Skip to main content
The Daily (NYT)

Is America’s Drinking Water the Next Front in the Iran War?

27 min episode · 2 min read
·
Dustin Volts

Episode

27 min

Read time

2 min

Topics

Leadership, Product & Tech Trends, Economics & Policy

AI-Generated Summary

Key Takeaways

  • Attack vector — remote access tools: Hackers scan the open internet to locate internet-facing computers that water system operators use for remote management, then use conventional hacking methods to gain entry. Small municipalities often employ only one or two operators who need remote access, making these endpoints both operationally necessary and chronically exposed to outside intrusion.
  • Escalation tactic — disabling safety alerts: Once inside networks, hackers are not simply observing; they are switching off internal monitoring systems that flag chemical imbalances or pressure failures to operators. This means contamination could theoretically occur without triggering any automated warning, prompting municipalities across multiple states to issue precautionary boil-water notices as a direct response.
  • Regulatory failure — blocked minimum standards: The EPA attempted to establish baseline cybersecurity requirements for water facilities during the Biden administration but was sued by Republican-led states and water industry groups arguing small providers lacked capacity to comply. With roughly 150,000 public water utilities nationwide, many operating aging infrastructure on tight budgets, no federal minimum security standard currently exists.
  • CISA gutted during active conflict: CISA, created during Trump's first term specifically to protect critical infrastructure including water systems, has lost over 1,000 staff in the second Trump administration and currently lacks a Senate-confirmed director. This downsizing coincides directly with an active US-Iran conflict, reducing the federal government's primary cyber-defense coordination capacity at maximum-risk conditions.
  • China's parallel prepositioning threat: US officials confirm China has separately infiltrated American critical infrastructure networks, including water systems, in a deliberate long-term strategy to embed access for potential future disruption — specifically in a scenario involving military conflict over Taiwan. This represents a second, unresolved layer of infrastructure vulnerability entirely independent of the current Iran-linked campaign.

What It Covers

NYT reporter Dustin Volz examines how Iran-linked hackers have breached water systems across at least 12 states and over 100 municipalities during the US-Iran conflict, exploiting decades-old infrastructure vulnerabilities while CISA, the federal agency responsible for defense, operates with over 1,000 fewer staff than before.

Key Questions Answered

  • Attack vector — remote access tools: Hackers scan the open internet to locate internet-facing computers that water system operators use for remote management, then use conventional hacking methods to gain entry. Small municipalities often employ only one or two operators who need remote access, making these endpoints both operationally necessary and chronically exposed to outside intrusion.
  • Escalation tactic — disabling safety alerts: Once inside networks, hackers are not simply observing; they are switching off internal monitoring systems that flag chemical imbalances or pressure failures to operators. This means contamination could theoretically occur without triggering any automated warning, prompting municipalities across multiple states to issue precautionary boil-water notices as a direct response.
  • Regulatory failure — blocked minimum standards: The EPA attempted to establish baseline cybersecurity requirements for water facilities during the Biden administration but was sued by Republican-led states and water industry groups arguing small providers lacked capacity to comply. With roughly 150,000 public water utilities nationwide, many operating aging infrastructure on tight budgets, no federal minimum security standard currently exists.
  • CISA gutted during active conflict: CISA, created during Trump's first term specifically to protect critical infrastructure including water systems, has lost over 1,000 staff in the second Trump administration and currently lacks a Senate-confirmed director. This downsizing coincides directly with an active US-Iran conflict, reducing the federal government's primary cyber-defense coordination capacity at maximum-risk conditions.
  • China's parallel prepositioning threat: US officials confirm China has separately infiltrated American critical infrastructure networks, including water systems, in a deliberate long-term strategy to embed access for potential future disruption — specifically in a scenario involving military conflict over Taiwan. This represents a second, unresolved layer of infrastructure vulnerability entirely independent of the current Iran-linked campaign.

Notable Moment

When asked directly about the Iran-linked water system hacks, President Trump dismissed the attribution entirely and instead blamed Minnesota Governor Tim Walz — a Democrat and 2024 vice-presidential candidate — for the breaches, despite federal agencies actively investigating Iranian hackers as the responsible party.

Know someone who'd find this useful?

Episode Transcript

This podcast is supported by USAFAX. The US is the world's largest oil producer. So why can events halfway around the world raise the price you pay at the pump? In Just the Facts, USAFAX founder Steve Ballmer uses government data to break down questions like this without spin or guesswork. From oil prices to the economy, health care, immigration, and more, get clear answers grounded in the numbers. Watch Just the Facts at usafacts.org/justthefacts. That's usafacts.org/justthefacts. From the New York Times, I'm Zolan Kano Youngs, filling in as host. This is The Daily. A growing number of cities and towns across The US have reported that their water systems have been hacked. The Times found that the operation was likely perpetrated by Iran. Today, my colleague Dustin Volts on the long standing infrastructure vulnerabilities exposed by the recent hacks and how Iran may be seeking a new kind of leverage in the war that affects something as elemental as the water we drink. It's Friday, August 7. Dustin, my guy, we both work in the Washington Bureau. We both live in the same DC neighborhood, and now we are together on The Daily. I'm so happy you are here. This is your first time on the show. Right? Living the dream. Yeah. First time. I'm really happy to be here. We're both living the dream. Alright. Excellent. You cover intelligence and cybersecurity, and I know that national security officials have long warned about the cyber threat from Iran. But this hack that you've been covering, impacting water systems and states across the country, this seems different. Is it? It is different. Yes. What we are living through right now is the stuff seemingly of sensationalized Hollywood thrillers. Wow. A suspected foreign power, which officials tell me is likely to be Iran, breaking into municipal water systems throughout the country and alarming the Trump administration and state officials in a way that we really have not seen before. Okay. So what happened? Walk me through what we know. So the timeline here, it really picks up First, at the beginning of war in February, when federal officials, the cybersecurity agency at DHS, and others issued public alerts saying, Iranian linked hackers are targeting critical infrastructure in The United States, and here's the typical computers that they're looking at trying to break into. But these alerts sort of happen all the time. They're easy to ignore. It's sort of unclear exactly how serious it is, and even if it's occurring, what the hackers might wanna be doing with it. But, clearly, when The United States is at war with foreign power, cyberattacks are something that kind of can become a more pressing concern, especially when that foreign power like Iran can't necessarily retaliate with missiles of its own that can reach the continental United States. Right. These alerts might not be necessarily unusual, but when we are in an active war with Iran, suddenly, there's a bit more of a red …

Get the full transcript (4,887 words) + summary by email — free

One-time email with the complete transcript and AI summary of this episode. No account needed.

One email, no spam. We’ll also show you what SignalCast does.

Browse all The Daily (NYT) transcripts →

You just read a 3-minute summary of a 24-minute episode.

Get The Daily (NYT) summarized like this every Monday — plus up to 2 more podcasts, free.

Pick Your Podcasts — Free

Keep Reading

More from The Daily (NYT)

We summarize every new episode. Want them in your inbox?

Similar Episodes

Related episodes from other podcasts

Explore Related Topics

This podcast is featured in Best News Podcasts (2026) — ranked and reviewed with AI summaries.

You're clearly into The Daily (NYT).

Every Monday, we deliver AI summaries of the latest episodes from The Daily (NYT) and 192+ other podcasts. Free for one show.

Start My Monday Digest

No credit card · Unsubscribe anytime