Foreign Hackers Hit America's Water. Trump Blamed a Democratic Governor. CISA Is Cutting Its Experts' Pay.
"We know these changes may result in financial hardship for some," Acting Director Nick Andersen wrote to staff, weeks after DHS told Congress the agency needs 600 more people.
On Friday morning, at a televised Cabinet meeting at Camp David, the president of the United States was asked about a coordinated cyberattack that had, days earlier, reached inside the control systems of more than 30 Minnesota water utilities.
By the time he spoke, it was no longer a Minnesota story. His own agencies had spent the week telling water operators nationwide to disconnect their industrial controllers from the public internet. The FBI and the EPA had issued a joint advisory the day before, reporting that water and wastewater utilities in at least seven states had come to the bureau with incidents, some of which degraded water operations. The Cybersecurity and Infrastructure Security Agency had told the entire sector, in an alert issued Thursday, that attackers were locking operators out of their own equipment and were targeting water entities of all sizes. American intelligence agencies have preliminarily assessed that Tehran is likely behind this campaign in the fifth month of the U.S. war against Iran.
Trump blamed Minnesota, calling the state “grossly incompetent” and the governor corrupt. He then veered way past dismissal:
“You know who’s behind it? Minnesota. Because they’re grossly incompetent.
I think the governor’s behind it.
I don’t think there was an Iranian cyberattack.”
While the president was assigning blame on television, his own cyber agency was rewriting the rules that determine whether its remaining experts stay.
An internal FAQ posted to CISA's human capital intranet, obtained by Hacking, but Legal, sets new eligibility criteria for the Cybersecurity Retention Incentive, the supplement worth 20 to 25 percent of salary that keeps certified specialists from taking private-sector offers. To qualify next fiscal year, an employee must now hold an "Exceeds Expectations" or higher rating on their annual performance review. Nothing in the federal audit being used to justify the change asked for that. A CISA employee tells me the new rules are expected to cost roughly a third of the agency its incentive. In an all-staff email announcing the change, Acting Director Nick Andersen told employees that "we know these changes may result in financial hardship for some," and pointed them toward financial education resources.
That is the workforce whose absence the president spent Friday blaming on a governor.
I have spent a significant portion of my career on the detection and response side of incidents like this one. I was promoted repeatedly at Mandiant (acquired by Google), a firm carrying expert credentials to handle intrusions for major organizations having the worst week of their institutional lives. I later served as Director of Incident Response at Intel Security and McAfee. I have personally authored containment plans and made 3 a.m. calls to argue about whether pulling a system offline costs less than leaving it up.
The president’s remarks aren’t just partisan noise.
At best, they represent a category error that inverts how attribution works, highlight a fundamental misunderstanding of how cyber warfare works, and make the next intrusion more likely to land. At worst, they showcase that this administration intends to leave the country vulnerable to a belligerent nation they started an illegal war against. Instead of taking responsibility and vowing to engage in retribution during a time of active hostilities, the chief executive has just used the attacks against our nation as political leverage against a fellow American — the sitting governor of a blue state, one who just so happens to have run against him in the last election.
The July 26 Intrusions
Between the night of Sunday, July 26, and Monday, July 27, someone moved through the operational technology of Minnesota’s community water systems. Minnesota IT Services called it a coordinated cyberattack against more than 30 systems; John Israel, the state’s chief information security officer, later put the figure at 36.
The targets were programmable logic controllers (the small industrial computers that physically open valves and start pumps) and the human-machine interfaces that sit in front of them. Federal investigators have since named Rockwell Automation MicroLogix 1100 and 1400 series controllers specifically, and the technique they describe has no finesse in it whatsoever. You reach an internet-facing device, change its IP address and its password, and the people paid to run that plant lose the ability to see it or touch it.
