MEFILES · Edition No. 32Today's edition · Archive · RSS
Seven files · One region · Zero illusions
Digital Front Monitor The full edition of August 16, 2026 →
Attribution Still Open

A Dozen States, No Federal Count, and the Word Nobody Has Used Yet Is ‘Confirmed'

TechCrunch’s 14 August explainer on the US water-utility intrusions still calls the attacks “allegedly carried out by Iran.” Two weeks after the first alerts, the number of affected states has drifted upward without anyone in Washington fixing it.

On 14 August at 12:04 PM PDT, TechCrunch published an explainer on the wave of intrusions against American water systems that began in late July, describing them as “allegedly carried out by Iran” and noting that what makes them notable “is how widespread they were, hitting targets in around a dozen states.” That phrasing sits on top of an earlier, smaller number. On 1 August the Washington Post reported a cyberattack on the operating technology at more than 30 water systems in Minnesota and “at least seven states” reporting interrupted water or wastewater operations, citing an FBI and Environmental Protection Agency alert warning that “malicious cyber actors” had been remotely tampering with water systems. TechCrunch also supplies the structural reason the sector is exposed: the United States has more than 150,000 water systems, many run by local operators who “may not have the resources or cybersecurity expertise needed to protect themselves.”

CBS News, publishing at 6:00 AM EDT on 1 August, framed the attribution question as genuinely open: investigators are “probing whether Iranian hackers are behind” the activity, and “official confirmation can take weeks or months as investigators collect technical evidence.” The technical thread predates the window. CISA said in 2023 and 2024 that a group affiliated with the IRGC calling itself CyberAv3ngers exploited programmable logic controllers; CBS reports the same class of device was targeted in Minnesota. A joint advisory updated on 22 July, reported by SecurityWeek, added Schneider Electric and Siemens to the list of vendors whose PLCs have been hit by Iranian APT actors, and described one US victim where FBI investigators found the attacker had used configuration software to download a malicious project file to a PLC, exfiltrating project files and then modifying and deleting the logic inside them.

Assessment: The drift from “seven states” to “around a dozen” happened in outlet copy, not in a federal statement. That is the thing to watch. No agency has published an authoritative victim count, so each publication inherits the previous one’s number and rounds it up; the figure hardens into fact by repetition rather than by evidence. CBS’s line about confirmation taking weeks or months is the honest position, and it cuts both ways — it protects investigators from premature attribution and it gives every intermediate claim a long unpoliced runway. Note also what the July advisory actually describes: PLC tradecraft consistent with a known actor set, which is a technical family resemblance, not a name. Treat the state count as unsettled and the attribution as unmade.