Submind YouTube summaries
Thumbnail for Did Iran Attack U.S. Water Systems?

Did Iran Attack U.S. Water Systems?

Watch on YouTube

Video summary

Cyber attacks targeting U.S. water and wastewater utilities have been reported across at least seven states, including Minnesota, South Dakota, Michigan, Georgia, New Jersey, and Alabama, with some reports suggesting the scope may extend to a dozen locations. Although these incidents exploited vulnerabilities in industrial control systems connected to the internet—often due to poor security practices like default passwords and exposed IP addresses at smaller municipalities—they did not result in widespread contamination or an immediate threat to drinking water quality. Instead, the attacks caused operational disruptions that forced some facilities to issue boil-water notices and revert to manual operations, leading to significant financial losses for the affected utilities. Experts attribute these incidents with a high likelihood of 90% to 95% to Iran, basing this conclusion on behavioral signatures, a history of targeting water infrastructure since 2013, and specific technical tactics linked to Iranian groups such as the IRGC's "Cyber Avengers." The nature of these attacks is characterized as opportunistic disruptions aimed at information warfare rather than long-term pre-positioning, seeking primarily psychological impact and power projection instead of causing physical harm. Consequently, experts advise against framing the events as a form of cyber escalation or accepting narratives that suggest Iran is targeting individual household taps, emphasizing that the primary goal was disruption rather than contamination. In response to these threats, specialists recommend strengthening defensive cybersecurity regulations and increasing funding for water utilities while reviewing existing security tools. They also suggest that private employment of offensive cyber capabilities might be necessary to deter adversaries effectively. The discussion highlights the importance of understanding these nuances amidst alarmist headlines regarding potential U.S. diplomatic openings and quieter government responses, helping to clarify what truly matters in the current geopolitical landscape without succumbing to fear-mongering. The episode concludes by acknowledging the value of this nuanced conversation for providing clarity during times of heightened public concern. Hosts announced that links to analysis pieces from all three guests will be included in the show notes and encouraged audience participation through a survey for feedback on future content. The segment ended with thanks to the guests, a call to subscribe to "State of Play," and information directing listeners to www.csis.org/geopolitics for further analysis, produced by Sarah Baker.
Read the full video transcript
Possible cyber attacks targeting water and wastewater utilities have now been reported across 12 US states. Although there has been no widespread contamination or an immediate threat to public drinking water, it seems like a serious and coordinated attack. So why is US critical infrastructure seemingly so vulnerable? What can be done to respond to it? And I'll be right in thinking this was probably Iran. [music] Okay. So today we are bringing together three experts from right across the SIS actually from all four departments between the four of us. Now um we have Caitlyn Welsh back on the show. Thanks so much for joining Caitlyn. Um, as you'll remember, Caitlyn is the director of our food and water security program in the global development department. And I'm very excited to welcome as well Lauren Williams, who is the deputy director and senior fellow in the strategic technologies program that's in our economic security and technology department. And then calling in, we also have Dr. Nikkita Sha who is a senior fellow with the intelligence national security and technology program in our defense and security department. It's a bit of a mouthful um but um so excited to have you all and just explain kind of the provenence of this. Firstly, thank you to Nina Priya in our external relations department whose whose idea I think was to was to make this happen. But this came, am I right in saying from a a briefing that you did to some um to to the Hill um and then you kind of all got talking more about how you were tackling this. You've all written about it um and and wanted to continue the discussion. So I'm excited to to do it in this format. Thank you for coming on State of Play to do it. I think um we will learn a lot because um I will say although I am quite focused on Iran, I have not been as focused on this. So I want to start by asking you what actually happened. So I think I said I I I think the numbers are 12 reported attacks now or across at least sorry attacks across 12 different states. But Caitlyn, can I start with you? What what has just happened? >> Yeah, thank you. Thanks Will. Great to be back. The number that you gave 12 is something that we're seeing in the press. But I will note that the only official number that we've got from the US government is at least seven. And that comes from an FBI press release that was uh that was released on July 30th. And the FBI said that since July 27th, at least a dozen sorry, at least seven states were subject to these attacks to water utilities. Um, again, the states were not listed, but we have tracked reports of attacks in six states. So, between late July and then as of actually just 3 days ago, August 10th, we've tracked reports of attacks in Minnesota, South Dakota, Michigan, Georgia, New Jersey, and Alabama. Coinciding with this FBI press release, I will also say that SISA, the Cyber Security and Infrastructure Security Agency, has issued a