In Braham, a town of about 1,700 that advertises itself as the homemade pie capital of Minnesota, public works crews noticed the well feeding the water tower misbehaving. They isolated the affected system, switched to a backup and restarted the plant in roughly 90 minutes. Plymouth lost cellular communications to two water towers and several wastewater lift stations and kept running by hand. So did South St. Paul. Maple Plain declared a local state of emergency.
Read that against the sector’s own guidance and it stops looking like failure. WaterISAC, the water sector’s information sharing and analysis center, publishes a document called 12 Cybersecurity Fundamentals for Water and Wastewater Utilities. Fundamental 1 is incident planning, and it instructs utilities to write emergency operating procedures for running the industrial process by hand, to be ready to island the control network if malware renders controllers untrustworthy, and to rehearse manual mode routinely so the muscle memory exists under stress.
Braham and Plymouth and South St. Paul did not improvise their way out of trouble on July 27. They ran the playbook their own sector had published for them, and it held.
Nobody in Minnesota lost water. Nobody was told to boil it. Neither fact was luck, and neither means the attack was trivial. A memo circulated by the Minnesota Bureau of Criminal Apprehension and obtained by CNN assessed that the intruders were probably trying to cause a loss of system pressure, which is the precondition for contamination getting into the pipes. That is the part worth sitting with. The goal was not to embarrass a city council. The goal was to make the water unsafe, and what stood in the way was a shift operator who noticed something wrong before the alarm told him.
The historical record explains why this one is different. Dragos, the industrial-security firm that tracks this sector more closely than anyone, counted 27 publicly disclosed cyber events in the U.S. water and wastewater sector across the eighteen years from 2006 through 2023. Of those 27, only three were verified as having impacted industrial processes and operations: an insider at a California canal authority in 2007, an insider at a Kansas rural water district in 2019, and the 2021 Oldsmar, Fla., intrusion in which someone tried to change a sodium hydroxide setpoint. Two of the three were disgruntled employees. None was a foreign state.
Then the curve bent. Late 2023 brought Aliquippa, and a county in Ireland left without running water for days. In April 2024 a group calling itself the Cyber Army of Russia posted video of itself inside the controls of a wastewater plant in Tipton, Indiana. That September, Arkansas City, Kansas dropped to manual operations after a weekend intrusion. Three weeks after that, American Water, the largest water utility in the country, pulled systems offline and ran parts of its operation by hand. Dragos now tracks the Iranian-linked crew behind the Unitronics campaign as BAUXITE and counts five separate campaigns from it since late 2023.
So Minnesota is not an anomaly, and I am not going to pretend it came out of a clear sky. It is the steepest point yet on a curve that started bending years ago, during which time the federal government took apart the agency built to help towns like Braham.
The Punishment of Disclosure
By Thursday, a full day before the Cabinet meeting, the FBI and the EPA had told the public this was a multi-state campaign. Utilities in at least seven states had reported incidents since July 26. Federal authorities described losses of monitoring and control at critical infrastructure sites, and effects that went well past a dark screen: pressure loss and flooding. CISA said the activity had produced boil-water notices and sustained manual operation.
None of those boil-water notices were in Minnesota. The federal agencies did not name the affected states, and as of this writing they still haven’t. So exactly one name is attached to this campaign in public, and it just so happens to belong to the state whose governor Trump has spent years attacking.
Geography has nothing to do with that. The single name is an artifact of how intrusions become visible in the first place, and this is the part of the story I would most want a general reader to understand.
In two decades of this work, the most reliable predictor of which organization ends up in the newspaper has never been which one was breached worst. It is which one was looking. Detection requires instrumentation, staff, and a willingness to say so out loud once you find something. A utility with no telemetry files no report, because it never learns it has anything to report. The exception is ransomware, where the attacker announces the victim for you. Nobody announced this one. The victim you can name is almost never the victim who got hit hardest.
