The Water Went Dark. The President Went After Minnesota.

Iran-linked hackers breached more than thirty municipal water systems across seven states. The FBI, CISA, and the EPA scrambled. Then Donald Trump stood at Camp David and blamed Tim Walz. Behind the theater lies a slower-moving catastrophe — a nation’s most fragile infrastructure exposed by cuts he ordered, and a Commander-in-Chief who cannot tell his own agencies from his political enemies.

Somewhere in the small hours between Sunday, July 26 and Monday, July 27, the water stopped listening. Across Minnesota — in Plymouth, in South St. Paul, in Maple Plain, in Braham — the pumps, chemical dosers, and pressure sensors that keep drinking water safe abruptly stopped responding to the operators who were supposed to be in charge of them. Within days, the same signature appeared in at least seven states. According to CNN, some utilities were forced to issue boil-water notices and switch entirely to manual operation. According to the FBI and EPA advisory issued July 30, hackers had “altered IP addresses and passwords, causing utilities to lose monitoring and control capabilities” — meaning that for hours, in some cases longer, no one on the American side of the connection could see or steer the systems that keep Americans from getting sick.

No contamination was reported. That is the good news, and it is the only good news. The rest of the story is a portrait of a country whose most basic civil infrastructure has been left, deliberately and openly, on the internet — and of a president who greeted that revelation not with a plan, but with a rally line.

I. What Actually Happened

The attackers went after devices called programmable logic controllers, or PLCs — the small industrial computers that decide when a pump turns on, how much chlorine to inject, when a tank has reached the right pressure. In an ideal world, PLCs live on isolated networks that no one outside the plant can reach. In the real America of 2026, thousands of them are directly reachable from the open internet, protected in many cases by default passwords or no passwords at all. As Minnesota’s chief information security officer John Israel told CNN, “I suspect that those attackers are going to … continue to look nationally across the infrastructure.” Security researchers at Tenable, cited by Tech Times, believe the intruders exploited CVE-2021-22681, an authentication bypass in Rockwell Automation controllers first disclosed in 2021 and rated 9.8 out of 10 on the industry severity scale — a flaw for which the manufacturer has said no patch is coming.

Read that again. The pathway into more than thirty American water plants was a five-year-old vulnerability the industry has publicly acknowledged it will not fix. And it was pried open four days after federal agencies issued a fresh warning that Iranian-affiliated actors were expanding exactly this kind of campaign.

THE SCOPE

More than 30 Minnesota community water systems disrupted on July 26–27, with confirmed impacts in Plymouth, South St. Paul, Maple Plain, and Braham. The FBI and EPA later warned that at least seven states saw operational impacts.

THE METHOD

Attackers targeted internet-facing programmable logic controllers, altering IP addresses and passwords to lock legitimate operators out. Researchers cited by MSN/Tech Times point to an unpatchable Rockwell flaw.

THE SUSPECTED ACTOR

Federal investigators and industry researchers point to CyberAv3ngers, a group formally attributed to Iran’s Islamic Revolutionary Guard Corps, with a documented history of hitting U.S. water utilities since November 2023.

THE OFFICIAL POSTURE

The Minnesota IT Services agency labeled it a “coordinated cyberattack.” Federal officials briefed state leaders that Iran was the leading suspect but stopped short of formal attribution, wary of a false flag amid the ongoing war.

The story here is not that a cyberattack happened. The story is that everyone who was paid to see it coming saw it coming. In April 2026, per an academic tutorial on operational-technology security, a joint advisory (AA26-097A) from the FBI, CISA, NSA, EPA, Department of Energy and U.S. Cyber Command formally documented the very Iran-affiliated campaign now in progress. A 2024 EPA Inspector General report found critical or high-severity cybersecurity flaws in 97 of 1,000 audited drinking water systems serving roughly 26.6 million Americans. The warnings existed. The money did not.

II. The President’s Response — And What It Reveals

On Friday morning, July 31, at a Cabinet meeting at Camp David, President Donald Trump was asked about the attack. He was in possession of the same intelligence that his own agencies — the FBI, CISA, the EPA, the office of the National Cyber Director — had already shared with the governor of Minnesota, with Sen. Amy Klobuchar, and with the country’s cybersecurity press. What he said, on camera, is now the historical record.

“We heard in Minnesota there was a cyberattack and they blame it on Iran. I don’t think so. I think I blame it on Minnesota because they’re grossly incompetent. There was a cyberattack of 30 water plants, and I would blame it on Minnesota and the governor, the corrupt governor of Minnesota. Iran’s got bigger problems than worrying about Minnesota.”

