite simply, officials knew something like this could happen because in some sense it already has happened.
“An episode that I think is particularly relevant is in 2013. New revelations that Iranian hackers”
infiltrated a small damn located less than 20 miles outside New York City. In Upstate New York, there was an intrusion at a small damn that was attributed by the US government to Iranian hackers. Officials say it's a new frontier for cybercrime, attempting to take over a physical piece of US infrastructure. That means that an enemy of this country was potentially able to put American lives in danger all from the comfort of a theoretical
computer terminal in downtown Tehran. And in this instance, we were just lucky. The dam actually just happened to be turned off for routine maintenance work. Wow. So in the event that they wanted to mess with the dam, they basically wouldn't have been able to. But still, this is the first time that individuals working for a foreign government have been charged with a cyber attack on US infrastructure. This was Iranian hackers who were later named and indicted by the Justice
Department who infiltrated this water system. So there have been warning shots then, so to speak, officials knew about this. So have there been attempts to fix it? There have certainly been efforts. I mean, there was a major effort in the Senate 15 years ago by Senator Susan Collins and Senator Joe Lieberman to have major cyber security legislation passed that would have specifically created
cyber security standards for a variety of critical infrastructure networks, including water.
That came close to passing it did not though. There was lobbying efforts through various industry groups who were concerned about creating standards for small localities that maybe wouldn't be able to keep up. That was the concern or one of the concerns expressed at the time. More recently, during the Biden administration, the EPA attempted to create minimum security guidelines for water facilities specifically and were sued for it by a few
Republican-led states and water industry groups. That again said, essentially, these are difficult to adopt for especially small providers. And we don't think the EPA necessarily has the correct
Authority to do this.
of take the ball down the field on cyber security in different critical infrastructure areas.
“And many of them were unsuccessful or encountered resistance or were not able to go forward.”
But what about the states? Like, can't the states take this on? The states have made a variety of efforts. And in fact, you just saw last week New York said they're going to invest about $9 million for specifically water system cyber security. This was an effort that was already underway, but they fast-tracked in light of these hacks that are ongoing. But the states are also under-resourced. They have budgets they need to balance. And this is not an area that
necessarily resonates with voters who are going to the polls in November. Republican or Democrat, you know, when you think of your top issues, water cybersecurity is not necessarily something that anyone is thinking about. Not exactly top of the priority for the voters in the polls is water cyber security over, say, education, crime, or filling your pot holes. No, absolutely. And so these water systems, you know, these are public utilities. According to the EPA, there's about 150,000
of them nationwide. Many of them are very small, are not getting a lot of money. And are operating aging technology and aging infrastructure. And so you have a situation in which everybody sort of
“knows, this is a problem. But it's sort of a question of, you know, where's the money going to come from?”
And where's the help kind of come from? Right. But we have seen one federal effort that was very specific to design, to help states address cyber security threats in their infrastructure. And that was created during the first Trump administration, the cyber security and infrastructure security agency or Sissa. That agency is housed at DHS, and it is specifically tasked with trying
to ensure the physical and cyber security of the nation's critical infrastructure, including
energy grids, oil and gas pipelines, and crucially water systems. Okay, that's a long list. How's it go about doing that? Sissa is intended to take classified intelligence downgraded in a way that they can share with states and let them know about the threats they're seeing coming from, especially foreign actors and help them work together with federal partners and each other to figure out ways to address the threats, to adopt the best cyber security practices, and in some cases to find
pots of money that can help them do that. Interesting. So this is almost like the federal government's geek squad coming and saying we're going to fix your systems or at least raise a flag and let you know what might be coming. That's right. And it's not just the water systems that they work on, they also do have a number of other areas of focus, including, at least historically, election security and helping states make sure that their voting machines are safeguarded from
any tampering as well. Elections security. Okay, that would seem to be an issue that might put you in shaky waters with President Trump. That is an understatement. Sissa was in many ways one of the strongest accomplishments of the first Trump term. He signed it into law. He signed it into law. It was part of his legacy and it was something that people had been clamoring for for years.