Minnesota’s own chief information security officer said as much to the New York Times, as Axios and others relayed: Minnesota was one of the early detectors, and the same activity had likely been running in other states across the country. Minnesota IT Services did not respond to questions Friday evening seeking to directly confirm the state’s early detection of the campaign, or detailing the level of federal assistance the state received during the crisis.
So the state that caught this early, escalated it, stood up a statewide response, worked it alongside four federal agencies, and told its residents the truth inside forty-eight hours is the one Trump singled out on national television as uniquely incompetent. The states still unnamed, some of them perhaps still boiling their water, went unmentioned, because nobody has published who they are and the president cannot attack a blank space on a map.
Punish disclosure and you get less disclosure. The sector has been complaining about that dynamic for years, in its own documents. In WaterISAC’s December 2024 guidance, Jennifer Lyn Walker, its director of infrastructure cyber defense, wrote a note to members under the heading that everyone wants to know and few are willing to share, urging utilities to “stop keeping your cyber incidents so close to the vest until a reporter calls.” Her argument was that the sector’s blind spots persist because victims stay quiet.
Minnesota did the thing the sector has been begging its members to do. Every utility manager in the country watched what it got them.
The Attribution Trap
Two entirely different activities go by the name “attribution,” and they share almost nothing but a word. Collapsing them is how you get Friday.
The first happens in a room with a whiteboard and too much coffee. It is incident response, and its questions are narrow. What did the adversary touch? How did they get in? Are they still here? What has to change so they cannot come back through the same door? NIST’s guidance, the framework most of us build our programs against, organizes the work around detection, response and recovery.
Nowhere in that sequence does the adversary’s nationality appear, because for eviction and hardening it is close to irrelevant. Tradecraft is everything: which port, which credential, which firmware, which undocumented cellular modem some integrator installed in 2019 and never told anyone about. But if you told me tomorrow that the Minnesota intrusions were the work of Iran’s Islamic Revolutionary Guard Corps, a criminal crew, a contractor with a grudge, or a bored nineteen-year-old, my plan would not change by a single line.
Pull the controllers off the public internet. Kill the default credentials. Verify the ladder logic against a known-good copy, because a project file can be modified to look correct while overriding safety instructions underneath. Rehearse manual operation. Containment, eradication, remediation, in that order, under every attribution hypothesis anyone has floated. Hold that work until the geopolitics settle and you have not paused remediation; you have handed the intruder the weekend.
The second activity happens in a different building entirely. It is a political and legal act performed by governments, and naming a state as responsible for a cyber operation is the predicate for countermeasures, for sanctions, for coalition statements, for anything the international system recognizes as a lawful response. It moves slowly on purpose, withheld until the evidence will survive contact with allies, adversaries, and lawyers.
It is also getting harder, not easier. Dragos’s most recent annual review describes threat groups that have organized themselves into a division of labor: one crew specializes in breaking into internet-facing systems and then hands that access to another crew that does the work inside the plant. The people who opened the door are not necessarily the people who touched the pumps. Anyone demanding a country’s name in week one is asking for something the evidence may not support in month six.
Which is why Minnesota’s own officials said what they said. They were not attributing the activity to a specific threat actor, and federal partners were better positioned to make that call. Professional caution is supposed to sound that unsatisfying. It was also correct, and it came from the people Trump called grossly incompetent.
He did not exercise that caution, and caution here would have meant silence, or some version of what his own agencies were already saying in writing. Instead he rejected the assessment his own government was still building and substituted a different one, aimed at an American governor, resting on nothing at all.
The Anatomy of Negligence
Let me make the strongest version of the other side of this argument. Were some of these water systems poorly defended? Almost certainly.
Internet-exposed controllers with factory-default passwords are a failure mode with its own advisory history. The IRGC-linked persona CyberAv3ngers compromised at least 75 Unitronics controllers across four countries in late 2023 using that same weakness, including at the Municipal Water Authority of Aliquippa, Pa. CISA has warned that malicious code from that campaign still sits on some devices today. In April, six federal agencies — the FBI, CISA, the NSA, the EPA, the Department of Energy, and Cyber Command — jointly warned that Iranian-affiliated actors were exploiting internet-facing PLCs across American critical infrastructure, and updated that advisory on July 22, four days before Minnesota was hit.