few warnings since the war in Iran started. A couple of those were at the end of July and they also talked about a significant increase in cyber threat actors targeting essentially water infrastructure. So that's as of the end of July. I will also say that um those notices were reiterating a notice that was first posted by SISA on April 7th and that talked about um authorizing a agencies identifying um again attacks to water infrastructure hitting multiple cyber attacks hitting multiple sectors. That press release did not identify how many states, whether one or multiple. So, at the end of the day, we really don't know how many states. We know at least seven from the FBI. In the press, we're seeing around a dozen. >> I'll stop there. >> Okay. And what actually happened? I mean, when we say cyber attack, it sounds quite scary, but as I said, as far as I know, there haven't been, you know, really widespread like people's water didn't just turn off. Um, it's not been poisoned. Maybe I I don't want to downplay it, but like how how how serious is what actually happened? >> Lauren, I'll jump in and then I think we all uh can add add uh dimensions to this. So, so let me take it to the um kind of the the cyber attack kind of the tactics uh level and then talk get to your your real question which is about the the actual impact which you know the important thing as you said will and as um you noted as well Caitlyn is that drinking water is is safe. We haven't heard of any reports across all of those states and all of the the smaller municipalities that were impacted and I'll get out what we mean by impacted that um there has been any contamination of the water system. So that is a resilience story, a good story for the United States. But um you know when you look at this from a a cyber security perspective, it's also a story again of how vulnerable our critical systems such as water are. So the the quick and dirty essentially is that cyber threat actors were able to get into these water systems from a wide range of states in the United States across the country due to the fact that critical industrial control systems these programmable logic controllers we've been hearing this term um for the last several weeks are connected to the internet in a lot of places across the United States which means that our critical water surfaces have internet connective connection points which attackers were able to exploit and there are a lot of reasons for that which I'm sure we'll dig into quite a bit here which is that you know these municipalities are generally very small there might just be a few people who are working at them and they need to be monitored kind of 24 hours a day which requires you to be able to have um you know remote access and uh in many of these cases uh there were kind of simple cyber security basics that weren't being followed default passwords were used. Um, IP addresses were exposed on the internet that attackers were able to exploit and to get into these systems and to cause >> physical impacts to cause changes in pressure to cause discernable anomalies in these systems. But again, fortunately, we didn't see actual water quality impacted. >> Okay, >> thanks Lauren. in terms of impacts and I um appreciate Lauren's explanation of exactly the nature of these attacks but um in the words of US government itself um they describe the impacts in terms of boil water notices and sustained manual operations i.e disconnection from internet internet and operation of utilities that way and also operational disruption and financial loss. So those are the way that the >> impacts have been described by at least by CISA um those impacts affecting communities around the country um as well as multiple sectors. So we shouldn't think about it just in terms of impacts on households but also many all of the sectors that rely on water for a variety of reasons. >> Interesting. Okay. So um can you can we talk a little bit more about kind of why this is so vulnerable like the vulnerabilities? I mean, we talk about critical infrastructure and I think maybe a lot of our listeners would assume with all the capabilities of the US government that that there would be a lot of resources put into protecting them. Um, I think Lauren, you started to get at this by saying, you know, lots of these are very small there. You know, they they don't have very many staff. They were using password one 123 uh as the password or something like that. Um, but but kind of what h how do you think about the vulnerabilities of critical infrastructure? Yeah, I'll I'll give a really quick answer and then I'll welcome Lauren and Nikita to join to jump in. But I think that water utilities lie at this dangerous intersection between being fundamentally necessary and fundamentally vulnerable. And in terms of being fundamentally necessary, it's actually um challenging to even describe the importance of water to everything that we do because we rely on it for everything. Everything from all household uses, consumption and sanitation and etc. health purposes, industrial purposes, military purposes, and the list goes on and on. So, fundamental to everything. And then fundamentally vulnerable because there are um the network of water [snorts] utilities around the country is so diffuse. There are about o over 150,000 water utilities around the country. Um many of them very small, small in staff, small in budget with very basic cyber security uh uh elements in place. And I'll let Lauren and Nita build on that. >> Yeah. No, it's exact it's exactly right. And this is gets at one of the the topics that the three of us were like we really want to get into this you know what is the importance of water and the water utilities being targeted including in the context