Suspected Iranian intrusions into American water and wastewater utilities have spread from Minnesota, where more than thirty systems were affected, to Michigan, where nine have been. The New York Times has reported at least five further states targeted. A federal alert went out on Tuesday, and the Michigan cases surfaced on Saturday.

What was reached matters more than how many. The confirmed activity is in operational technology, the systems used to monitor and control equipment remotely, and at some facilities the attackers shut operating controls down. That is a category of access distinct from stealing records: it touches the machinery itself.

No public health consequences have been reported. Water kept flowing safely, and the practical effect on residents amounted to a brief request in Braham, Minnesota, that people minimise use. The FBI and the Cybersecurity and Infrastructure Security Agency are leading the response, and federal officials have named Iranian actors as the chief suspect. Braham's mayor Nate George said he was fairly confident of the same.

The politics arrived quickly. President Donald Trump blamed Minnesota for gross incompetence; Governor Tim Walz noted that the president is aware other states were hit as well. The precedent sits a decade back: in 2016 the Justice Department charged Iranian hackers over an intrusion at a dam near New York City, which is roughly how long this class of target has been understood to be exposed.