The sector does have a discipline problem, and pretending otherwise would be dishonest. But the numbers make it a structural problem rather than a Minnesota problem.
Dragos has found that roughly 60 percent of high-severity vulnerabilities in the water sector’s operational technology sit in controller assets, and that internet-accessible ICS networks turned up in 53 percent of its own service engagements. An earlier CISA scan of 44 water entities found more than a third running risky remote-access services and about one in six running unsupported Windows on internet-facing assets. Exposed control gear is close to standard equipment in this business, which is why attackers were able to go after it in seven states at once instead of one.
The specific blind spot exploited here was flagged in writing well in advance. WaterISAC’s December 2024 guidance told utilities to hunt for interconnections they had forgotten about, and asked pointedly whether a vendor had installed a cellular modem for maintenance that was serving as an undocumented back door. Nineteen months later, CISA’s July 30 alert warned that this targeting includes cellular modems installed by operators, vendors, or integrators that may never have been inventoried, and Plymouth’s disruption ran straight through that path. The sector knew, and had known for years, but knowledge is not the same thing as a budget line. Cybersecurity can be expensive.
Negligence and culpability are different things, and conflating them is how you end up blaming a town for being burgled. Whoever left the window unlatched did not commit the burglary. In cyber operations that line is drawn in law as well as in ethics: responsibility for an intrusion attaches to whoever conducted it, and a state does not shed it by working through proxies or personas.
There is a second problem with the negligence charge as delivered. It was pointed at the wrong person, and now at the wrong scale.
A failure that shows up in one state on one weekend is a story about that state. A failure that shows up in seven states in five days, against the same class of device, using the same technique, is a story about a sector. You cannot hold a governor responsible for a national pattern in municipally owned infrastructure he has no legal power to regulate. Whatever went wrong here went wrong in jurisdictions Trump has not criticized, because nobody has told him which ones they are.
There is no federal cybersecurity mandate for American drinking water. Roughly 50,000 community water systems operate in this country, most of them municipal, many serving a few thousand people with no dedicated security staff. The EPA leads federal water-sector cyber policy and lacks explicit statutory authority to require anything of them. The one serious attempt to change that, a March 2023 memorandum directing states to evaluate cybersecurity during sanitary surveys, was challenged in court by Missouri, Arkansas, and Iowa, joined by two national water associations. The Eighth Circuit stayed it. The agency withdrew it that October.
So a governor of Minnesota cannot compel a municipal utility in Braham to re-architect its remote access, and has no line item that would pay for it if he could. The accountability structure Trump invoked on Friday does not exist, in significant part because his own party’s attorneys general went to court to make sure it never would.
The Federal Divestment
If the argument is that somebody failed to prepare American water systems for an Iranian cyber campaign during a war with Iran, then the ledger deserves to be read all the way to the bottom.
A third of CISA’s workforce is already gone. The administration has proposed cutting more than $700 million from the agency’s next budget, a figure Senator Mark Warner called a dangerous underestimation of the threats facing the country in a June letter that also documented five of ten regional directors serving in an acting capacity. There has been no Senate-confirmed director since January 2025. Federal funding for the threat-sharing hub that served some 18,000 state and local entities, including small utilities, ended last September; it now runs on paid memberships that many towns simply did not buy.
In May, the GAO told Congress that these reductions may limit the federal government’s ability to support water and wastewater systems. That warning is ten weeks old. The attack is five days old.
None of this is new information, and none of it is a surprise to anyone who has been paying attention. I wrote about the dismantling in March 2025, when the firings were still in the low hundreds and the agency was being told to stop tracking Russian threats, and I updated it the following day as more came out. The reasoning behind the demolition was never operational. CISA had been recast on the right as a censorship shop, a story I have traced before and which bears almost no resemblance to what the agency actually did.
