//
OFFLINE — VIEWING CACHED CONTENT
← Back to Archive

IC BRIEF

Current as of 0327 EDT (UTC-04), Saturday 08 August 2026

Contents

10 stories from 44 sources across 36 organizations


KEY JUDGMENTS

Sub-threshold adversary operations against Western infrastructure are expanding across three concurrent campaigns: Iranian-linked cyberattacks on US water utilities in twelve states, drone reconnaissance of a German Patriot depot, and state-linked hacking of Croatian government networks. Federal agencies will likely issue formal attribution of the Iran campaign within two months, reversing the prior-cycle assessment that attribution was unlikely. High confidence rests on the campaign's near-doubling from seven to twelve states, consistent CyberAv3ngers-pattern intrusion signatures, and boil-water advisories raising the political cost of non-attribution.

Russia is unlikely to mount a direct attack against a NATO member by early 2027, despite the revised US assessment that Putin could test alliance resolve. High confidence reflects the absence of force repositioning, forces committed in Ukraine, and Article 5 deterrence. A NATO member will likely connect the German drone incidents to Russian hybrid operations within two months, reinforced by Berlin's referral to military counterintelligence.

Iraq's September 30 deadline for disarming Iran-aligned armed groups will very likely pass without enforcement. Moderate confidence rests on every prior Baghdad disarmament deadline expiring without action and no observable enforcement preparation. A resumed militia strike against Saudi or US targets would test whether Saudi intelligence engagement with Baghdad survives escalation.


IC Operations & Tradecraft

CIA Creates Secret Cuba Task Force to Pressure Havana Leadership

BLUF: Elevating Cuba to Priority 1 collection alongside great-power adversaries locks in intelligence infrastructure that will outlast the task force's narrower covert mandate to fracture Havana's elite.

The CIA has secretly formed a classified Cuba task force to intensify pressure on Havana for the economic, political and leadership changes Trump has demanded, staffing it with case officers, analysts, cyber specialists and covert-influence officers 12. Unlike the CIA's 1960 Bay of Pigs-era unit, the new task force cannot train armed proxies or conduct lethal operations; its mandate is to fracture the Cuban political elite and push out hardliners 23. The administration separately designated Cuba a National Intelligence Priorities Framework "Priority 1" target alongside China, Iran and Russia, prompting the NSA and National Geospatial-Intelligence Agency to redirect satellite collection toward the island 23. Cuba's deputy foreign minister, Carlos Fernández de Cossío, called the effort familiar "espionage, subversion and destabilization" in a statement to the Times 23.

Analyst Note: The task force marks a doctrinal shift from crisis diplomacy to sustained covert pressure, betting elite fracture inside Havana succeeds where sanctions and public ultimatums have not. Redirected NSA and National Geospatial-Intelligence Agency (NGA) collection gives Washington a persistent targeting picture of Cuban leadership's finances and defenses outlasting any single administration's attention span, though sourcing rests on a single New York Times report, with other outlets merely redistributing that account. Absent lethal or paramilitary authority, leverage depends on recruiting or turning insiders, a slower and less certain instrument than the 1960s precedent it replaces. Havana's swift public rebuttal shows leadership already treats the campaign as confirmed, foreclosing any window for quiet signaling before public commitment hardens on both sides, and the disclosure itself may function as the operation, a calculated leak meant to unsettle Cuba's elite rather than a neutral account of covert planning.

Sources:

1: CIA Forms Secret Cuba Task Force: Sources - Newser

2: CIA sets up secret Cuba task force as Trump pressures Havana - San Juan Daily Star

3: The window is closing: The CIA creates a secret unit to step up pressure on the Castro leadership - Voz Media

