A Telegram channel promises blackouts, while the intrusions it claims remain unsophisticated and unsuccessful
NBC News reports Iranian probing of US water, telecom and energy systems, sourced to four people with no name attached. Three federal agencies said nothing on the record.
NBC News reported on Wednesday 2 September that Iranian hackers had in recent weeks targeted US telecommunications, energy and other infrastructure alongside water systems, attributing the account to four people with access to government and industry cyberthreat information. No named official, no document, no vendor report accompanies it. NBC’s own framing is narrow: “The attempted cyberattacks have focused on automated systems connected to the internet and so far have not been successful,” as quoted by Political Wire. NBC characterised the recent attempts as technically unsophisticated while noting they still carry risk, because some infrastructure operators depend on basic internet-connected equipment. The circulating quote comes from a Telegram channel calling itself APT IRAN, which posted that “soon, the United States will witness unexpected and critical events in the energy, water, and telecommunications industries.” The channel supplied no evidence of any successful operation.
The official record for the week is silence. CISA did not respond to NBC’s request for comment; the White House referred questions to the FBI, which did not respond; the CIA declined to comment. The numbers being attached to the story do not reconcile either. NBC reports the FBI investigating municipal water systems in at least seven states last month. CBS News, citing unnamed sources roughly a month earlier, put at least twelve states as reporting water-system attacks possibly linked to Iran-backed hackers. Different samples, different definitions, and no basis for merging them. A widely repeated figure of more than 100 water and wastewater facilities targeted is attributed to a CISA advisory dated 21 August 2026, which The Files has not been able to match to any published advisory; the document we can find is AA26-097A of 22 July, on Iran-affiliated actors exploiting internet-connected PLCs.
Assessment: The distance between the Telegram post and the tradecraft is the whole item. A persona that announces itself as an APT is doing branding, not operations; real intrusion sets are named by vendors, not by their own channels. Nobody we can find has published attribution on APT IRAN, and if nobody does in the next fortnight, that absence is the finding. Read the sector list — energy, water, telecoms — as a menu of what frightens Americans rather than a target deck. The threat carries its own deadline: “soon” is testable, and an uneventful week is publishable. Distrust the 100-facility number until the advisory behind it surfaces.