Is America’s Drinking Water the Next Front in the Iran War?
Episode
27 min
Read time
2 min
Topics
Leadership, Product & Tech Trends, Economics & Policy
AI-Generated Summary
Key Takeaways
- ✓Attack vector — remote access tools: Hackers scan the open internet to locate internet-facing computers that water system operators use for remote management, then use conventional hacking methods to gain entry. Small municipalities often employ only one or two operators who need remote access, making these endpoints both operationally necessary and chronically exposed to outside intrusion.
- ✓Escalation tactic — disabling safety alerts: Once inside networks, hackers are not simply observing; they are switching off internal monitoring systems that flag chemical imbalances or pressure failures to operators. This means contamination could theoretically occur without triggering any automated warning, prompting municipalities across multiple states to issue precautionary boil-water notices as a direct response.
- ✓Regulatory failure — blocked minimum standards: The EPA attempted to establish baseline cybersecurity requirements for water facilities during the Biden administration but was sued by Republican-led states and water industry groups arguing small providers lacked capacity to comply. With roughly 150,000 public water utilities nationwide, many operating aging infrastructure on tight budgets, no federal minimum security standard currently exists.
- ✓CISA gutted during active conflict: CISA, created during Trump's first term specifically to protect critical infrastructure including water systems, has lost over 1,000 staff in the second Trump administration and currently lacks a Senate-confirmed director. This downsizing coincides directly with an active US-Iran conflict, reducing the federal government's primary cyber-defense coordination capacity at maximum-risk conditions.
- ✓China's parallel prepositioning threat: US officials confirm China has separately infiltrated American critical infrastructure networks, including water systems, in a deliberate long-term strategy to embed access for potential future disruption — specifically in a scenario involving military conflict over Taiwan. This represents a second, unresolved layer of infrastructure vulnerability entirely independent of the current Iran-linked campaign.
What It Covers
NYT reporter Dustin Volz examines how Iran-linked hackers have breached water systems across at least 12 states and over 100 municipalities during the US-Iran conflict, exploiting decades-old infrastructure vulnerabilities while CISA, the federal agency responsible for defense, operates with over 1,000 fewer staff than before.
Key Questions Answered
- •Attack vector — remote access tools: Hackers scan the open internet to locate internet-facing computers that water system operators use for remote management, then use conventional hacking methods to gain entry. Small municipalities often employ only one or two operators who need remote access, making these endpoints both operationally necessary and chronically exposed to outside intrusion.
- •Escalation tactic — disabling safety alerts: Once inside networks, hackers are not simply observing; they are switching off internal monitoring systems that flag chemical imbalances or pressure failures to operators. This means contamination could theoretically occur without triggering any automated warning, prompting municipalities across multiple states to issue precautionary boil-water notices as a direct response.
- •Regulatory failure — blocked minimum standards: The EPA attempted to establish baseline cybersecurity requirements for water facilities during the Biden administration but was sued by Republican-led states and water industry groups arguing small providers lacked capacity to comply. With roughly 150,000 public water utilities nationwide, many operating aging infrastructure on tight budgets, no federal minimum security standard currently exists.
- •CISA gutted during active conflict: CISA, created during Trump's first term specifically to protect critical infrastructure including water systems, has lost over 1,000 staff in the second Trump administration and currently lacks a Senate-confirmed director. This downsizing coincides directly with an active US-Iran conflict, reducing the federal government's primary cyber-defense coordination capacity at maximum-risk conditions.
- •China's parallel prepositioning threat: US officials confirm China has separately infiltrated American critical infrastructure networks, including water systems, in a deliberate long-term strategy to embed access for potential future disruption — specifically in a scenario involving military conflict over Taiwan. This represents a second, unresolved layer of infrastructure vulnerability entirely independent of the current Iran-linked campaign.
Notable Moment
When asked directly about the Iran-linked water system hacks, President Trump dismissed the attribution entirely and instead blamed Minnesota Governor Tim Walz — a Democrat and 2024 vice-presidential candidate — for the breaches, despite federal agencies actively investigating Iranian hackers as the responsible party.