Prior Reporting - [The New York Times: Cuba has been elevated to Priority 1 for US intelligence](https://en.cibercuba.com/noticias/2026-08-06-u1-e199894-s27061-nid337153-new-york-times-cuba-fue-elevada-prioridad-1) (2026-08-06) - [C.I.A. Sets Up Secret Cuba Task Force as Trump Pressures Havana](https://www.nytimes.com/2026/08/05/us/politics/cia-cuba-task-force.html) (2026-08-05) - [CIA Forms Secret Task Force Aiming at Cuba's Regime Change](https://www.cubaheadlines.com/articles/337151) (2026-08-06) - [C.I.A. Sets Up Secret Cuba Task Force as Trump Pressures Havana](https://newsnetworks.com/c-i-a-sets-up-secret-cuba-task-force-as-trump-pressures-havana-297034.html) (2026-08-05) - [C.I.A. Sets Up Secret Cuba Task Force as Trump Pressures Havana](https://www.nytimes.com/2026/08/04/us/politics/cia-cuba-task-force.html) (2026-08-04)

US Intelligence Concludes Putin Could Test NATO With Limited Military Attack in Coming Years

BLUF: A Russian limited attack on a NATO ally remains unlikely by end of January 2027, though Baltic and Polish frontline states face sustained sub-threshold hybrid probing.

New US intelligence assessments, first reported by the Wall Street Journal, concluded that Russian President Vladimir Putin could test NATO's resolve with a limited attack on an allied country within the next few years 1234. Scenarios range from a cyberattack to a small-scale land incursion, and one source told CNN Putin would most likely target the Baltics or Poland 34. The Kyiv Independent, citing the Journal, reported that officials now believe an attack could come as early as this fall and as late as 2029, a shift from the prior assessment that Russia's war in Ukraine would rule out action against NATO 5. The Journal tied the assessments to US shortfalls in Precision Strike Missiles, Army Tactical Missile Systems and Stinger interceptors 4.

Analyst Note: Russia is unlikely to mount a limited attack against a NATO member, whether cyberattack, sabotage, or small-scale land incursion, by the end of January 2027, since Putin's near-term priority remains a negotiated off-ramp in Ukraine and the reported strain on Precision Strike Missile, Army Tactical Missile System (ATACMS), and Stinger stockpiles narrows Washington's own bandwidth to respond even as it tempers rather than eliminates incentives to test Article 5. Confidence is high, resting on convergence between the US assessment and independent German and Lithuanian warnings rather than a single data point, though sourcing beyond the Journal's two primary reports is amplification rather than independent corroboration. This reverses Washington's prior view that the Ukraine war would preclude action against NATO and pulls the earliest window into this fall, though the timing may instead reflect a Pentagon push for munitions funding amid Trump's pushback on stockpile-shortfall reporting. Baltic and Polish forces will absorb near-term sub-threshold probing, while a shift toward overt attack would force NATO to preposition air and missile defenses and accelerate eastern-flank interceptor production.

Sources:

1: US Intelligence Warns Putin Could Test NATO With Limited Attack in Coming Years - Kyiv Post

2: US Intelligence Warns Putin Could Test NATO With Limited Attack in Coming Years - The Wall Street Journal

3: US intel assesses Putin could launch attack aimed at testing NATO unity - CNN

4: U.S. Intel Finds Putin Could Test NATO's Resolve With Limited Incursion - The Wall Street Journal

5: US intel warns Russia could test NATO as early as this fall, WSJ reports - Kyiv Independent

Allied Intelligence

Mossad Chief Fires Two Senior Officials Behind Failed Iran Regime-Change Plan

BLUF: Removing the plan's architects while keeping them in the agency contains accountability inside Mossad, shielding Netanyahu from a political reckoning over the failed Iran campaign.

Mossad Director Roman Gofman removed the heads of the agency's Intelligence Directorate and Iran Division, Channel 12 News reported Thursday, corroborated by Times of Israel, Haaretz, the Jerusalem Post and The National 1234. The Intelligence Directorate chief had held the post since December, and neither official was named, though Channel 12 identified both as architects of the plan to topple Iran's regime 134. Security sources told the network the departures were by mutual agreement amid a wider Mossad reorganization, with both expected to remain at the agency in other roles 14. A source cited by Haaretz disputed that account, saying Gofman, a former Netanyahu military secretary who backed the regime-change plan, ordered the dismissals to help the prime minister distance himself from its failure 23. The plan, a joint Mossad-CIA proposal presented to President Trump, envisioned Kurdish ground forces advancing into Iran under Israeli and US air cover to install former president Mahmoud Ahmadinejad as regime successor, and collapsed amid Turkish pressure and Kurdish reluctance following Israeli-US strikes on Revolutionary Guard positions in Iranian Kurdistan 134.