Set 2,324 filled positions against 150,000 public water systems and the arithmetic turns bleak fast. Even if every one of those employees, across sixteen critical infrastructure sectors and including administrative and emergency-communications staff, were reassigned tomorrow to drinking water and nothing else, you would have one federal body for every 21 community systems. No such reassignment exists or has ever been proposed. Trump treated that arithmetic as sufficient on Friday, and a governor as the reason it isn’t.
Walz made his own version of this point, telling reporters that the cuts had taken an axe to CISA and left the country exposed. He is right, and you do not have to take his word for it. Every figure in this section comes from the administration’s own budget request, an inspector general, a Senate letter the agency has not disputed, and the Government Accountability Office.
The Phantom Rebuild
Here is where the official story and the internal one stop matching.
The public version is recovery. Homeland Security Secretary Markwayne Mullin told a House panel in late June that CISA needs about 600 new people and is ready to rebound once a confirmed director arrives. Acting Director Nick Andersen has approved hundreds of mission-critical hires and extended roughly 200 job offers. Republicans who spent last year voting to defund the agency are now, per Politico, scrambling to rescue it, spooked by AI-enabled attacks and by their own midterms. This week the administration announced it will rebuild the election-security operation it gutted, with under 100 days to go before Election Day.
That is the story being told to Congress and to reporters. It is not the story inside the building.

A CISA employee, who spoke on condition of anonymity because they are not authorized to discuss internal personnel matters and fear retaliation, first described the change to me. The document behind it sits on the agency’s own human capital intranet, where any employee can read it.
The program is the Cybersecurity Retention Incentive, worth 10 percent of base salary for qualifying positions and 20 or 25 percent for staff who hold certifications on an approved list. It exists because those certifications are expensive to earn and maintain, and because the private sector will always outbid the federal government for the people who hold them.
Last September, the DHS Inspector General found that CISA had mismanaged the program, spending $138 million between 2020 and 2024 without properly documenting who qualified, and paying $1.41 million in unallowed back payments to 348 people. The audit made eight recommendations. CISA concurred with all of them. Most were due to be implemented by July 2026.
At the time, CISA staffers warned reporters that the audit lacked context and could hand the administration a pretext to gut a program the workforce depended on. That is a matter of public record from September. The FAQ shows what arrived instead.
To be fair to the agency, part of the rewrite is exactly what the auditors asked for. The Inspector General found that CISA had quietly dropped the share of time an employee must spend on cyber work from 51 percent to 30 percent, let that policy expire, and then kept operating at the lower number anyway. The new rules restore the 51 percent threshold. That is a legitimate fix to a documented problem.
The rest is not in the audit at all.
Under the new criteria, an employee must have received an “Exceeds Expectations” or higher rating on their annual performance review to keep the incentive. They must not have been demoted, reprimanded, or suspended in the previous twelve months. They must have held an eligible position for the previous 90 days and worked at CISA continuously for a year. Employees hired through the Cyber Talent Management System, the program built specifically to recruit private-sector security talent into government, are excluded from the incentive entirely.
Nowhere among the Inspector General’s eight recommendations is there a performance-rating threshold. The auditors asked CISA to define mission-critical roles, document eligibility, fix its recordkeeping, and recover improper payments. Tying a retention supplement to annual review scores was a choice the agency made on its own.
“The OIG report did not say remove cyber pay for all employees who didn’t get a 3.5 or higher on their performance evals,” the employee said. “The call is coming from inside the house.”
The DHS Office of Inspector General did not respond to a request for comment by deadline on Friday evening asking whether its audit recommended tying the retention incentive to annual performance ratings.