of this conflict which Nikita um will will dive into a and what is the broader conversation around critical infrastructure cyber security because I think it's it's a combination of all of those things water is important in this case it has to do with the the threat actor and its interests and capabilities but also at the same time and I'll I'll stick to this point and then Nikita and can add on our critical infrastructure broadly and we're and that includes water, it includes energy utilities, it includes our transportation and there are 16 sectors and CISA um you know manages this the security of all of these. They are uniquely vulnerable in the United States and that's for all the reasons that that Caitlyn already laid out which is because we have such a dispersed system of owners and operators um utilities included. So, we've got privately managed and owned utilities in the United States. Water, for example, is um kind of operated by localities or or private operators. And then we've got kind of the state level, which may or may not, you know, be very connected um from a cyber security perspective. We already talked about how these utilities might just not have experts um who are steeped in or even thinking about cyber security because they're trying to just keep the water um uh kind of the day-to-day operations of of water um going strong. And then there's the connection between uh the federal government level where you just kind of lose connectivity at each each step that you move up the chain. Um, and all of that is to say that we have a very fragmented and kind of deregulated way of approaching cyber security in the United States. We look at it from a sector by sector level. So water cyber security requirements are different from energy are different from space which I worked on in government. Um, and it just adds to the challenges and it it means and we also have not historically funded cyber security um, adequately in the United States as well. And it really comes to a head in situations like this. And I'll um I'll just add on really briefly um just building on what Caitlyn and Lauren have said, you know, you've got these these very fragile but very critical um ecosystems that we've been talking about. Um and so that makes them lowhanging fruit for adversaries in in a conflict to target because it ultimately gives them symbolic value. They're showing that they can reach into the US homelands. They can tinker around with things and they can have a a pretty important symbolic effect which is very much what they're after. >> So Nikita, let's talk about that then. Let's talk about who did this. So, um I you know the reports are saying it's sort of assumed to be Iran, but I don't think the US government has assigned a culpability explicitly to to Iran. So, what can you tell us about how we know about who did this? >> Yeah, it's it's a really important question and you know, as you said, there's been no official attribution or or kind of recognition from the US government that this is Iran. Um from my perspective it's it's something like 90 95% likely to be Iran because of um the way that the attacks were conducted from a technical perspective. Um so so in cyerspace we tend to think about different actors having their own behavioral signatures almost you know they have certain things about the way that they conduct attacks their intent their capability and if you look across those all signs effectively point to Iran. Um I'll pick out three things. So, one is Iranian cyber actors. Um, whether it's the Ministry of Intelligence and Security or the Iran, uh, the Islamic Revolutionary Guard Corps, they have a history of targeting the water sector across the United States and Israel. Um, that goes right back to 2013 when, um, Iranian actors attacked a dam in New York State. Um, it also, uh, goes to attempts in Israel, um, I believe in 2020 where they tried to poison, um, an Israeli water supply. Um and then it goes through to um you know likely to to the events that we're seeing now, but also an April 2026 advisory that that CISA put out earlier this year um where it pointed to again Iranian cyber attacks on the water and energy sectors. So there's a real continuity there in terms of how Iran um targets the water sectors across you know two adversarial countries. Um the other thing I'll mention is the technical component in question. So if you look at the way that the attackers got in and the particular type of industrial control uh technology that they were targeting, they're called programmable logic controllers, which is a a kind of technical way of saying these are the heavy industrial machines that enable you to control industrial systems basically and monitor what's going on, etc. um c certain Iranian cyber actors and um the IRGC in particular uh this is a group called cyber avengers um that's linked to the IRGC it's highly likely to be them because they have a target uh a history of targeting PLC's in particular um they've done it before in Israel um again this is linked to the CIS advisory in in April this year it's highly likely to be that particular actor so there is always a chance it might not be um but you know from my perspective all signs pointing towards Iran. >> No. >> And I'd just like to underscore something that Nikita said. Um at the highest levels of the US government, there's been reluctance to attribute these attacks to Iran. I will say though that in public issuances from July 22nd and from April 6th, they have named Iran affiliated threat actors targeting critical infrastructure including water infrastructure. So parts of the US government have named Iran. >> Yeah. And I'll jump I was going to jump in here kind of with the somewhat of a question. So hopefully not going