“He had to remember this was in the wake of Russian meddling in the 2016 election when”
Democrats and many Republicans thought election security was a very, very serious paramount issue that we need to focus on. And that's something that it's first director, Chris Krebs, did focus on it, Sissa. And he had a lot of runaway to do a lot of things in that environment until after the 2020 election, when he said that the election had in fact been secure from manipulation. And that's when he got crossways with President Trump. Right, this is something
we've seen on the White House be. President Trump has really gone after targeted Chris Krebs and his second term, his administration has even investigated him. That's correct. And collateral damage for the wrath that Chris Krebs has endured since Trump came back to the White House has been his former agency, Sissa itself. And so during the Second Trump administration, you've seen a severe downsizing in a paired-back mission at Sissa. Over a thousand staffers have
been let go. Wow. You've seen efforts more recently by DHS Secretary Mollon to potentially look at hiring back some of those people. But Sissa, as it stands now, has less funding than it
once had has way fewer officials working on cybersecurity issues across all of these critical infrastructure
issues, including water, and during the entire Second Trump term, it has not had a Senate confirmed leader. So how do these cuts factor into the hack that we have been discussing? Like how was this being felt on the ground? Well, it's hard to draw a direct line to the cuts and how a agency is dealing
With a specific response.
states. And by all accounts the states that I've been speaking to are very grateful for that help.
But it is a different Sissa than we have seen previously. It is one that does not have the same cloud within the administration. It does not have the same resources. And we are at the same time seeing a bit of a unusual reaction from the federal government or a confusing one. The president of the United States himself was asked about these attacks last week. And they blame it on Iran. I don't think so.
“I think I blame it on Minnesota because they're grossly incompetent. And basically said, I don't think”
it's Iran. I think the governor's behind it. I don't think it was an Iranian attack. I think that Minnesota would get attacked again. And blamed Minnesota Governor Tim Waltz, the Democrat there for the intrusions. He blamed the governor of Minnesota for water systems in Minnesota getting hacked. That's right. I mean, it's no secret that the president does not like the governor of Minnesota, who ran as Vice President in 2024. There have been a number of clashes in that state over
immigration enforcement issues. And this is just seemingly the latest flashpoint between Minnesota and the Trump administration. And what really drives home is how hard it is to keep even these sort of national security threats, these very complicated cyber issues, divorce from politics. And because you have this sort of awkward fading cyber security agency housed at DHS, the same area of government that is tasked with leading these aggressive immigration raids in
Minnesota and elsewhere, that due to those issues was unfunded for many months recently. And that included CISA. You had a CISA that had a lot of people furloughed and not working. Even as the war started, this is fascinating. The agency that actually could help address some of these issues when it comes to cyber security also happens to be sitting in one of the more polarizing departments in the federal government. And by the way, it's at a time where it would seem like the
stakes are high because we're at war right now. Absolutely. In some ways, the stakes have never been
higher when we're in an active conflict with Iran. Dustin, hearing you talk about this, the question I have in my mind is the US seems vulnerable. Iran has this ability. Why aren't they actually taking advantage of this? What's keeping Iran from using this leverage? That's a million dollar
“question. I think there are a few things to consider here. First of all, if a foreign power,”
even one that's currently already out war with the United States decided to contaminate drinking water, I think that would provoke an enormous response, both from the Trump administration and potentially also internationally. You know, right now the Iran war is not very popular with, well, it's not a popular in America with most Americans, but it's also not popular among our allies. You could see a situation in which if Iran actually tried to do that to harm civilians, that could be treated
very seriously. Yeah. And that could provoke goodwill toward the United States and lead to more of a unity against this regime. This is interesting. What you're saying is what has been up until this point in unpopular military campaign by the United States, they could suddenly gain some support. If Iran starts taking action, that impacts people inside US borders. I mean, I think that's certainly a possibility. I mean, I'm not inside the head of the Iranian hackers who are believed to be
“responsible here, but that is one thing to consider. I mean, I think another thing is you want to”
keep your options open. This sort of option of contaminating drinking water, hypothetically, might not be something they feel like they need to do yet, or they're not cornered enough where they feel like that's a step they need to take. They want to keep that in their back pocket, potentially. And that's not a crazy notion because we've seen it with another foreign adversary,
China. China for years has, in fact, been infiltrating critical infrastructure networks
throughout the United States, including water systems. In what officials have said, is a prepositioning effort to burrow inside these systems to potentially one day later on cause massive disruptions that would occur potentially in the event of a major conflict with the US. For example, a fight over Taiwan. This is something that the officials that I speak to say sort of a top of mine concern, and it's something that no one has been able to figure out
how to address. So even if it's unclear as of now, when Iran might take advantage of this weather Iran could take advantage of this vulnerability, it is a vulnerability that is still on a dress when it comes to US national security. It's a huge vulnerability and it's a huge one that I think
People can understand.
