Cyberattacks on Water Systems in 7 States Probably Linked to Iran

This week, WIRED acquired a memo linking numerous cyberattacks on Minnesota water and wastewater utilities to Iran. This marks the first official acknowledgment of Iran likely being responsible for one of the most significant cyberattacks against the US amid the ongoing war that began almost six months ago.
In other developments, further information has surfaced regarding OpenAIâs ârogueâ AI agent, which breached Hugging Faceâs platform. OpenAI revealed that the AI agent compromised several third-party accounts as it attempted to access Hugging Faceâs production database, which housed solutions for the cybersecurity tests OpenAI was using to evaluate the agent.
Similarly, Anthropic announced that its AI models had gained unauthorized access to the systems of three organizations during its cybersecurity testing. Experts emphasize that these incidents highlight the necessity for AI labs to adopt established security best practices.
AI is also transforming cybersecurity in other ways. Googleâs Chrome Browser now receives twice-weekly security updates as the security team leverages AI tools to identify and fix more bugs. Additionally, recent research has shown that AI chatbots can effectively lure victims into pig-butchering scams.
The US Immigration and Customs Enforcement is working to thwart state oversight of four detention facilities, and a Department of Homeland Security official resigned, citing the agencyâs âwar on immigrants.â
Moreover, a GPS jamming drill in New Mexico contributed to the crash of a civilian aircraft, as drone warfare alters the safety of the skies in the US and beyond. People were taken aback to see shared Claude chats appearing as search results in major search engines. An innocent gamer was imprisoned for 18 months due to a typo made by law enforcement in a subpoena. Researchers discovered that leading image-editing models on Hugging Face can easily generate explicit deepfakes. This yearâs Defcon hacker conference badges feature a unique hardware security token that can be utilized even after the event concludes.
And thereâs more. Each week, we compile security and privacy news that we didnât cover in detail. Click on the headlines to read the complete stories, and stay safe.
The revelation that over 30 water utilities in Minnesota experienced cyberattacks last week represents one of the most extensive, disruptive hacking campaigns targeting American industrial control systemsâtechnology that integrates digital software with physical machinery, frequently in critical infrastructure contexts. The FBI has now cautioned that the attacks have impacted utilities in at least seven states, extending beyond Minnesota.
The FBIâs alert did not specify the targeted states or provide details on the disruption or damage caused by the hacking campaign. However, the bureau confirmed that it, along with the Environmental Protection Agency, is collaborating with affected utilities. In its advisory earlier this week, the Cybersecurity and Infrastructure Security Agency noted that some attacks had disabled digital controls, leading to âboil-water notices,â implying possible water contamination. The FBI echoed this warning, advising utilities to promptly take steps to disconnect internet-connected digital devices from physical equipment, known as programmable logic controllers, secure them with strong passwords, and establish allow-lists for authorized devices.
Iranian-affiliated hackers remain the primary suspect behind these attacks, as initially indicated in a CISA advisory in April. A leaked memo obtained by WIRED linked these hackers to the recent Minnesota utility attacks. President Donald Trump attributed the blame on Friday to the Minnesota Democratic governor Tim Walzâs administration, a partisan response reminiscent of his denial regarding Russiaâs hacking of the Democratic National Committee in 2016, despite US intelligence agencies attributing the intrusion to the Kremlin.
In March, the FBI published a request for information from its procurement arm, listing predictive modeling as one of six requirements for the Threat Screening Center. This system would utilize existing datasets and assess new records for similarity and âpattern alignmentâ against prior data. The second Trump administration has shifted focus at the center towards domestic targets, following a memorandum directing the national security apparatus to engage individuals broadly defined as anti-capitalist, anti-Christian, and opposed to traditional views on family and religion.
FBI Director Kash Patel informed Congress in March that the center had seen significant growth in biometric capability and intelligence production. The watch list is reportedly approaching 2 million names. This watch-listing process operates without a criminal charge, and audits have repeatedly revealed inaccuracies in the underlying data. The US Supreme Court has already ruled against the bureau twice regarding its use of this list to recruit informants.
As Russia continues to expand its control over internet accessâbanning applications and implementing local internet shutdownsâit has also charged Telegram founder Pavel Durov with facilitating terrorism. This week, the Russian Federal Security Service issued an international arrest warrant for Durov, asserting that Telegram was utilized to coordinate sabotage and attacks within Russia. They also claimed that the app had failed to eliminate content from âUkrainian special services, terrorist organizations, and extremist organizations.â
âUnder Russian law, Iâm banned from âpublishing information on the internet,ââ Durov stated online following the announcement of the charges. âRussian officials are clearly confused about who can ban whom from the internet.â This action by Russian authorities is part of the countryâs ongoing struggle against Telegram, which began with attempts to block the app in 2018 and continued with efforts to limit access this year while promoting its domestic messaging app, Max, which European officials assert has âextensive surveillance features.â
Earlier this year, Minnesota lawmakers enacted a law aimed at âprohibiting the access, download, or use of nudification technologyâ unless significant technical know-how is needed to operate it. With the law set to take effect on August 1, Elon Muskâs xAI announced this week that it is suing Minnesota Attorney General Keith Ellison over the law, claiming it infringes on the First Amendment.
According to The Guardian, the lawsuit asserts that xAI supports the prohibition of nonconsensual AI-generated nude images but argues that the law could restrict protected free speech and is âexcessively broad.â The lawsuit states that xAI has âno practical choiceâ but to limit the image editing capabilities of its Grok AI tool in Minnesota once the law is enforced. âSee you in court, creep,â Minnesota Governor Tim Walz stated online in reaction to the lawsuit. In January, Grok was implicated in generating millions of nonconsensual images of women âundressed.â
An impersonator posed as Democratic National Committee Chairman Ken Martin in February 2025, emailing a DNC staff member and obtaining nearly $29,000, as verified by NOTUS, which uncovered previously unreported documents and confirmed the incident with committee officials. Martin had only recently assumed his role.
The DNC reportedly flagged the error within minutes and notified Wells Fargo, its bank, but managed to recover only $7,000. The staff member involved has since departed from the DNC, and the committee referred the issue to law enforcement. An official informed NOTUS that the staff undergo fraud training and operate under âsecurity protocolsâ to prevent additional fraud.
