Recipe for Disaster: The Water is Boiling

Share
Recipe for Disaster: The Water is Boiling
Photo by Jason Richard / Unsplash

This post was authored by Jill Fields and originally published by Justice Connection on August 18, 2026.

In late July and August, malicious cyber actors focused on disrupting U.S. water and wastewater infrastructure. These cyber actors exploited vulnerable, internet-exposed industrial control systems, namely programmable logic controllers. They tampered with device configurations instead of physical destruction. The attacks centered on locking out operators, changing settings, and degrading automated processes to force manual intervention. The Iranian government is widely believed to be responsible for these attacks.

These cyberattacks were predictable – and this administration’s fumbles left us dangerously unprepared. The culmination of personnel losses, program eliminations, and willful ignorance by the Trump administration almost certainly created a recipe for disaster where Iranian cyber-hackers have adapted, infiltrated, and attacked U.S. critical infrastructure. This assessment is made with high confidence based on historical information, expert interviews, Office of Personnel Management data, and various news sources.

The U.S. Intelligence Community has long warned of Iran’s cyber capabilities. Former Deputy Assistant Director of FBI Cyber Division and current senior vice president at Halycon, Cynthia Kaiser, told PBS News Hour this month that she would be surprised to learn that the attacks were not conducted by Iran. Iran has the geopolitical motive, the capability to carry out these attacks, and a history of doing so. Beth Sanner, former Trump presidential intelligence briefer, noted when fighting an asymmetric battle with a smaller, weaker opponent like Iran, they become creative and think like insurgents.

Iran has a history of exercising its cyber capabilities against the United States and U.S. related targets. (See Figure 1, Iran Hacking Timeline.) Whether disrupting U.S. banks or hacking the FBI Director’s personal email, Iranian cyber groups have shown they will make the most of any opportunity.

How Could This Happen?

Step 1: Cut One-third of CISA employees

Since Trump’s second inauguration on January 20, 2025, the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) has lost one-third of its workforce. As of October 2025, the Trump administration sought to shrink CISA’s workforce through layoffs and orders to take new jobs elsewhere or leave the government. DHS ordered many CISA employees to report to other government agencies, including Immigration and Customs Enforcement and Customs and Border Protection. The administration specifically focused on cuts in the Stakeholder Engagement Division and the Integrated Operations Division. Both divisions work closely with local, state, and private partners either through managing relationships or providing services to partner organizations.

The FBI worked closely with partners at CISA, especially our partners in the regional offices. In the field, FBI agents partnered with CISA for site visits to state, local, and privately managed critical infrastructure. These visits were crucial to supporting partner engagement and providing local points-of-contact for industry partners to request assistance or report security concerns, including cyber intrusions. The FBI also supported CISA through the InfraGard program, a partnership between the FBI and members of the private sector for the protection of U.S. critical infrastructure. Through Infragard, the FBI shares threat intelligence bulletins and alerts, provides training, and creates educational programs.

Many of CISA’s regional advisors were also pushed out. These regional advisors spent years building relationships with state, local, and private sector partners. Without these points of contact, state, local, and private sector partners don’t know who to contact, meaning information sharing is delayed or does not happen at all. Many industry partners describe the relationship as broken, citing unanswered requests for assistance and serious doubts of CISA’s current capabilities. According to CyberScoop, one source reported that “Organizations that previously turned to CISA for help now seek alternatives, like industry alliances, outside consultants or government-to-government partnerships.” Another source said, “Not only is the White House hostile to CISA, but cybersecurity isn’t a priority for them.” (See Redline.)

The personnel loss was felt deeply across CISA, even in sections that were not specifically targeted with layoffs.In February 2026, then-executive assistant director Nick Andersen held a Cybersecurity Division town hall to inform employees of shifting priorities. Andersen said many programs would be eliminated to take on other priorities, and employees would have to do “a lot more work with a lot less people.”

Step 2: Chop Subject-Matter Expertise

Shortly before the United States launched attacks on Iran, FBI Director Kash Patel fired approximately a dozen agents and staff members from CI-12, a counterintelligence squad at FBI’s Washington Field Office that monitored threats from Iran. These firings amount to throwing away decades of subject-matter expertise on a geopolitical rival described by the intelligence community as “adaptable and opportunistic.” Included among those who were fired was a section chief in the FBI’s Counterintelligence Division who handled espionage threats from the Iranian government and its proxies. Christopher O’Leary, former FBI agent and MS NOW national security contributor, called these firings “the equivalent of institutional decapitation” that dangerously exposes and leaves the country “vulnerable to sophisticated adversaries.”

The terminations came so swiftly that agents likely did not have time to conduct a proper hand-off of sources. This means the FBI is likely not receiving the real-time reporting and information from confidential sources that the U.S. Intelligence Community has come to rely on. The expertise and solid relationships built with confidential sources cannot be replaced by new agents. One source told CBS News these terminations were “devastating to the FBI’s Iran Program.”

Aside from the loss of FBI special agents, the FBI has lost many career intelligence analysts. According to OPM data, from January 1, 2025, to January 31, 2026, 232 intelligence analysts, with an average of 19.6 years of government experience, left the FBI. Two hundred and thirty-two might not sound like very many compared to the over 1,400 special agents who left, but the FBI only has around 3,000 intelligence analysts. Congress authorized the FBI to have that number of analysts after 9/11, and they have not increased that number since. These analysts were adept at analyzing threat variables to provide real-time actionable intelligence to decisionmakers and timely warnings to government partners and the public. The subject matter expertise and relationships with government partners those analysts had cannot be replaced by new hires.