in a different direction that you were looking to go will because I think for all of us we've had a lot of conversations in the last couple of weeks with different stakeholder groups about different elements of this uh crisis and one of or these attacks and one of the questions that's come up and my conversations has been you know is it important or is it not to to tie these attacks to Iranian threat actors and as as Nikita argued and I completely agree to map their past you t tactics and techniques to the current um attacks that we're seeing across the country. Kind of why is that important or is it not important? I think it is, but uh kind of curious from Caitlyn and and Nikita's perspectives and Caitlyn, I know you're looking at this in a global context, in the context of the war. >> Yeah. Yeah, that's a really good question, Lauren. Um I I think in the context of the Iran war and its fallout, I think it is important to name Iran if indeed it is Iran. um happy to talk about how targeting water infrastructure sits in the context of the war generally speaking. Um I think though that any any attacks by malicious actors to water infrastructure in the US would have a number of impacts. Um and I'll say really quickly we've been focusing on the physical impacts, what they are and what they are not of these ongoing attacks. Um, beyond these physical impacts though, there are psychological impacts that are real and these attacks certainly have captured public attention and policymakers attention. And then there's also the threat of uh potential future attacks. Um, and whether or not the attacks were effective today um is a different question from whether or not they may be um effective in the future. So in this case that malicious actors might be laying the tracks for future attacks. Um so all all those things would be in place no matter who the actor is. Um in in terms of Iran though assuming it is Iran uh that's responsible for the these most recent attacks. It is interesting to look at it again in the context of the in the broader context of the ongoing war with Iran. I'll pause there though will I don't know if we want to go to Nikita first and then I'm happy to talk about that context. >> Yeah sure. No let's let's turn to Nikita and then but I I'm I'm really interested in that broader context piece. But Nikita, >> it's a really good question and and so what I'd say is if if you if we kind of zoom out for a moment and look at the way that Iran's been um kind of conducting itself so far in the conflict, one of the key things that it's been doing is opportunistic disruption. So the CIS advisory from uh late July uh itself calls the these operations opportunistic targeting. And I think the word opportunism is such a critical point because as we've seen in this conflict in the um 12-day war between Israel and Iran last year and in the Russia Ukraine war that's still ongoing. In conflict cyber actors behave quite differently and what they're doing is they're looking for quick things that they can throw at vulnerable targets that are poorly defended to see what sticks and that to me is very much what it looks like has happened here. Um in this case Iranian actors have been targeting a number of critical infrastructure sectors across the US. So so not just water. Um they've gone after uh energy, they've gone after local government, they've also gone after transport. I I could keep going with that list. Um and in this case, I think they found a particularly poorly set of defended um systems that had some pretty basic vulnerabilities from a cyber perspective. So think, you know, default passwords, lack of authentication, um they had operational technology connected to the internet, which is highly advised against. Um and so they threw something quickly. Um they've actually been building accesses on this. um back to January 2025 and over the course of this year, which to me suggests they weren't looking to pre-position on something. So, in this case, they were looking for instant impact. Part of the reason for that is there are other systems that they're prepositioning on where there's evidence of that against uh different types of US and Israeli organizations. Part of that is also because of the real goal here. So, if you're thinking about an attacker's intent, what the Iranians are really after is um information warfare as an objective. So they're looking for cognitive effect against the US public and in this case yes the primary goal is disruption of the the water systems but really the secondary goal is that psychological effect. So how can they how can they project power by showing that we can reach into the US homeland we can tinker with some of your most critical systems and we can have an effect even though you know you're you're attacking us and you're really grinding us down um you know kinetically uh back in the actual country. this is an area we can where we can punch above our weight and so the goal here it looks to me is very much to so fear to create a sense of insecurity and to project that power directly into the US. Um so for me it's it's less about prepositioning for longerterm attacks. It's much more about immediate quick impact that they will then amplify through social media channels and and through the news. And the last point I'll end on is it's why information warfare during conflict is so tricky because on the one hand there's a real duty right to to report to the American public and the global public this is what we're seeing this is what's going on there is a real risk as to how things portrayed because it can risk amplifying the attack which very much plays into Iran's objectives of of power projection that's so interesting and Nikita just before we started recording we were