Analyst Note: Mossad removed the Intelligence Directorate and Iran Division chiefs, tying the agency's first accountability for the failed regime-change plan to internal ranks rather than the political leadership that approved it; both retain unnamed roles, limiting visibility into the reshuffle. Channel 12 is the sole primary source, with Times of Israel, Haaretz, Jerusalem Post and The National amplifying without independent confirmation. Haaretz's account that Gofman ordered the removals to shield Netanyahu from the plan's failure conflicts with security sources' claim of mutual departure amid routine reorganization, though the shakeup could equally reflect Gofman consolidating control after already ousting his deputy early in his tenure. How that dispute resolves will color assessments of Mossad's leadership bench for any renewed covert push on Iran's nuclear and missile programs.

Sources:

1: Mossad head reportedly removes 2 senior officials behind failed Iran regime-change plan - Times of Israel

2: Mossad Chief Reportedly Removes Senior Officials Amid Failed Effort to Topple Iran Regime - Haaretz

3: Mossad reportedly removes two senior officers over botched Iran regime change plan - The National

4: Mossad Director Gofman removes two senior officials over failure to replace Iranian regime - report - Jerusalem Post

⁨המהלך של ראש המוסד נגד הוגי התוכנית להפלת המשטר באיראן (The Mossad Chief's Move Against the Architects of the Plan to Topple Iran's Regime)⁩ - Channel 12 News (N12/Mako)

The Price of Failure, and the Question of Responsibility: Gofman Showed the Way Out to Senior Officials Who Worked on Overthrowing the Iranian Regime - Ynet

Prior Reporting - [Israelis Offer New Details on Joint Regime-Change Strategy and Mossad-CIA plan for Kurdish Invasion](https://www.spytalk.co/p/israelis-offer-new-details-on-joint) (2026-07-06)

Saudi Intelligence Chief Meets Iraqi PM to Discuss Security Coordination Amid Militia Threat

BLUF: Riyadh's willingness to accept al-Zaidi's no-launch pledge without accountability for strike deaths trades near-term diplomatic momentum for dependence on militia restraint Baghdad cannot guarantee.

Saudi intelligence chief Khalid bin Ali Al Humaidan met Iraqi Prime Minister Ali al-Zaidi in Baghdad on Friday, renewing an invitation for al-Zaidi to visit Riyadh 123. The visit follows Baghdad's cancellation of an earlier trip in protest of the July 29 US-Saudi strikes, which killed 20 fighters from Iraqi armed groups including five Iranians 3. Al-Zaidi's office said the two discussed strengthening security coordination and intelligence sharing to address regional challenges, and Al-Zaidi reiterated that Iraq would not allow its territory to be used to launch attacks on other countries 124. Separately, the Iran-aligned Islamic Resistance in Iraq announced Friday it was postponing a threatened retaliatory strike over the July 29 strikes, crediting lobbying by senior political figure Hadi al-Amiri 3.

Analyst Note: Riyadh's decision to send its intelligence chief in person, rather than a lower-tier channel, signals it now treats al-Zaidi's public no-launch pledge as sufficient for rapprochement without securing accountability for the 20 deaths from the July 29 strikes; corroboration is broad, resting on three independent primary accounts plus a secondary Al Jazeera report with no shared wire feed. The Islamic Resistance in Iraq's retaliation is deferred rather than renounced, credited to Hadi al-Amiri's lobbying rather than any enforceable state guarantee, leaving de-escalation dependent on the same informal intermediaries intervening again if Saudi-US operations resume. The thaw may equally reflect mutual face-saving, letting Riyadh and the militias avoid blame while the underlying dispute goes unaddressed. Al-Zaidi's unresolved September 30 disarmament deadline for the armed groups will determine whether the opening holds.