Episode Transcript
This podcast is supported by USAFAX. The US is the world's largest oil producer. So why can events halfway around the world raise the price you pay at the pump? In Just the Facts, USAFAX founder Steve Ballmer uses government data to break down questions like this without spin or guesswork. From oil prices to the economy, health care, immigration, and more, get clear answers grounded in the numbers. Watch Just the Facts at usafacts.org/justthefacts. That's usafacts.org/justthefacts. From the New York Times, I'm Zolan Kano Youngs, filling in as host. This is The Daily. A growing number of cities and towns across The US have reported that their water systems have been hacked. The Times found that the operation was likely perpetrated by Iran. Today, my colleague Dustin Volts on the long standing infrastructure vulnerabilities exposed by the recent hacks and how Iran may be seeking a new kind of leverage in the war that affects something as elemental as the water we drink. It's Friday, August 7. Dustin, my guy, we both work in the Washington Bureau. We both live in the same DC neighborhood, and now we are together on The Daily. I'm so happy you are here. This is your first time on the show. Right? Living the dream. Yeah. First time. I'm really happy to be here. We're both living the dream. Alright. Excellent. You cover intelligence and cybersecurity, and I know that national security officials have long warned about the cyber threat from Iran. But this hack that you've been covering, impacting water systems and states across the country, this seems different. Is it? It is different. Yes. What we are living through right now is the stuff seemingly of sensationalized Hollywood thrillers. Wow. A suspected foreign power, which officials tell me is likely to be Iran, breaking into municipal water systems throughout the country and alarming the Trump administration and state officials in a way that we really have not seen before. Okay. So what happened? Walk me through what we know. So the timeline here, it really picks up First, at the beginning of war in February, when federal officials, the cybersecurity agency at DHS, and others issued public alerts saying, Iranian linked hackers are targeting critical infrastructure in The United States, and here's the typical computers that they're looking at trying to break into. But these alerts sort of happen all the time. They're easy to ignore. It's sort of unclear exactly how serious it is, and even if it's occurring, what the hackers might wanna be doing with it. But, clearly, when The United States is at war with foreign power, cyberattacks are something that kind of can become a more pressing concern, especially when that foreign power like Iran can't necessarily retaliate with missiles of its own that can reach the continental United States. Right. These alerts might not be necessarily unusual, but when we are in an active war with Iran, suddenly, there's a bit more of a red …
Get the full transcript (4,887 words) + summary by email — free
One-time email with the complete transcript and AI summary of this episode. No account needed.
One email, no spam. We’ll also show you what SignalCast does.
You just read a 3-minute summary of a 24-minute episode.
Get The Daily (NYT) summarized like this every Monday — plus up to 2 more podcasts, free.
Pick Your Podcasts — FreeKeep Reading
More from The Daily (NYT)
Billy Strings Escaped the Darkness. He’s Playing to Not Go Back.
Aug 8 · 52 min
The Joe Rogan Experience
#2507 - Harland Williams
May 29
More from The Daily (NYT)
The Cyclospora Mystery: How Human Poop Got on So Much Lettuce
Aug 6 · 30 min
Up First (NPR)
Massie Ousted, Trump, Vance and Iran, San Diego Mosque Shooting Investigation
May 20
More from The Daily (NYT)
We summarize every new episode. Want them in your inbox?
Billy Strings Escaped the Darkness. He’s Playing to Not Go Back.
The Cyclospora Mystery: How Human Poop Got on So Much Lettuce
Arizona’s Food Stamp Crisis Is Coming for the Rest of the U.S.
Will Michigan Rewrite the Rules of Democratic Politics?
The Tangled Tale of the Tate Brothers and the Trumps
Similar Episodes
Related episodes from other podcasts
The Joe Rogan Experience
May 29
#2507 - Harland Williams
Up First (NPR)
May 20
Massie Ousted, Trump, Vance and Iran, San Diego Mosque Shooting Investigation
The Joe Rogan Experience
Apr 17
#2485 - John Fogerty
Up First (NPR)
Mar 21
On the Iranian Border, More Military on the Way, Warm Western Winter
The Bulwark Podcast
Mar 13
Tom Nichols: Sinking Into the Mire of a Longer War?
Explore Related Topics
This podcast is featured in Best News Podcasts (2026) — ranked and reviewed with AI summaries.
You're clearly into The Daily (NYT).
Every Monday, we deliver AI summaries of the latest episodes from The Daily (NYT) and 192+ other podcasts. Free for one show.
Start My Monday DigestNo credit card · Unsubscribe anytime