talking a little bit about this and I was saying you know how much does this actually matter if people weren't I mean Caitlyn you talked about the costs and you talked about um boil um orders, water, sorry, boil water notices, but like if it didn't really harm people, are we exaggerating how bad this is given that cyber attacks are now kind of a part of warfare in the 21st century? So, um yeah, interesting. Um and and I guess Caitlyn, you you said I think you may have a slightly different take on this that it it actually, you know, water is becoming much more of a weapon of of war. So h how are you thinking about this within the broader context of the weaponization of of war and attacks on water infrastructure in this war specifically? >> Sure. And and I would say to your point about how how bad this was um even if there were not widespread attacks um as part of a we could we we might be able to consider these ongoing because we've had notices of new states as of 3 days ago. Even if there were not widespread impacts on households, communities, industry, um these attacks did reveal extreme vulnerabilities. And I I I I'm thinking Lauren might have some more to say about that. Um [sighs] so in in that sense they did have impact by revealing those you know those severe vulnerabilities. Um in terms of the context of these attacks um uh within the Iran war um you know it's interesting to think about these attacks as being opportunistic as Nikita was saying and this could be this could be Iran just you know throwing spaghetti against the wall and seeing what sticks and this is one thing that is that is sticking right now. Um at the same time there are very interesting parallels between two spates of attacks on water infrastructure in the Gulf region as part of this war. One being this spring and then one being this summer. In the spring we saw attacks between Mar early March and early April on multiple countries on water infrastructure in Iran, Bahrain, UAE, Kuwait. Those attacks attributed to United States and Iran. And then again in summer you had attacks on water infrastructure in Iran and Kuwait attributed to the United States and Kuwait sorry and Iran. So two two different spates of attacks. Um around the time of that first debate you had President Trump speaking publicly or at least writing publicly about this and this is from two social. He said if if the Hormoo strait is not immediately open for business we'll conclude our lovely stay in Iran by doing a number of things um uh and Car Island possibly all desalination plans. So, sorry. Um, blowing up and completely obliterating lots of things, including Car Island and possibly all the desalination plants, which we have purposely not yet touched. So, there was an official acknowledgement at least of intent to target those things. And then you did have direct targeting. Um, that was in March. We were tracking those attacks in the Gulf at the same time that SISA was putting out public notices of those attacks happening to US water utilities and in states here in the United States. Again, you had a ramp up in hostilities in the Gulf this July. At the same time that FBI, SISA and others warn of increasing attacks and we're seeing reports of increased attacks. So on the one hand, it could be opportunistic. On the other hand, we are seeing strong parallels between these attacks in the Gulf and in the United States. Yeah, just to jump in here because I think to tie um connected tissue I think to to both of your points like I think what we are seeing is opportunistic targeting of water systems by Iran. So if if that's a way to kind of draw connected dots because as I think Nikita you noted at the very beginning we you know Iran is target 2013 and in 2023 and now we're in 2026 has cons consistently through its uh proxies tied to the IRGC targeted water sector infrastructure. So a dam in 2013, water system in Pennsylvania in 2023, and then right now I think to to the point what we've seen is opportunistic targeting of a specific industrial control system that specifically targets water utilities across a range of states that were vulnerable or had vulnerable systems. So to me I think it does certainly you know point to the fact that there is a specific emphasis on water or specifically an an emphasis and a um developed you know capability of being able to target vulnerable uh water sector infrastructure that has obviously caused physical but not safety impacts across the United States ac across 12 different states. You know, we were earlier when these attacks were first starting to be discussed, there was some conversation around, you know, why Minnesota, why Michigan, for example. But now we're having a conversation where it's South Dakota and Georgia and Alabama. Um, and I think that more so speaks to the infrastructure as opposed to the state. >> So before we start to bring this to a close, I would love to hear from each of you what you think should be done about this. Now, my understanding is there's a bit of a debate among the um sort of in the cyber security world about whether you should go on offense or defense. Um, and again, my understanding is that the Trump administration has leaned a little more into the offensive piece of that, but tackling whichever part of that you want to, I'd love to hear what you think should be done um to to better improve to better build resilience of water infrastructure, but then also to deter Iran. So, Lauren, I know you just spoke, but can I go back to you and c can I start with you on what you would like to see be done in response? >> Sure. So I'm I'm going to focus on the the defensive side of the coin and and going to say that I think as we've all talked about and pointed to different you know data points US