U.S. Won't Formally Blame Iran For Water-Utility Hacks By Deadline
My call: The U.S. keeps Iran in the shadows and the word 'attribution' in quotation marks through September 30.

The Call: Fuzzy Wins
Here is the simple, scorable bet: by the end of September, the U.S. federal government will not say the quiet part loud. No formal, on-the-record statement that the government of Iran is responsible for the coordinated hacks on water systems in at least seven states, including dozens of Minnesota utilities. Lots of smoke, no named arsonist.
The consensus expectation is that once someone starts messing with Americans' tap water, the gloves come off and the podiums come out. In reality, Washington has a favorite tool for awkward cyber moments: strategic mumbling.
The pattern is already visible. CISA has been waving red flags about Iranian-affiliated actors poking Rockwell Automation controllers all year. Investigators whisper about tradecraft that looks familiar. Yet in public, officials are suddenly connoisseurs of nuance, warning that anyone can fake anyone and that attribution is very difficult and so on. When the technical people start talking like defense lawyers, you are not on a glide path to a clean public blame call.
Driver 1: The Forensics Are Messy On Purpose
The technical spine of the Iran theory is straightforward enough: internet-facing PLCs, Rockwell gear, patterns that rhyme with previous Tehran-linked runs at U.S. infrastructure. CISA even pre-spoiled the plot with advisories about Iranian-affiliated actors targeting exactly this kind of equipment.
Yet listen to what investigators are actually saying in public. They are stressing that the threat actor might have mimicked Iranian tactics. They highlight that no confirmed evidence links the campaign to Iran. They keep repeating that formal attribution is "not yet" done.
That is not how officials talk when they are one FOIA request away from going on camera with a flag and a logo. It is how they talk when the malware log looks like a Reddit thread: some genuine Iran fingerprints, some false-flag cosplay, some commodity tools anyone can buy for the price of a mid-range streaming subscription.
To cross the line into formal attribution, the U.S. usually wants more than "it looks like last time." They want SIGINT, tasking orders, infrastructure reuse that is basically a signature, or at least allied intel that can share the blame. In the next 60 days, the odds of that entire chain of confidence completing, surviving the lawyers, and emerging in a public statement are modest. The hackers are playing in the mud on purpose, and mud slows policy down.
Driver 2: Trump Likes His Villain List Domestic
Technical ambiguity would be a headache in any administration. Under this one, it is a feature.
President Trump has already live-tested his preferred narrative. Confronted with reports that intelligence points toward Iran, he shrugged and blamed Minnesota. Not Tehran, not the IRGC, not some shadowy APT. Just "grossly incompetent" local Democrats.
That tells you where the political gravity sits. A foreign-state attribution would validate the agencies he enjoys contradicting, admit that a U.S. adversary just got inside critical infrastructure, and slightly dilute his favorite storyline that blue-state elites cannot plug in a router.
Ambiguity, by contrast, is perfect. As long as the actors are "Iranian-linked," "affiliated," "resembling prior campaigns," or "one of several suspects," the White House can safely ignore the foreign angle and keep punching the local ones. You cannot fact-check a president with an intelligence assessment that the president refuses to let exist in final form.
Bureaucracies do not win fights with an uninterested commander-in-chief in under two months. They stall, they narrow their language, they bury verbs in passive voice. Which, conveniently, is exactly what "no formal attribution" looks like from the outside.
Driver 3: Escalation Is Expensive, Vagueness Is Cheap
Naming a state for an attack on water utilities is not just a press conference; it is a policy commitment. Once you say "Iran did this," a bunch of things line up behind it: sanctions, cyber retaliation, allied coordination, at least three Sunday-show appearances where someone in a flag pin calls it a red line.
That is escalation fuel in a relationship with Iran that is already radioactive. Critical infrastructure is one of the few domains everyone pretends to treat as special. Put "Iran" and "American drinking water" in the same official sentence and you are halfway to a new round of tit-for-tat.
Or you could not do that. You can warn broadly about "foreign adversaries," push CISA alerts, and quietly encourage utilities to stop hanging PLCs on the open internet like porch lights. You can respond with quiet cyber operations or narrow sanctions that mention "malicious cyber activity" without tying it to a tap in Minnesota.
From the system's point of view, strategic ambiguity is not cowardice, it is asset management. You get to harden defenses, maybe whack some infrastructure in cyberspace, and avoid finding out what Tehran thinks counts as symmetrical response for a hit on its own pumps.
What Would Have To Break This Forecast
For Washington to cross the line before September 30, at least one of three things has to happen very fast.
- An intelligence coup that is too clean to ignore: captured tasking orders, pristine SIGINT, a defector on cable news. Something that makes non-attribution look more embarrassing than attribution.
- A political pivot where Trump suddenly finds it convenient to be the guy who punches Iran over water. That would require a separate crisis or a polling epiphany that "tough on Tehran" beats "tough on Minnesota."
- Allied and industry pressure so unified that it raises the reputational cost of staying vague. Think G7 statements, heavyweight cyber firms saying "this was Iran" with their whole chest, and Congress howling for a name.
All of this is possible in theory. None of it looks likely within a 60-day window where the story is still mostly confined to policy nerds and angry Minnesotans, and where the observable language from investigators is getting more careful, not more direct.
Stakes: The Enemy Is Now "The Threat Actor In Your Area"
The real cost of staying fuzzy is not that Iran gets away with something. Tehran already knows what Tehran did.
The cost is that the public ends up with a hazy villain called "bad cyber actors" and a vague action item called "resilience." Instead of a clean line like "Iran tried to mess with your water, so we disconnected X and regulated Y," we get another sermon about best practices and shared responsibility while PLCs in small towns continue to sit on the open internet like unattended luggage.
When this eventually resolves, we will likely get a quiet line in a report or a sanctions footnote that retroactively admits what everyone suspected. There will be no podium and no primetime speech, just a paragraph that lands long after anyone remembers which community system in Minnesota had to reboot its pumps.
Until then, expect the official story to stick with a familiar Washington villain, one that never sues for defamation and never gets due process. By September 30, the hackers may or may not be Iranian, but the only actor anyone will name with confidence is "systemic vulnerabilities."
In the American cyber playbook, foreign adversaries are optional characters. The real permanent antagonist is misconfiguration.
Around the Shallot
Stay in the same broken universe.
Forecasts, satire, cartoons, and quizzes should feel like one publication, not disconnected tabs.

Tech
Euronews Launches Infinite New Shows To Finally Explain Europe, Ideally Before Europe Collapses
From ‘The Ring’ to ‘No Comment’, the network bets that what citizens really crave is more formats, but branded.
Aug 2

Forecast
By 2027, U.S. Data Centers Won’t Reach 12 Percent of Power Use
Wall Street says the AI gods will devour a tenth of the grid in record time. The grid has other ideas, like physics, permitting, and everyone else who also wants electricity.
Aug 1
Comments
Be the first to comment.