Sources:

1: Saudi intelligence chief visits Baghdad for talks on regional security - Arab News

2: Iraqi premier receives renewed invitation from Saudi leadership to visit Riyadh - Anadolu Agency

3: Saudi intelligence chief meets Iraqi PM, renews Riyadh visit invitation - Al Jazeera

4: Iraqi PM, Saudi intelligence chief discuss regional security as militias delay response - Al-Monitor

UNICEF Places Washington Office Head on Leave Over Allegations of Sharing UN Documents With Israeli Diplomats

BLUF: Exposure of a long-running Israeli liaison channel inside UNICEF, surfaced by hackers rather than internal oversight, compounds credibility risks for the agency's already contested Gaza reporting.

UN deputy spokesman Farhan Haq said Friday that UNICEF is taking "appropriate action" against Yahav Lichner, head of its Washington office, over allegations he secretly shared confidential UN documents with Israeli diplomats in 2014 and 2015 while serving at the UN Population Fund 123. Lichner has reportedly been placed on administrative leave, though Haq could not confirm whether Secretary-General Guterres has been briefed or whether UN internal oversight is investigating 13. Haq said UNICEF, as Lichner's employer, is leading the matter and that the alleged conduct, if true, would violate UN Charter and civil-service obligations of independence and impartiality 123. The allegations stem from a Drop Site News investigation published August 4, based on hacked emails from former Israeli UN ambassador Ron Prosor's archive obtained by the Handala group and released via Distributed Denial of Secrets 2.

Analyst Note: Yahav Lichner's placement on leave, without confirmation that Guterres or UN oversight is engaged, points to damage control ahead of resolution rather than a resolved accountability process. Corroboration rests on two independent primary accounts (Xinhua's spokesman quotes and Drop Site's original investigation), while Middle East Monitor repackages Anadolu's wire reporting rather than confirming independently, narrowing genuine convergence despite no contradiction. Because the alleged conduct predates the current Gaza war by roughly a decade, it suggests a standing informal Israeli liaison channel inside UN agencies rather than a one-off leak, reopening vetting questions for staff rotating between United Nations Population Fund (UNFPA), UNICEF, and other bodies handling Gaza-adjacent files; the disclosure, drawn from a hacked archive released by an Iran-linked group, is as plausibly an information operation targeting UN-Israel ties as documented misconduct. UNICEF's Gaza casualty-reporting credibility, already contested by both sides, is now entangled with the unresolved personnel matter.

Sources:

1: UNICEF taking appropriate action against staff accused of spying for Israel - Anadolu Agency

2: UNICEF taking action against staffer over alleged espionage for Israel: UN spokesman - Xinhua

3: UNICEF 'taking appropriate action' against staff accused of spying for Israel: UN - Middle East Monitor

"For Your Eyes Only": Israel's Mole Inside the United Nations - Drop Site News

IC Workforce & Organization

Pentagon Revokes Former Air Force Secretary Kendall Classified Access Over Air Force One Disclosure

BLUF: Kendall's clearance revocation follows the administration's pattern of punitive administrative action against former officials, and a criminal referral by November 8 remains unlikely.

The Department of War revoked former Air Force Secretary Frank Kendall's eligibility for access to classified information and barred him from holding any sensitive position, effective immediately, Pentagon spokesperson Sean Parnell announced Friday on X 1. Parnell said the action follows Kendall's "unauthorized disclosure of classified information regarding Air Force One's capabilities" to an unnamed media outlet, after reporting last month, including by The New York Times, raised security concerns about the Qatari-gifted jet 12. Kendall told the AP and CNN he was "completely mystified" by the revocation, saying he has been careful not to disclose anything classified and that no one has told him what he is alleged to have revealed 34. Parnell did not say whether Kendall faces a prosecution referral 23.