critical water infrastructure or expand that to critical infrastructure but I'll talk about water specifically has been known to be vulnerable from a cyber security perspective for a long time and we're seeing that vulnerability um be act acted upon in an opportunist IC but maybe also in the broader context of the war potentially strategic way um by a nation state threat actor which you know means that nation state threat actors are impacting and kind of coming home to roost um in our you know municipalities across the country. So that's the situation that we find ourselves in today and there has been a lot of discussion over years fortunately now it's kind of coming to a head in this current crisis about identifying and implementing requiring specific cyber security requirements or regulations for the water sector in particular. So there were conversations around um the Biden administration putting out water sector cyber security requirements several years ago. There was a lot of push back. there tends to be push back from the industry when you're talking about adding on cyber security requirements because those of course cost money and uh you know the money that it costs uh to focus on cyber security then the argument is that it gets passed on to consumers. So this was the kind of the um thrust of arguments against kind of acting and moving on these requirements several years ago. Now there there um I think several different layers of activities happening across the country and Caitlyn you're probably tracking more than I am but specifically I'll point to um two senators uh Senator Clolobashar Senator Schiff Minnesota and California senators who have put um out um draft legislation essentially that would better empower the EPA, the Environmental Protection Agency, better empower uh cyber security agencies to identify and require ire um best uh specific practices for for utilities across the country. And fortunately as well they are putting up um kind of dollars against those requirements which is the most important challenge yet fund these mandates. So $300 million is what they have um identified. We see states that are well resourced doing this as well. New York for example um just put up you know $9 million against uh cyber security requirements to to better shore up their capabilities. But that's that's a state that's being proactive and has been working on these issues for for several months. So, you know, it is a time of crisis, but we are at least now um seeing some activity on the national level. But that's I'll leave this maybe for a closing thought. Um that's also against the backdrop of kind of uh federal funding cuts and staffing cuts at our critical cyber security agencies, which is not necessarily a good news story here. >> Yeah. Okay. Caitlyn, can I turn to you next? Yeah, certainly. This week so far, I've been tracking some legislation that's been introduced, at least two pieces that have been introduced. Um, I saw a letter from industry that referred to four other pieces of legislation that policymakers should consider supporting. So, there are there's no shortage of proposals on the Hill about how to address issues like this. Um, in terms of what's best to do to fortify our defenses against the ongoing attacks and potential future attacks, one thing that I think is really important is essentially to review what's already in place. It might not be a matter of reinventing the wheel, creating entirely new um authorities and agencies, etc. There might already be a a good set of tools in place that just need attention uh and staffing and funding that we can use in the near term. Um, apart from legislation, I'll also note that there was an an op-ed in the Washington Post this spring that talked about actually a volunteer effort to match cyber security experts with the lowest resourced water utilities to actually just give them those better cyber cyber capabilities in the immediate term, not a long-term fix, but that's a near just a near-term thing that just to put on folks radars. But I think a first step in Congress is just to review what's already in place because again, might not have to reinvent the wheel. Um, in terms of any new legislation that might come on, it's really important to get input from experts from industry and academia and elsewhere as well as water utilities of all sizes because these actually are the smallest utilities that are being that are being attacked right now. And then finally, whenever new legislation, and maybe this is the moment for new legislation to be passed, um, that uh that that legislation protect water utilities of all sizes. And again, right now it's the smallest ones that are being attacked because they have the smallest amount of resources and there is great psychological impact there. At least one piece of legislation that I saw proposed recently actually applies only to medium and large size utilities. I think that would be highly ineffective to pass new legislation that does not protect the utilities that are precisely being targeted. Um so just some thoughts there, but I I'll be watching with a lot of interest on the hill to see if this is a moment for bipartisan action on the issue. >> Great. Nikita, do you have anything to say on the offensive side? Because there's Oh, and please do add on the defensive side as well if you're interested, but I I wonder like should a response be limited to the cyber >> like to the cyber realm or would you like to see a broader response that that goes beyond that? >> Um I think I think it's really important to think about the different facets of of cyerspace, right? So um I I'll kind of make three points. The the first is if you look at Iran's wider behavior in this conflict, yes, they're pursuing