— President Donald Trump · Cabinet meeting, Camp David · July 31, 2026

The remarks were reported by ABC NewsFox 9 MinneapolisFox News, and CBS Minnesota, among others. The president was told by his own government that Iran was the leading suspect. He said, in effect, that he did not care what his government thought. He said his political opponent had done it. He said this while the United States is at war with Iran — a war he initiated — and while the same Iranian-affiliated hackers his agencies had been publicly tracking for years were, at that very moment, still probing American water plants in at least six other states.

Gov. Tim Walz’s response, delivered via social media, was as direct as the situation demanded. “Trump knows exactly who is responsible for this attack, and knows that other states were hit too,” Walz wrote, according to CBS Minnesota. “This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran.” Walz went further in a Facebook post cited by KTTC, charging that the Department of Government Efficiency had “took an axe” to CISA — the very agency now scrambling to defend the water sector — and left the country “exposed to cyber attacks.”

III. The DOGE Fingerprints

Walz’s charge is not rhetoric. It is documentation. According to Broadband Breakfast’s June 2026 reporting, “CISA has lost one-third of its workforce since the start of the Trump administration,” in the words of Sen. Mark Warner of Virginia. According to NOTUS, among those pushed out were staffers actively tracking Salt Typhoon and Volt Typhoon — the Chinese state-sponsored intrusion campaigns targeting American critical infrastructure. According to TechCrunch, more than 100 CISA employees, including “red team” specialists whose job was to find the vulnerabilities enemies would exploit, were fired without warning in early 2025.

The congressional numbers tell the same story in a colder register. CISA’s fiscal year 2026 budget was cut to $2.6 billion from $2.8 billion in fiscal 2025, and the administration’s 2027 request would cut it further, to $2.4 billion. The Cybersecurity and Infrastructure Security Agency was created during Trump’s own first term, in 2018, to defend precisely the kind of infrastructure the Iranians have now attacked. Trump then spent the first eighteen months of his second term hollowing it out. And on Friday, standing at Camp David with the results in front of him, he blamed a governor in Minnesota.

The cybersecurity establishment is not being subtle about what this means. Speaking to CNN, industrial-security veteran Gus Serino called the scale of the Minnesota attacks “unprecedented” and warned that “many drinking water utilities continue to rely on technology architectures that lack fundamental cybersecurity controls.” Joshua Corman, co-founder of the volunteer security group I Am The Cavalry, was starker: “So much depends upon water… No water, no hospital, no kidding… in 2-4 hours.” That is not a metaphor. It is a rule of thumb about how quickly acute-care medicine collapses when the pumps go quiet.

Get Involved Today

Contribute to our mission and turn your concerns into action.

IV. The Stakes for Public Health and National Security

Take Corman’s warning seriously for a moment. Modern hospitals cannot sterilize instruments, run dialysis machines, cool imaging equipment, or maintain sanitation without pressurized potable water. Neither can nursing homes. Neither can food-processing plants, dairy operations, or the industrial base of any American city. A successful contamination attack — not merely a monitoring outage — could put lethal doses of chlorine, or fluoride, or ferric chloride into a distribution system in minutes. Even a sustained loss of pressure allows contaminants from the surrounding soil to be drawn into pipes through negative pressure, exactly what boil-water advisories are designed to warn against.

The Minnesota attackers, on this occasion, did not attempt contamination. Whether that restraint reflects operational limits, tactical patience, or an explicit intelligence signal — a demonstration of capability — is the question that ought to be occupying the West Wing. Instead, per the reporting of every major outlet from CBS News to Al Jazeera, it is being occupied by an attempt to convert a foreign attack on American civilians into a domestic political weapon.

V. A Timeline of Foreseeable Catastrophe

November 2023

Iranian IRGC-affiliated hackers operating as CyberAv3ngers shut down a water pumping station in Aliquippa, Pennsylvania, leaving the message: “You have been hacked, down with Israel.” Federal agencies issue a formal warning.

February 2025

The “Valentine’s Day Massacre” at CISA: DOGE fires more than 130 probationary staff, including red-team specialists and threat hunters tracking Chinese and Iranian actors.

April 2026

The FBI, CISA, NSA, EPA, DOE, and U.S. Cyber Command jointly issue Advisory AA26-097A, warning that the Iran-affiliated CyberAv3ngers campaign has expanded to Rockwell, Siemens, and Schneider Electric controllers.