The FAQ also contains a disclosure that has not been reported. CISA writes that it recognizes “a complete sunset of the CRI Program, as previously planned, would exacerbate critical hiring gaps across its cybersecurity workforce.” The plan of record, in other words, was to end the retention program outright. What the workforce is being handed now is the version that survived.
The employee who spoke to me received a middle-of-the-road review last cycle, in a period when managers had been pressed to rate more conservatively and hand out fewer top marks. Under the new rules, that rating disqualifies them. They are losing 25 percent of their pay, a reduction that leaves their salary uncompetitive with the private sector.
CISA anticipated the objection and wrote it down. One of the questions in its own FAQ, posed and answered by the agency, is why it would make changes costing employees the incentive “when we already have a large number of vacancies.” Andersen’s email goes further, telling staff outright that “we know these changes may result in financial hardship for some,” and directing them to financial education resources.
No internal modeling is required to see where that leads. Certified specialists losing a quarter of their pay, in a market where every private employer is hiring, will start taking calls. Each one who leaves widens the vacancy gap the agency says these changes exist to address, at an organization already down a third of its people.
The employee estimates that roughly one third of the agency will be affected, and believes the money may not return until fiscal 2028.
There is a second problem arriving with the new fiscal year. Because eligibility now depends on a position description showing 51 percent or more cyber work, employees whose descriptions are stale or were filled out with the wrong percentage will fail the test on paper. CISA seems to know this. Its FAQ poses that exact question — what happens when a position description does not accurately reflect the time an employee spends on cyber duties — and answers it in a single sentence from its human capital office: “OCHCO is actively reviewing position descriptions to make updates as necessary.” No timeline. No recourse. Applications open Monday, August 3, and close September 4.
Nobody’s actual duties will have changed. The forms describing those duties will simply be wrong.

I asked the employee what it looks like from the inside when the same administration cuts their pay and then blames a governor for an attack the agency was formed to help prevent.
“It’s intentional,” they said.
The Inspector General’s stated worry, in the very report now being invoked, was that mismanagement of this program “undermined morale among qualified cybersecurity professionals and jeopardized CISA’s ability to retain critical talent.” The remedy is producing the harm the audit warned about.
So is this incompetence, or is it deliberate? I have argued elsewhere that this is the wrong question, and that it is the wrong question by design. Singh’s Law: any sufficiently advanced incompetence is indistinguishable from sabotage. Intent lives inside somebody’s head and can be litigated indefinitely. Wreckage shows up in staffing charts and turnover numbers and can be audited by the quarter. Past a certain threshold the two stop separating, and reaching for the distinction mostly serves whoever benefits from the inquiry ending right there.
This entire piece is an argument that chasing attribution is the wrong instinct in the opening week of an incident. The same discipline applies to the people who cut the budget. Judge the wreckage: a third of the workforce gone, the retention program for whoever is left being cut in the middle of an active campaign against American water systems, and a Cabinet secretary telling Congress the agency is actually on a rebound.
The employee I spoke with put it more plainly.
“Morale is low and we haven’t been given support or reasons to stay. It’s fucked up.”
News of these pay cuts hasn’t reached the public before now. It does not contradict what CNN reported this week from a closed-door congressional briefing, in which a CISA official said the agency was too depleted to deliver even its normal election-security support before the midterms. Both accounts describe the same institution: one being publicly restored and privately hollowed.
CISA's Office of Public Affairs and the Department of Homeland Security received a detailed request for comment on Friday evening, listing the documents and criteria described above. Neither responded by the publication deadline. Any response will be added here in full.
The False Flag Distraction
Investigators have said they are weighing whether someone impersonated Iranian tradecraft to inflame an already burning conflict. Former intelligence officials told the New York Times they consider that unlikely, and the operational indicators, disruption rather than profit and no ransom demand, point toward a state actor. But it remains a live hypothesis, and taking it seriously is a mark of competence rather than weakness.