Analyst Note: A criminal referral against Kendall by November 8 is unlikely, since Parnell declined to confirm one and the administration has revoked clearances from dozens of officials, including General Milley, without follow-on prosecution in nearly every prior case. With no classified fact or damage specified, the action reads as an administrative sanction rather than an Espionage Act case, though the rhetoric may instead reflect retaliation against a vocal administration critic. Sourcing rests on a single Pentagon statement that AP, CBS, CNN, and The Hill merely restate and Kendall denies. The move marks the administration's first punitive step in the Qatari jet controversy. A confirmed referral would commit Justice Department resources and chill other officials from speaking, while absent one Kendall faces only reputational costs. Confidence is moderate: consistent Pentagon messaging, but sparse signs of prosecutorial intent.

Sources:

1: Effective immediately, the Department of War has REVOKED former Secretary of the Air Force Frank Kendall's eligibility for access to classified information... - Sean Parnell (Pentagon Press Secretary, via X)

2: Pentagon revokes former Air Force Secretary Frank Kendall's access to classified information - KTAR/AP

3: Pentagon revokes security clearance of former Air Force chief for disclosing "classified information regarding Air Force One's capabilities" - CBS News

4: Pentagon revokes access to classified information for former Air Force secretary - CNN

Pentagon revokes former Air Force secretary's access to classified information - The Hill

Prior Reporting - [US orders travelers on Air Force One to throw away gifts, pins, and burner phones after China trip](https://techcrunch.com/2026/05/15/us-orders-travelers-on-air-force-one-to-throw-away-gifts-pins-and-burner-phones-after-china-trip/) (2026-05-15) - [US staff, press ditch Chinese credentials before departing Beijing](https://thehill.com/homenews/administration/5879679-trump-beijing-security-clash/) (2026-05-15) - [White House Staff Told Reporters to Toss 'Burner Phones,' Other Items in Trash While Leaving China Amid 'Bugging' Fears](https://www.mediaite.com/media/tv/white-house-staff-told-reporters-to-toss-burner-phones-other-items-in-trash-while-leaving-china-amid-bugging-fears/) (2026-05-15) - [Here's How Seriously the US Took Digital Security on President Trump's Trip to China](https://townhall.com/tipsheet/dmitri-bolt/2026/05/15/heres-how-seriously-the-us-took-digital-security-in-china-during-high-stakes-beijing-summit-n2676153) (2026-05-15)

Adversary Intelligence

Suspicious Drones Sighted Over German Military Base Days After Leipzig Airport Explosive Drone Incident

BLUF: Back-to-back drone penetrations of a Ukrainian air-logistics node and a Patriot repair depot trace a deliberate campaign to map Germany's military support chain for Ukraine.

Two drones were sighted around 10 pm Thursday over the Bundeswehr's Mechernich base, a Patriot air-defense repair and weapons-storage site west of Bonn, and military police opened an investigation now held by Euskirchen police, the Bundeswehr's Operational Command confirmed 1. Sueddeutsche Zeitung, citing a confidential police document, reported a private security firm logged six drone flights overnight into Friday and that arriving officers spotted a large drone suspected to be a Fly-380 Vertical Take-Off and Landing (VTOL) with roughly a 400-kilometer range, per TASS 2. The same report said a case was opened for suspected unauthorized surveillance of the installation, with military counterintelligence and Berlin's Joint Drone Countermeasures Center also involved 2. The sighting comes days after an explosives-rigged drone was found near Ukrainian transport aircraft at Leipzig/Halle Airport, an incident Interior Minister Alexander Dobrindt called a hybrid attack by "highly professional" actors without ruling out foreign involvement 1.

Analyst Note: Suspected reconnaissance overflights at Mechernich, involving six logged flights and daylight loitering as police arrived, indicate whoever staged the Leipzig/Halle explosive-drone incident can sustain repeat penetration of German military airspace rather than mount a single opportunistic strike, deliberately targeting a Patriot depot rather than straying civilian traffic. Referral to military counterintelligence and the Joint Drone Countermeasures Center shows Berlin now treats the two incidents as one campaign, pushing counter-drone hardening beyond airports to depots and repair facilities, though the account rests on a single unverified reporting chain amplified rather than independently confirmed by secondary outlets. A non-state or commercial operator flying unrelated nuisance or intelligence-gathering missions near the Leipzig plot remains a plausible alternative to a genuinely linked campaign. Set against a revised US assessment that Putin could test NATO's resolve with a limited incursion, the pattern fits sub-threshold hybrid probing that typically precedes an escalation decision.