July 22, 2026

CISA updates the advisory to note active exploitation of PLCs across U.S. critical infrastructure, including the theft of PLC project files and the manipulation of embedded safety logic.

July 26–27, 2026

More than 30 Minnesota community water systems are hit in a coordinated overnight campaign. Utilities lose monitoring and control; some are forced into manual operation.

July 30, 2026

The FBI and EPA issue a public warning that at least seven states have seen operational disruptions. The New York Times reports that investigators consider Iranian actors the leading suspect.

July 31, 2026

At a Camp David Cabinet meeting, President Trump publicly rejects his own government’s assessment and blames Gov. Tim Walz and the state of Minnesota.

VI. Why He Is Doing This

The temptation, in the face of remarks like Friday’s, is to conclude that the president has simply lost the thread. That conclusion is too generous. Trump’s blame-Walz maneuver is doing three specific things simultaneously, and each is worth naming.

First, it deflects from the cuts. If Iran is the culprit, the natural next question is whether America’s cyber defenses were adequate. The answer, plainly, is that they were not, and the reason they were not is that the president himself gutted the agency responsible. Blaming Walz erases the question.

Second, it manufactures a political enemy. Trump has, per Fox News’s own reporting, repeatedly attacked Walz — the 2024 Democratic vice-presidential nominee — over unrelated state welfare-fraud scandals. Grafting the water attack onto that grievance line is not policy; it is campaign content.

Third, and most dangerous, it reframes an act of foreign aggression as a partisan domestic dispute. When the Commander-in-Chief tells the public that a foreign adversary did not attack American civilians, and that a state governor did, he is not merely lying. He is disabling the ordinary machinery by which a democracy responds to attack. Congressional appropriators cannot rally the political will to refund CISA if the president denies the threat exists. State utility commissioners cannot demand hardened PLCs from vendors if the White House says the problem is the governor. Every one of the seven affected states loses standing to demand federal assistance the moment the federal government insists there is no federal problem.

Constitutional Analysis  ·  25th Amendment, Section 4

A Commander-in-Chief who cannot name the enemy is a Commander-in-Chief who cannot lead the response.

The 25th Amendment to the United States Constitution, ratified in 1967, provides a mechanism by which a president who is “unable to discharge the powers and duties of his office” can be temporarily removed. Section 4 specifies the process: the Vice President together with a majority of the Cabinet, or “such other body as Congress may by law provide,” transmits a written declaration of incapacity to the Congress, and the Vice President immediately assumes the powers of the office.

The amendment was written after the Kennedy assassination to ensure the continuity of executive function. It was not written for scandals. It was written for moments when the person in the chair can no longer discharge the specific duties the Constitution assigns to him — including, unambiguously, the duty to defend the nation against foreign attack.

The bill establishing the formal review body has already been introduced. On April 14, 2026, Rep. Jamie Raskin of Maryland introduced legislation to create a bipartisan Commission on Presidential Capacity to Discharge the Powers and Duties of the Office, backed by 50 co-sponsors, as reported by The Hill. A week earlier, Rep. Raja Krishnamoorthi of Illinois had publicly called on Vice President JD Vance and the Cabinet to invoke the amendment directly, citing “reckless escalation, erratic decision-making, and general conduct that raises grave questions about his fitness to discharge the duties of the presidency.” On April 30, per The Hill, Sens. Sheldon Whitehouse and Jack Reed of Rhode Island entered into the Congressional Record a statement from 36 physicians — neurologists, psychiatrists, and cognitive-disorder specialists from Harvard, Tufts, Columbia, and George Washington — warning of the president’s “rapidly worsening, reality-untethered, increasingly dangerous decline” and explicitly citing his access to nuclear codes as grounds for 25th Amendment action.

The constitutional case is not built on Friday’s remarks alone. It is built on a documented pattern: a president who tells his own military that a whole civilization “will die tonight”; who publicly rejects the assessments of his own intelligence agencies; who cannot, on the day of an active foreign cyberattack, direct his rhetorical fire at the actual perpetrator rather than a domestic political rival. Friday’s water-attack remarks are not the case for the 25th Amendment. They are one more data point in a case that has been mounting for months.