The hypothesis argues in one direction only. A credible false-flag risk calls for more rigor before public attribution, longer forensic patience, tighter coordination with the allies who will be asked to co-sign whatever we eventually say. It argues for nothing whatsoever in the direction of naming an alternative culprit without evidence, and least of all in the direction of naming an American state.
It is also worth remembering that this was foreseeable, and foreseen. When the administration stood down cyber operations against Russia in early 2025 and began stripping out the people who did attribution work, the warning from those of us watching was specific. Degrade a country’s ability to attribute attacks and you hand every adversary the option of hiding behind someone else’s fingerprints, while corroding public confidence in the attributions that do get made. That was seventeen months ago. We are living in the world it described, with one bitter revision: the distrust is not being manufactured by a foreign service. It is coming from the podium.
Consider what an adversary learned watching Friday. Strike American water systems during a shooting war, and the American president will decline to name you, then spend his airtime on a domestic rival instead. The entire apparatus of deterrence signaling gets switched off on your behalf, free of charge.
Public attribution exists to impose cost. Refusing to use it while the intrusions continue in at least seven states tells every actor probing our infrastructure that the cost of hitting us is pretty much zero.
What Defense Actually Looks Like
The real work of protecting American drinking water this week did not happen on a stage at Camp David, and it will not happen on cable news. It happened in equipment rooms in quintessential American towns most of us could not find on a map, and it looks like this.
It looks like someone pulling a programmable logic controller off the public internet, where it should never have been reachable in the first place. It looks like a public works director building an honest inventory of every remote-access path into the plant, including the cellular modem a vendor installed years ago and nobody wrote down. It looks like replacing default passwords that shipped from the factory, putting remote access behind multifactor authentication, and checking the logic running on a controller against a known-good copy, because a malicious change can be made to look correct on screen while quietly overriding a safety instruction underneath.
Most of all, it looks like the thing Braham did on July 27: knowing how to run the plant by hand, because somebody had written the procedure down and made the crew practice it.
And if the intent of this campaign was to cause a loss of pressure, then the durable defense is engineering, not software. WaterISAC’s guidance on independent cyber-physical safety systems is explicit about the answer: a control the compromised computer cannot reach. Pressure switches hardwired to pump controllers. A shutdown interlock wired directly between a chemical analyzer and the metering pump it governs. An alarm that never travels through the device an attacker owns. A safety function living inside the same box as the process logic falls the moment that box is taken.
Not one item on that list requires knowing whether the person on the other end was in Tehran.
All of it requires money, staff, and time, which is what your town council, your state legislature, and your congressional delegation actually control. If you want a question to ask them this month, it is not who did it. It is whether the utility that serves your house has done those things, when it last practiced running without its computers, and who is paying for the work.
Then there is the part that requires courage rather than budget. Call the FBI. Call CISA. Report it, even after watching what happened to the people who did. Minnesota is being pilloried this week for the exact behavior that made the rest of the country safer: it looked, it found something, and it said so inside forty-eight hours. That disclosure is the only reason utilities in six other states got a federal warning at all.
This was a serious act against American civilians in at least seven states committed by someone who has not yet been named during a war this administration started. The people who kept the taps running were public works crews and state security teams doing their jobs under fire, while the federal experts who would normally have backed them up were being told their pay was about to be cut.
The states we can name were told on national television that they were incompetent, and that their governor did it. Those still unnamed went unmentioned; nobody has published who they are, and the president cannot attack a blank space on a map.
Attribution is a tool. Used well, it builds coalitions, imposes costs on adversaries, and tells defenders what is coming for them next. Used the way Trump did on Friday, it is a cudgel, swung against Americans to the obvious benefit of the people who attacked them.
If you work at CISA, a water utility, etc. and you have something to add: I protect my sources. jackie @ hackingbutlegal.com.
The author is an information security practitioner, formerly of Mandiant and Director of Incident Response at Intel Security and McAfee.

