American water utilities are the pressure gauge, and the President disputes his own agencies' silence
A campaign against internet-exposed water controllers has touched at least 12 states and, per the New York Times, more than 100 facilities. No federal agency has attributed it — and Donald Trump has publicly rejected the Iran attribution anyway.
The sequence is now reasonably firm. On 26–27 July, Minnesota authorities reported that hackers had targeted roughly 30 water systems in the state. From 27 July the FBI said utilities in at least seven states had reported attacks. On 30 July the FBI and EPA issued a joint warning about “malicious cyber actors” targeting operational-technology devices, specifically the programmable logic controllers that govern water quality, chemical dosing and pressure. A CSIS mapping analysis published 19 August counts 12 states with reported incidents and nine publicly confirmed, and cites New York Times reporting that at least 100 facilities were targeted nationally, names and locations withheld. Set against roughly 150,000 water systems in the United States, per TechCrunch, that is a narrow slice — but CISA says the actors are “targeting water entities of all sizes,” and that PLC attacks have “resulted in boil water notices and sustained manual operations.”
CSIS’s assessment of severity is unglamorous and worth holding onto: damage has been relatively minor, with no reports of water quality degraded to the point of endangering consumers. The worst case was in Georgia, where a pump station was shut down, pressure dropped, contamination risk rose and residents were advised to boil water — with no related illnesses reported. CSIS sets out the two available readings without choosing: Iran signalling rather than damaging, in order to cap escalation, or a genuine escalation given the campaign’s breadth against earlier incidents. Kurt Gaudette, head of intelligence at Dragos, described the targets as “very low-hanging fruit” — small utilities with default passwords and internet-exposed controllers. CISA’s own advice is blunt: remove publicly exposed PLCs and other OT from the internet “as soon as possible.”
The attribution gap is the strangest feature. Federal agencies have declined to attribute publicly, while multiple outlets' sources point to Iran. President Donald Trump said he did not think “there was an Iranian cyberattack,” and per TechCrunch blamed the state of Minnesota — the outlet’s speculation about his motive is inference, not fact. Joe Slowik, director of threat research at Dataminr, told the Washington Post, as relayed by the Jerusalem Post: “It is not a secret that these things have been taking place since the spring. There have been disruptions in multiple critical infrastructure sectors. It’s a big deal.” A month on, the distance between the President’s position and his agencies' silence has not closed.
Assessment: This is the frame the British generator story is being hung on, and the fit is looser than the coverage implies. What both cases share is not a threat actor but a class of victim: assets small enough to sit below regulatory notification thresholds and cheap enough to leave a controller facing the open internet. That is an asset-inventory problem dressed up as a geopolitical one. Two cautions on the numbers. The state and facility counts are still moving, and neither CISA nor the FBI has published a list, so treat 12 and 100+ as floors from journalism rather than findings. And note that CISA advisory AA26-097A dates to April, updated in July — it is being recycled in some coverage as a fresh August warning. It is not.