Seven States Became Twelve in Six Days, and No Federal Document Has Named Iran
The FBI and EPA warned water utilities about “malicious cyber actors” on 30 July. By 5 August the count had nearly doubled, Bloomberg had promoted the suspects into its headline, and nobody had published a list of who was hit.
The sequence is documented and the gaps in it are documented too. More than 30 Minnesota community water systems were targeted on 26–27 July, per SecurityWeek, with NBC News and the Washington Post placing the operational-technology intrusion at the same scale statewide. On Thursday 30 July the FBI and EPA issued a joint public service announcement to utilities nationwide; per NBC’s reading, the actors “remotely accessed internet-facing devices, changed IP addresses and passwords, and caused utilities to lose monitoring and control capabilities.” The alert named no state and no country. NBC put the figure at seven states on 31 July. Michigan confirmed on 3 August. By 03:24 ET on 5 August, SecurityWeek was reporting at least 12 states, a count it attributed to ABC News. Only Minnesota, Michigan, Georgia, South Dakota and New Jersey have been named publicly. No agency has published a list.
The attribution language degrades as it travels. The FBI/EPA document says “malicious cyber actors.” NBC has a single unnamed law enforcement official saying the Minnesota intrusion “had hallmarks of Iranian meddling.” The Washington Post says “spy agencies suspect” Iran. CBS News, on 1 August, framed it as investigators probing whether Iranian hackers are responsible and noted that official confirmation “can take weeks or months.” Bloomberg’s newsletter of 5 August, at 18:27 UTC, simply asserts it: “Iran-Linked Cyberattacks on US Water Utilities Continue,” reporting the incidents are “expanding and ongoing, according to an information-sharing center” it does not name in the accessible text. That is a headline running a step ahead of the bureau whose alert started the story.
The confirmed consequences so far are narrower than the coverage. In New Jersey, two municipal systems were targeted; per OANN citing ABC News, internet-exposed programmable logic controllers were compromised, operators temporarily lost remote monitoring and automated management, both utilities shifted to manual operation, and service was not disrupted. Georgia’s Clayton County Water Authority said it “experienced a temporary disruption affecting a portion of its operational systems and water service,” with reduced pressure in some areas and service restored within hours. Minnesota’s IT services spokesperson said there was no indication the breaches contaminated any municipal supply. Michigan is where the numbers diverge: WDIV reported nine systems targeted, while the state environment department’s own statement says only that “we received a small number of reports from Michigan communities indicating activity consistent with what federal agencies described.”
Assessment: Two different things could be producing the rise from seven to twelve. Attacks spreading, or reporting catching up after a federal alert told hundreds of utilities what to look for. The second is at least as likely as the first, and it is the reading nobody has printed. Watch for a new CISA advisory number rather than another update to the existing one: a fresh AA-designation would mean the government treats this as a distinct campaign, and would be the first federal document written about these incidents rather than retrofitted to them. Until then, the honest count is five named states and one contested figure in Michigan.