opportunistic disruption. They're also investing a lot and really prioritizing in in cyber espionage. They're also thinking about these these cyber enabled influence operations, which is what we've discussed a little bit and having that psychological effect. And so I think a much of the the coverage of of these particular instances pointed out with many of these utilities, they look at the war and think, hold on, that's that's going on all the way over there. That doesn't affect me. whereas actually because of the the different attack types I've mentioned and and the psychological value that we've discussed um it makes them the perfect targets. So there's an even higher premium on what Lauren and and Caitlyn have discussed in terms of having those basic cyber security standards in place. Um minimum kind of requirements um and then really thinking about their their resilience in the longer term because um it's very much Iran's way of connecting and bringing home something that's far away to the American public that makes um American businesses um however big or small the perfect targets in this conflict. And so kind of reflecting on response, I' I'd pick out two things. The first is from an offensive perspective, this is an administration that really does put a premium on offensive cyber operations. They want the United States to have a more aggressive stance in cyerspace. They want to take the fight to their adversaries much more. And what I found interesting about this attack was um President Trump's response where he was quite quish uh sorry, he was quite quick to to quash any talk of this being Iran as the responsible actor behind these cyber attacks. um and he in fact uh tried to blame um democratic officials for for being responsible which was um you know pretty surprising and and they were very quick to refute that in turn but I think that in itself is a strategic move right so again if we're zooming out and we're thinking about what's going on more broadly with this conflict diplomatic negotiations are ongoing they're quite fragile they're quite fraught and so the way I read um President Trump's statement was uh almost an effort to to minimize um the the kind of risks or the threats posed by these particular attacks in order to preserve those wider diplomatic channels and keep negotiations going. The thing I would say about that is um we absolutely shouldn't take that at face value and think oh well that's it the US isn't going to to do anything in response to Iran. Um I think firstly doing defensive measures and and strengthening your defensive measures isn't itself a very important form of response um to adversaries. I think the second thing is I would very much assume that the United States will use offensive cyber capabilities to respond to Iran in private. Um, and it might not be something that they they talk about or they're transparent about, but I imagine that would be taking place behind closed doors. And then the last thing I'll point out is um if we look at the response of some of the um you know mun municipal officials in these attacks, um some of them did a really fantastic job. um in Minnesota in particular, they were very quick to revert to manual planning, thinking about um water reserves and how they could switch those instead so that public water supply wasn't actually disrupted or impacted. Um and I think that was a really fantastic example of cyber resilience in practice where you have those manual uh backup methods in place and you can turn to those quickly uh in order to minimize the impact of a particular cyber attack and and really withstand um a cyber attack. So I think it's a fantastic example of um a good response. >> Thank you. Just a really quick note to foot and this is a whole other conversation around this administration's response to um adversary cyber activities. your your anecdote about President Trump's response to Iran reminded me of a side of a conversation with a journalist that he had after the Trump she summit where someone asked him about uh China or like Beijing's um cyber activities and he was quick to deflect there as well and said something along the lines of you know we do it and they do it too. >> So I think there's a bigger there's a bigger story there when it comes to not wanting cyber operations from nation state actors to detract from other administration priorities. >> Interesting. Okay, unfortunately I have to start bringing us to a to a close now. So, the title of this episode now seems kind of obvious based on what you've all been saying, but I probably have to ask you anyway. So, did Iran attack US water systems? Lauren? >> Yes. >> Yes. Kayn, >> uh, according to US government agencies and at least earlier this year. Yes. >> Okay, Nikita. >> Highly likely. Yes. >> Yeah. Okay. So now then the more fun one. So is there a word or phrase that you that you would like to ban pundits from using when talking about anything we've been discussing today or or more broadly? Um let's go the other way around. Nikita, can I start with you? >> Sure. Um I'd like to ban the phrase cyber escalation. Um I've I've seen that thrown around a little bit in response to these attacks. I think it's a very unhelpful narrative. Um, there's actually something I'm I'm about to put out a short commentary on, which is, um, I don't think this is a it's helpful to read this as escalation. Um, it's also very difficult to determine what escalation looks like in cyerspace. And in this case, I think it is something opportunistic. There are also political reasons to to minimize these and and preserve wider uh, relationships. And um I think you know ultimately we're talking about psychological impact not not kind of um not necessarily physical or psychological in addition to