Step 3: Dissolve CIPAC and Threat-Information Sharing

On March 7, 2025, DHS disbanded the Critical Infrastructure Partnership Advisory Council (CIPAC). CIPAC and the Cybersecurity Information Sharing Act of 2015 (CISA 2015) provided the legal framework to facilitate cybersecurity, along with threat-information sharing and communications between the public and private sectors. Both CISA and FBI were part of CIPAC. According to industry leaders, while the government is a less reliable partner because of federal cuts, reorganizations, and other disruptions, the elimination of CIPAC is “disastrous” and the “most seismic disruption.”

The personnel losses, cancellation of CIPAC, and reprioritizations not only put CISA at a disadvantage, but also the Sector Risk Management Agencies (SRMAs), other government agencies, and critical infrastructure operators. SRMAs are the federal departments or agencies designated within the U.S. government to lead security, resilience, and risk mitigation programs for the 16 critical infrastructure sectors. Kelly Murray, a former Assistant Director for CISA’s Office of Chemical Security, stated “Without [CIPAC and CISA 2015], sector owners and operators and government alike are unable to reap the full benefits of public-private coordination. . .infrastructure protection depends on sustained, trust-based, cross-sector public–private partnership.”

Meetings with infrastructure leaders have been cancelled, longtime points of contact have been removed and not replaced, and CISA leaders stopped attending industry events and coordination programs. In early March 2026, the Trump administration reportedly blocked the dissemination of a DHS/FBI Intelligence Bulletin warning state and local law enforcement of a heightened threat environment in the wake of the war with Iran. These bulletins and alerts are critical for state, local, and private sector partners and for the safety of the American people. The information is used to inform and prepare communities, targeted groups, and individuals on real threats. In the words of Lauren C. Anderson, former FBI executive: “the U.S. government should not withhold credible threat information from the public.”

While the Infragard program continues to operate as an independent threat-sharing network, the dissolution of CIPAC stripped the vital legal and confidentiality frameworks needed to protect private industry-government collaboration. Trust in the government to be able to effectively combat cybersecurity threats has effectively diminished if not completely disappeared, leaving U.S. critical infrastructure in a debilitating, vulnerable state.

The United States has approximately 150,000 public water systems. Most water systems are small and have very few cybersecurity measures. Utility companies, especially small and medium-sized companies, relied on many of the free services CISA once provided under CIPAC, such as vulnerability scans, table-top exercises, and security briefings. Without these resources, utility companies must pay large fees to private firms for the same information. Small and medium utility companies already work within small budgets, and they cannot afford to pay for this information.

Kaiser shared with PBS News Hour that she was most worried about the water sector because of the lack of funding and IT personnel needed. She reiterated that small municipalities’ lack of resources leaves them vulnerable to attacks. While the support CISA brought to these small municipalities was important, Kaiser said it was critical that we “renew the funding for state and local cybersecurity grants that all of these municipalities are dependent on to be able to have the right kind of cybersecurity.”

Step 4: Stir in a Proven Cyber-Capable Adversary

On February 28, 2026, President Trump directed the U.S. military to launch Operation Epic Fury, a major military campaign coordinated with Israel against Iran, a proven cyber-capable adversary.

Since then, Handala, a hacking group operating under Iran’s Ministry of Intelligence and Security (MOIS), has taken credit for multiple cyberattacks against the United States and U.S.-related interests, including the data-wiping attack against Stryker Corporation, a medical technology company, and the hacking of FBI Director Kash Patel’s personal email. In June, Handala breached California water systems. Handala asserted that its objective was not to disrupt water service but framed the intrusion as a warning to the White House to stop U.S. military strikes on Iranian water reservoirs, which had already cut drinking water access during a heat wave for 20,000 residents.

Not only does Iran have cyber capabilities, it is a strategic adversary that takes advantage of U.S. policy changes. In 2023, an Islamic Revolutionary Guard Corps (IRGC) affiliated group hacked into a small Pennsylvania water facility just one month after the EPA rescinded strengthened cybersecurity guidelines for water and wastewater systems following a lawsuit by Republican-led states and groups. The IRGC’s “ability to blend proxy operations, cyber activity, covert logistics, and transnational repression creates a multidimensional threat environment that challenges traditional security frameworks,” according to Homeland Security Today.

So far this year, Iran is doing what it does best: exercising controlled escalation and asymmetric retaliation. The controlled escalation of the hacks into U.S. water systems from June to August show an adversary testing the United States’ threshold for attack. One expert told the New York Times, “The campaign felt a lot like pre-attack staging, not the attack itself. The level of access is sufficient for significantly more harm than has been seen.” Others may perceive it as a warning shot.

Step 5: Hope for the Best

On August 4, 2026, Nick Andersen, now the Acting Director of CISA, stated CISA is recovering from the loss of personnel and hiring personnel to “restore key services to better protect the country from malicious attacks and other threats.” FBI employees continue to be terminated for political reasons or no known reason. Many positions remain unfilled.

On July 1, 2026, more than 15 months after disbanding CIPAC, CISA launched its replacement, the Alliance of National Councils for Homeland Operational Resilience — Critical Infrastructure (ANCHOR-CI). CISA claims ANCHOR-CI’s framework is broader than CIPAC’s and provides for more flexibility. However, CISA has more of an oversight role in ANCHOR-CI by providing approval of the councils, participating organizations, leadership, subject matter experts, and member entities. Also, the CISA Director can appoint additional participants “as needed.” This oversight adds to the bureaucracy, which could slow responsiveness. The Director’s control over the councils’ participants could also hamper the independence of the councils and could limit discussions and information sharing.

Time will tell if ANCHOR-CI’s new framework can bring the critical infrastructure communities back together to be more effective than before. Until then, we should all be cognizant of the threat of cyber-capable adversaries like Iran.