water. This is, you know, the tap coming out of your kitchen sink. This is something that we take
for granted every day in a developed country that is hugely vulnerable and has been for decades and continues to get more vulnerable in some respects as these systems become more and more digitized, more and more accessible in some ways. And if that doesn't wake people up to the very severe risks here, I don't know what else will. Well Dustin, I appreciate your reporting. Thank you. Thank you for having me.
[Music] We'll be right back.
“Here's what else you need to know today.”
Clarke will call the role.
Center Johnson. Yes. Center Lincoln. Hi. On Thursday, a Senate Committee voted along party lines to hold Dr. Anthony Fauci, the face of the government's COVID response in contempt of Congress. Fauci invoked the Fifth Amendment and refused to answer questions during a hearing last week about the origins of the coronavirus. Dr. Fauci faced no risk of federal prosecution.
All he had to do was tell the truth. More than 100 times though, he refused.
“That is what we were voting on today. The resolution spearheaded by the Senate Committee's”
Republican Chairman, Ram Paul, highlighted the deep partisan divisions over Fauci and his legacy.
Paul and other Republicans have argued that a part in President Joe Biden gave Fauci made Fauci an eligible for Fifth Amendment protections. Biden was moved to issue the part in before he left office because of Republican threats to in prison Fauci. Fauci's attorney called the Senate vote a political stunt. And President Trump signed a pair of executive orders aimed at restricting
birthright citizenship after the Supreme Court ruled that a similar effort by the administration
“was unconstitutional. It was not immediately clear how the orders would be enforced.”
But any renewed effort to prevent babies born in the U.S. from automatically gaining citizenship would likely be met with legal challenges. Today's episode was produced by Stella Tan, Lexi D.L. in Olivia and that. It was edited by Annie Minoff and Michael Benoit and contains music by Marion Lesano, Diane Wong, and Rowan Neemisto. Our theme music is by Wanderley. This episode was engineered by Alyssa Moxley.
The daily studio support team is Maddie Masielo, Nick Pittman, Kyle Grandilla, Ephem Shapiro, and Samantha Winter. Our radio team is Jodi Becker, Rowan Neemisto, Diane Wong, and Catherine Anderson. Alexandra Lee Young is our deputy executive producer. Michael Benoit is our deputy editor. Paige Cowett is the editor of the daily. Ben Cowhoon is our executive producer. Special thanks to Sam Dolnik and the founding editor of the show, Lisa Tobin.
That's it for the daily. I'm Zolinkano Young's. See you on Sunday. I'm Gilbert Cruz, and this week on the Book Review podcast, the 50 best thrillers of the 21st century. Police, procedural, private detective novels, cozy mysteries, action thrillers, science fiction thrillers. Who did it? What happened to the person? What is the twist? You're racing through, but you're like, "Stop. It's so good." And then you just go back and read the whole thing again. A lot of people
die by poison. Arsonic is a good method. Yeah. Listen to the Book Review wherever you get your podcasts.