Sources:

1: Drones sighted over military base in western Germany - DPA

2: Unknown drones spotted over Bundeswehr base in western Germany — newspaper - TASS

Suspicious drones sighted over German military base days after Leipzig airport incident - Kyiv Independent

FDD Analysis Documents Expanding Intelligence Sharing Between Russia China Iran and North Korea Citing DIA Assessment

BLUF: Aggregating previously delivered congressional testimony into a unified axis framework, Foundation for Defense of Democracies (FDD)'s analysis functions as defense-budget advocacy rather than an independent threat indicator.

An FDD analysis published Friday, accompanying a new book by Bradley Bowman, Elaine Dezenski, and Mark Montgomery, cites Joint Chiefs Chairman Gen. Dan Caine's July 21 testimony to the Senate Appropriations Committee that China, Russia, Iran, and North Korea are "sharing intelligence, combat capabilities, and technology" 12. The analysis cites DIA's 2025 Worldwide Threat Assessment, which concluded North Korea holds its strongest strategic position in decades due in part to Russian military assistance 1. It also cites testimony from US Forces Korea commander Gen. Xavier Brunson that Russia is expanding transfers of space, nuclear, and missile-applicable technology to Pyongyang 1, and April 2025 United States Indo-Pacific Command (INDOPACOM) testimony that China supplied 70 percent of the machine tools and 90 percent of the legacy chips used to rebuild Russia's military production 1.

Analyst Note: The FDD analysis, paired with a commercial book by the piece's own authors, aggregates months-old testimony (Caine's July 21 remarks, DIA's 2025 threat assessment, Brunson's and INDOPACOM's testimony on machine-tool, chip, and technology transfers) into a single narrative of institutionalized Beijing-Moscow-Tehran-Pyongyang cooperation, recasting four largely transactional bilateral relationships as a coordinated axis. Sourcing rests entirely on FDD's own analysis, with RealClearDefense merely syndicating it and no independent outlet corroborating the underlying testimony, leaving the piece better read as advocacy timed to the defense-industrial-capacity budget debate than as a fresh threat indicator. The repackaging of already-public testimony suggests the piece is primarily aimed at shaping the authors' policy agenda rather than disclosing new intelligence.

Sources:

1: Axis of Aggressors Military Cooperation Is Worse Than You Think - Foundation for Defense of Democracies

2: Axis of Aggressors Military Cooperation Is Worse Than You Think - RealClearDefense

Counterintelligence

Croatia Arrests Serbian National Linked to BIA Intelligence Service for Hacking Government Systems

BLUF: Zagreb is unlikely to formally attribute the government network intrusions to Serbia's Serbian Security Intelligence Agency (BIA) by early October, as prosecutors build a criminal case that defers the diplomatic confrontation neither capital wants.

Croatian police arrested Georgije V., 33, a Serbian national from Novi Sad, on July 28 while vacationing on Croatia's Adriatic coast; a court ordered one month of pretrial detention despite an offered 20,000-euro bail 1. He is charged with unauthorized access to the Interior Ministry, Finance Ministry, Croatian Health Insurance Fund (HZZO), Croatian Pension Insurance Institute (HZMO), Croatian Regulatory Authority for Network Industries (HAKOM) and Central Registry of Insured Persons (Croatia) (REGOS), intrusions Index.hr and Srpske Novine trace to early April and routed through servers in Sweden and Belize 23. Index.hr identified him as owner of Novi Sad cybersecurity firm Elite Security Systems, which markets penetration-testing services 2. Croatia's Chief State Attorney, Ivan Turudic, referenced an unspecified national-security case this week 1, which Jutarnji list identified as this arrest and linked to Serbia's BIA intelligence service 1; neither tportal nor Index.hr confirms that link 24.

