The Cyber Campaign That Ceasefires Can't Reach
The U.S. is fighting a cyber war with the tools of a political one — and the adversary has said so, in its own words.
When hackers breached water systems across more than thirty Minnesota cities last week, Donald Trump had a diagnosis ready.
They blame it on Iran. I don’t think so. I think I blame it on Minnesota because they’re grossly incompetent. I would blame it on Minnesota and the governor, the corrupt governor of Minnesota. — Donald Trump
Six federal agencies had already warned that Iran-affiliated actors were systematically compromising programmable logic controllers across the United States. The U.S. holds nearly three-quarters of all globally exposed industrial control devices.
The FBI and its partners are issuing this advisory to ensure organizations are best positioned to defend themselves against exploitation by Iran-affiliated cyber actors. — Federal Bureau of Investigation
A governor can be blamed for a breach. A governor cannot be blamed for a national exposure surface. The contradiction is not subtle, and it is not new. It is the same one that has structured the American response to Iran's infrastructure campaign since it began: treat each intrusion as a failure of local execution, and the systemic condition that makes the next one inevitable goes unaddressed. The vulnerability surface is concrete and catalogued. In May, Iranian hackers breached automatic tank gauge systems at gas stations across multiple states by exploiting devices connected to the internet without password protection.
The bottom line is that Iranian actors are under pressure and are trying to strike wherever they find an opening in cyberspace. — Yossi Karadi
The same month, Israeli researchers linked the LA Metro cyberattack to Iran's Ministry of Intelligence and Security through the group MuddyWater, part of a broader espionage campaign targeting aerospace, defense, and telecom across the U.S., Israel, Europe, and the UAE [1]. Canada's cyber agency had already warned that pro-Russia hacktivists were exploiting the same class of weakness — unpatched vulnerabilities and weak credentials in industrial control systems across water, energy, and agricultural facilities — and attributed the problem not to technology gaps but to an unclear division of roles and a lack of regulatory oversight.
This focus on readily accessible flaws — effectively the lowest-hanging fruit — underscores a critical point: robust security hygiene measures are the most effective defence. — Paul Shaver
The pattern is not a series of discrete failures. It is a single condition, observed from multiple angles, by multiple governments, across multiple sectors. The federal agency charged with defending against exactly this kind of campaign is CISA. During Iran's retaliatory cyber offensive in March — a coordinated campaign that integrated nearly 5,800 cyberattacks across the U.S., Israel, Bahrain, Kuwait, and Qatar with physical drone strikes on data centers in the UAE and Bahrain [2] — CISA was operating at roughly 38 percent staffing.
I am in direct coordination with our federal intelligence and law enforcement partners as we continue to closely monitor and thwart any potential threats to the homeland. — Kristi Noem
The reduction was not an accident. The Department of Government Efficiency had driven 998 departures and 65 reassignments from the agency [3]. The acting director defended the cuts before Congress as "mission-focused," with capability "measured by outcomes, not headcount."
The work that we do is mission-focused, which means capability is measured by outcomes, not headcount. — Madhu Gottumukkala
Congress then proposed an additional $268 million in cuts, targeting two line items in particular: vulnerability management, at $22.2 million, and threat hunting, at $17.5 million [4].
CISA shall not reduce staffing in such a way that it lacks sufficient staff to effectively carry out its statutory missions — United States Congress
And when that mandate is carried out with discipline and focus, the agency earns bipartisan support in Congress and confidence from the industry. When it does not, that confidence erodes. — Andrew Garbarino
These are the two functions most directly relevant to finding and fixing the kind of exposed industrial controllers Iran-linked actors are exploiting. The cuts were proposed in January. The gas station breaches happened in May. The water system attacks happened in July. The timeline is not causal in any provable sense, but it is directional: defensive capacity contracted, and the campaign expanded into the gap. CISA has not been idle. It issued an emergency directive in February requiring federal agencies to patch a critical Cisco vulnerability [5]. It is piloting Anthropic's Mythos AI model to scan federal government software for vulnerabilities [6]. But the AI pilot scans federal repositories. The actual targets are municipal water systems in Rapid City, South Dakota — hit by a denial-of-service attack on a lift station on July 31 — and unpassworded tank gauges at gas stations. The gap between what is being defended and what is being attacked is the story. Minnesota's state-level response to the water system attacks was, by its own account, effective. The state's IT commissioner said the response "worked as intended, enabling agencies at every level of government to rapidly coordinate, contain the incident and help prevent more serious impacts to critical services" [7]. Containing one attack is not the same as defending against a persistent campaign. And the campaign has stated, in its own words, that it operates on a timeline American political tools cannot reach. In April, the Iran-linked group Handala made its position explicit.
And let it be clear: The cyber war did not begin with the military conflict, and it will not end with any military ceasefire. — Handala
The declaration was not rhetorical. It was operational doctrine, and it has been borne out. A U.S.-Iran ceasefire was declared in June. It collapsed by July. Trump announced the end on Truth Social.
We have agreed to do so, but the United States has stated to them, in no uncertain terms, that the Cease Fire is OVER! — Donald Trump
The political-military timeline lurched from escalation to ceasefire to collapse. The cyber campaign continued through all of it. In late July, Iran struck a Kuwaiti desalination plant twice in two days — infrastructure targeting as kinetic doctrine, not merely a cyber tactic [8]. The Rapid City wastewater attack came days later. Trump's response to the broader campaign has been to threaten retaliation. In April, as federal agencies confirmed Iran-linked hackers were exploiting Rockwell Automation software and Allen-Bradley PLCs across U.S. energy and water sectors, he directed a military threat at Iran over the Strait of Hormuz [9]. His March cyber strategy shifted U.S. posture from reactive defense to aggressive offense, promising that "American Power will finally stand up in cyberspace" [10]. Offensive posturing, like blame, is a political tool. It addresses an adversary's calculus. It does not address the condition of 3,900 exposed programmable logic controllers inside the United States. The CISA AI pilot is the image that captures the whole. A technological substitute for human analysts, deployed inside an agency that has lost a third of its staff, scanning federal software repositories while municipal water systems go down in South Dakota and gas station gauges sit on the open internet without passwords. The pilot may find vulnerabilities in government code. It will not find the next exposed lift station in the next small city. And the adversary has already said it will keep looking.
- 1. Israeli Researchers Link LA Metro Cyberattack to Iranian State
- 2. Iran Executes Coordinated Cyber and Missile Offensive Against U.S. and Israel
- 3. CISA Acting Director Defends One-Third Staffing Cut Before House
- 4. Congress Proposes $268 Million Budget Cut for CISA
- 5. CISA Mandates Federal Patching of Critical Cisco SD-WAN Flaw
- 6. CISA Uses Anthropic AI to Scan Government Software
- 7. Cyberattack Targets Water Systems in Over 30 Minnesota Cities
- 8. Kuwait Condemns Iranian Strikes on Water and Power Plants
- 9. Trump Threatens Iran as Hackers Target U.S. Infrastructure
- 10. Trump Unveils Aggressive New National Cybersecurity Strategy