physical and I think escalation just sucks the nuance out of those discussions. >> Interesting. Okay. Thank you Kaitlin. >> Yeah. Um one way that I've heard this phenomenon described is um Iran coming for people's tap. Is Iran coming for your taps um in your household taps? And I think that that's counterproductive. I think that this is a moment to bring attention to the importance of fortifying our public water utilities to threats of all types of to cyber attacks to infrastructure degragation, climate shocks, etc. Um so I think that that moment is very very important and I hope those things happen. Um to lead the public to think that Iran is targeting um individual household taps is again uh that that's counterproductive. >> Okay. Yeah. Lauren, >> I think I I want to ban not a word, but it just uh I want to ban talking about these attacks in isolation without looking at the broader context, which is obviously the opposite of what we've done today. But [laughter] yeah. >> Yes. Okay. Cuz I actually um there was a a piece of me that thought, are we doing exactly what we we shouldn't be doing by by playing this up and giving it too much attention? But I think you've actually done the opposite of that. So to summarize then what I've heard you say. So you've said firstly what actually happened. So at least seven states have been attacked maybe up to a dozen. Um hackers got into systems across the the country largely through the or I think through the internet. Um that resulted in boilwater notices, financial losses, and Caitlyn you highlighted it could be ongoing as well. We've had another one as as recently as 3 days ago. And I should say we recorded this on the 13th of August as well. Um so kind of why is it so vulnerable? Well, water is critical to absolutely everything. Uh, and it is also fundamentally vulnerable and I think you've said, you know, a lot of these utilities have small budgets, small staff, and it's a really fragmented system as well, which means it's very difficult to uh protect all of it. Um, and it's seen as lowhanging fruit to actors like Iran. So then, was it Iran? And I think the consensus seems to be very very likely and that uh Nikita you gave several reasons for that. This matches the behavioral signature of past Iranian attacks. There's a history of targeting water since at least 2013 and the technical piece as well. Targeting uh PLC's is something that they've done before and it also fits into the broader context. I think you've said yes, it's an opportunistic attack, but it's also a sort of strategic opportunistic attack uh because of that history of water and and uh targeting water. Caitlyn, you highlighted uh the different spates of attacks on water that we had in the war earlier on in the spring and then also in the summer with dissalination plants being hit. Um attacks attributed to both the US and and to Iran. Um, and then I think, uh, Nikita, you said it's it's not just, you know, it's it's partly about seeing what sticks. It's partly about having instant impact, but it's also about projecting power and the information warfare piece of this. It's a psychological thing, trying to bring the war and the consequences of the war home to Americans so they can feel it. So then we finished by talking about the response. And on the defensive side, um you would like to see um identifying specific uh regulations uh water security uh cyber cyber uh security requirements for the water sector. Um and there's some interesting legislation um including uh that uh tries to uh gather best practices and also funds some of these defenses. But Caitlyn, you said it's not just, you know, we we don't have to reinvent the wheel. uh there are some interesting and important pieces in place. It needs attention. It needs staffing and it needs funding. And then on the offensive side, kind of interestingly, although the Trump administration at large has focused quite a lot on building the offensive capabilities, President Trump himself has chosen to downplay these attacks uh and and not to link them directly to Iran. Maybe that's because of uh the state of uh diplomacy in the the war um where you know the 60-day so-called ceasefire is about to expire. Um and and maybe he wants to create more of an opening for diplomacy. Um but or you also said we should we shouldn't assume that there isn't a more private a quieter uh response from the US government. So um I think I think we've covered a lot. Uh that was um that was I think some real nuance to this conversation. Um you know some quite alarmist headlines but I think you've really helped us think through um you know what actually matters, what's new and what needs to be done really importantly. So I should say that um in the show notes we will link pieces from all three of you. Um you've been doing really great work on this and and so I'll make sure that the audience has access to that. Um a final plug as well for the audience. I keep saying this, but we have a survey out at the moment for uh about State of Play. So, if you do have thoughts that you'd like to share with us, we'd be really really grateful uh to hear what you'd like to see more of, what you'd like to change, what you'd like to hear less of. Um but I think for now, I'll say uh Caitlyn, Lauren, Nikita, thank you so much. It's such a pleasure. I am sure you're going to collaborate more and I'm very excited to see what you produce, but thanks for using this platform to share some of your analysis. Thank you so much. >> Thank you. Oh, thank you. >> Summary. >> Thanks for listening to State of Play. If you enjoyed this episode, subscribe to it wherever [music] you heard it. And you can find more analysis at www.csis.org/geopolitics. This podcast was produced by Sarah Baker. Until next time.