The practical barriers are real. Vice President Vance will not initiate proceedings against the president who put him where he is. The Cabinet, purged of dissent, will not act. A Republican-controlled Congress will not pass Raskin’s commission bill, and the president could veto it if it did. This is not a mystery. But those are barriers of political will, not of constitutional fact. The Framers of Section 4 wrote the mechanism precisely because they understood that a Commander-in-Chief who cannot perceive reality is a Commander-in-Chief who cannot defend the country — and the barriers to invoking it are the political cost of leaving the mechanism unused.

What Friday demonstrated is that the ordinary check — a president responding to a foreign attack on American civilians by directing the machinery of government to defend them — has failed. The Constitution provides another check. That it will not be used does not mean it should not exist, and it does not mean the case for it has not been made.

Editorial Conclusion

A foreign adversary attacked American water. The president’s own agencies told him. He said, on camera, that he did not believe them, and he named a domestic political rival as the enemy instead. This is not a communications problem. It is a defense problem, a constitutional problem, and — for every family drinking water from a compromised PLC in Plymouth or Duluth or six other states — a public health problem.

The country that built CISA in 2018 to defend this exact infrastructure watched its president spend eighteen months tearing CISA apart. The country that expects a Commander-in-Chief to name the enemy when the enemy attacks watched a Commander-in-Chief name Tim Walz. Refund the agencies. Get the PLCs off the open internet. And be honest, finally, about the man who told the country on Friday that Iran had nothing to do with the attack that Iran, by every credible assessment his own government has produced, carried out.

The water is the warning. The next attack — on a grid, on a hospital chain, on the ports — will not be a warning. It will be the thing itself.

Sources & References

  1. CNN Politics — “Sweeping cyberattack on water systems in multiple states has US officials on edge” (Jul 31, 2026). cnn.com
  2. CBS News — “U.S. investigating if Iran was behind cyberattack on water systems in 7 states” (Aug 1, 2026). cbsnews.com
  3. ABC News — “Trump blames Minnesota governor, not Iran, for cyberattacks on the state’s water systems” (Jul 31, 2026). abcnews.com
  4. Star Tribune — “Trump blames ‘incompetent’ Minnesota, not Iran, for water system cyberattacks” (Aug 1, 2026). startribune.com
  5. Fox 9 Minneapolis-St. Paul — “Trump blames Minnesota’s ‘gross incompetence’ for cyberattack on water systems, not Iran” (Aug 1, 2026). fox9.com
  6. CBS Minnesota — “Trump blames ‘grossly incompetent’ Minnesota for cyberattacks, despite feds investigating Iran’s role” (Aug 1, 2026). cbsnews.com
  7. Fox News — “Trump says Minnesota governor to blame for water systems cyberattack” (Aug 1, 2026). foxnews.com
  8. Newsweek — “Map Shows States Hit By Cyberattacks on Water Systems” (Aug 2, 2026). newsweek.com
  9. Al Jazeera — “US authorities probe cyberattack on water systems in Minnesota” (Jul 30, 2026). aljazeera.com
  10. KTTC — “FBI: Cyberattacks hit water systems in at least 7 states; Trump, Walz spar over Minnesota hack” (Jul 31, 2026). kttc.com
  11. Tech Times — “Iranian Hackers Exploited Unpatchable PLC Flaw to Breach 30 Minnesota Water Systems” (Jul 29, 2026). techtimes.com
  12. CBS News — “A brief timeline of Iranian cyberattacks on U.S. companies, political figures, water systems and more” (Aug 1, 2026). cbsnews.com
  13. Broadband Breakfast — “One Year After DOGE Cuts, Cybersecurity Agency Struggles Over Staffing” (Jun 13, 2026). broadbandbreakfast.com
  14. NOTUS — “DOGE Laid Off Workers Who Were Protecting Infrastructure From Foreign Hackers” (Mar 3, 2025). notus.org
  15. TechCrunch — “DOGE axes CISA ‘red team’ staffers amid ongoing federal cuts” (Mar 11, 2025). techcrunch.com
  16. The Hill — “Raskin introduces bill to assess president’s fitness under 25th Amendment” (Apr 14, 2026). thehill.com
  17. The Hill — “Concerns Grow Over Trump’s Mental Fitness for Presidency” (Jun 10, 2026). thehill.com
  18. House Judiciary Democrats — “Ranking Member Raskin Demands White House Physician Immediately Evaluate Donald Trump’s Cognitive Fitness” (Apr 10, 2026). house.gov
  19. Rep. Raja Krishnamoorthi — “Krishnamoorthi Calls for President Trump’s Removal Under 25th Amendment” (Apr 7, 2026). house.gov

Related News

Scroll to Top