Analyst Note: Official Croatian confirmation of a BIA tie is unlikely by October 8, given the case is proceeding as a computer-crimes prosecution while forensic analysis of seized devices and cross-border requests to Belgrade continue. Zagreb has strong incentive to withhold a state-attribution finding until evidence clears the higher threshold that espionage charges require, and prosecutors have signaled the investigation will stay closed to further disclosure. A formal attribution would force a diplomatic confrontation with Serbia that neither government appears prepared to manage this early in proceedings. Moderate confidence rests on a single named-source claim that two independently reporting Croatian outlets have not corroborated.

Sources:

1: Secrecy Surrounds Croatia's Arrest of Alleged Serbian State-Linked Hacker - Balkan Insight

2: Srpski haker upao u MUP, Ministarstvo financija, HZZO, HZMO... Doznajemo tko je on - Index.hr

3: Croatia Traces Hacking Breach to Novi Sad Cybersecurity Firm - Srpske Novine

4: Slučaj špijuna Georgija V.: Kako je Srbin koji je hakirao pola Hrvatske pao baš na ljetovanju - tportal

IC Technology & Cyber

Soufan Center Assesses Iranian Cyberattacks on Water Systems Across 12 US States as Grey Zone Capabilities Test After CISA FBI and NSA Issue Joint Advisory

BLUF: Iran's probing of water-utility Operational Technology (OT) across 12 states will likely draw formal US attribution within two months, converting a grey-zone capability test into a named deterrence challenge.

Water utilities in at least 12 states, including Michigan, Minnesota, Georgia, New Jersey and South Dakota, have reported cyberattacks on operational technology, up from the seven states cited in a July 30 joint FBI, EPA and Cybersecurity and Infrastructure Security Agency (CISA) advisory warning that threat actors had remotely accessed water and wastewater control systems 1. More than 30 Minnesota community water systems were affected 1, and Georgia's Clayton County Water Authority, serving 300,000 Atlanta-area customers, reported a pressure drop and issued a boil water advisory later lifted 12. The FBI said the intrusions share common hallmarks, including changed passwords and loss of remote monitoring and control, with effects including pressure loss and flooding 2. Federal agencies have not formally attributed the campaign, but sources cited by CBS News and The Record identify Iran-backed hackers as the suspected actor 12, and officials report no impact on drinking water safety 13.

Analyst Note: Federal agencies likely will issue formal attribution naming Iran-linked actors within the next two months, as successive FBI, EPA and CISA advisories grow more technically specific and intrusion tradecraft continues to match the 2023 CyberAv3ngers' pattern of default-credential access to programmable logic controllers. Boil-water advisories and lost remote-control capability at utilities serving hundreds of thousands of customers raise the political cost of continued non-attribution and press CISA toward a public determination. High confidence in this judgment rests on matching technical indicators, altered credentials and lost Programmable Logic Controller (PLC) monitoring capability, recurring independently across a widening set of states and utilities.

Sources:

1: At least 12 states report cyberattacks on water systems possibly linked to Iran-backed hackers, sources say - CBS News

2: Cyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidents - The Record

3: Suspected Iranian Hack of U.S. Water Systems Sign of Grey Zone Capabilities - The Soufan Center

EPA, FBI, CISA, NSA Issue Joint Cybersecurity Advisory to Water System Regarding Iranian-Affiliated Cyber Attacks - EPA / FBI / CISA / NSA joint advisory

Prior Reporting - [FBI: Water Hacks in Seven States Aimed at Contaminating Drinking Supplies](https://www.techtimes.com/articles/322503/20260731/fbi-water-hacks-seven-states-aimed-contaminating-drinking-supplies.htm) (2026-07-31) - [Feds issue warning to local water systems over increased cyberattacks, following Minnesota incident](https://abcnews.com/US/investigators-iran-connection-minnesota-water-system-hacks-us/story?id=135237777) (2026-07-31) - [Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a) (2026-07-22)

COLLECTION GAPS

UNCLASSIFIED // OPEN SOURCE