Coverage spread: 2 sources — 1 center · 1 right
Lean ratings via AllSides / Media Bias-Fact-Check. How this works.
Where they agree
- At least seven US states have reported cyberattacks affecting water system infrastructure.
- Officials and experts agree no water quality or safety issues resulted from the intrusions.
- Normal operations were restored at all affected sites without lasting disruption.
- The incidents were reported to federal authorities, including the FBI.
Where they differ
- The Hill sticks to confirmed facts — seven states, FBI reports, water safety maintained — without naming any group or country behind the attacks.
- The New York Post names Iran-linked group Cyberav3ngers as the likely perpetrator, citing cybersecurity firm Tenable and CISA’s July 22 warning.
- The Post links the attacks to the broader US-Iran war and IRGC ties, a geopolitical angle absent from The Hill’s brief report.
- The Post raises the more alarming possibility that hackers may have accessed chemical dosing controls, a detail not mentioned in The Hill’s coverage.
What happened
At least seven states have reported cyberattacks on local water systems to the FBI, according to The Hill, which notes that authorities say water quality itself was not compromised. The New York Post, citing cybersecurity firm Tenable, reports the intrusions hit dozens of internet-connected water control systems — more than 30 in Michigan alone — with hackers locking out administrators and, in some cases, disrupting the pumping of water into storage towers like water towers. No lasting damage or contamination was reported, and normal operations were restored at every affected site.
Tenable’s public sector chief technology officer, Chris Day, told the Post that the pattern of the intrusions points to Cyberav3ngers, a hacking group that claims ties to Iran’s Islamic Revolutionary Guard Corps (IRGC). Day said Tenable began tracking the group’s chatter on dark-web forums in April, around the time the US and Iran went to war, when Cyberav3ngers announced plans to target North American water infrastructure. The US Cybersecurity and Infrastructure Security Agency (CISA) issued a warning on July 22 flagging Cyberav3ngers, and by extension Iran, as a likely threat to US water systems.
How exposed were the systems
Law enforcement sources told the Post that in some cases hackers may have gained access to systems that control and monitor the dosage of chemicals used in water treatment — a detail that raises the stakes beyond simple system lockouts, even though no evidence of tampering with chemical dosing has been reported. Day described Cyberav3ngers as an “opportunistic,” mid-tier threat actor that looks for exposed systems with known vulnerabilities rather than deploying sophisticated novel exploits.
Is it over
No group has publicly claimed responsibility for the recent wave of attacks, which the Post says is unusual for Cyberav3ngers, a group Day describes as normally vocal about its operations. He suggested two possibilities: either the campaign is still underway and the hackers are waiting to maximize damage or publicity before claiming credit, or they are simply following their past pattern of announcing attacks only after the fact. Cyberav3ngers has been active since at least 2020, historically targeting infrastructure in countries seen as adversaries of Iran, and previously hit water systems in Pennsylvania in a separate wave of attacks between October 2023 and January of the following year.
How the coverage differs
The Hill’s item is brief and cautious, sticking to the confirmed fact that seven states reported incidents to the FBI and that officials maintain water quality was not affected — it does not name Iran or any hacking group. The New York Post goes considerably further, naming Cyberav3ngers as the likely culprit, citing a specific cybersecurity firm and analyst, tying the campaign to the US-Iran war and the IRGC, and raising the more alarming possibility that hackers accessed chemical-dosing controls. The Post frames the story as an ongoing threat that may not be finished, while The Hill’s framing is narrower and more reassuring, emphasizing that safety was maintained.
Why this matters
Water utilities in the US rely heavily on industrial control systems that are often internet-connected for remote monitoring, a setup security researchers have long warned leaves smaller municipal systems vulnerable to exactly this kind of opportunistic intrusion. The involvement of a group with alleged IRGC ties, emerging in the same window as active US-Iran hostilities, underscores concerns that state-linked actors may use critical infrastructure as leverage or retaliation during periods of military tension. CISA’s public warning suggests federal officials view the threat as credible enough to alert utilities nationwide, even as the practical impact of this particular wave has so far been contained to disrupted access rather than any confirmed harm to the public.
Sources
Featured photo: U.S. Department of Homeland Security (DHS) via Wikimedia Commons (Public domain)