When War Reaches the Water Tower
America’s war with Iran may have reached a Minnesota water tower.
On July 26 and 27, hackers targeted more than 30 community water systems across Minnesota. In Braham, attackers temporarily shut down computerized controls for the city’s well and treatment plant, leaving the community dependent on water already stored in its tower. Within days, the FBI reported similar incidents involving water and wastewater utilities in at least seven states, some causing lost pressure and flooding. Officials reported no compromise of drinking-water quality. U.S. officials reportedly believe Iranian-linked hackers were likely responsible, although the FBI has not publicly attributed the attacks, and no public evidence yet ties AI to them.
That qualification matters. Neither Iran nor artificial intelligence has been conclusively tied to these attacks. But the broader warning is unmistakable: America’s distant wars can now reach directly into local communities without a missile crossing our border.
Cyberattacks are not new. Iranian operatives attacked American banks and penetrated the control system of New York’s Bowman Avenue Dam more than a decade ago. Iran’s Islamic Revolutionary Guard Corps-affiliated CyberAv3ngers compromised programmable logic controllers at American water facilities, and China’s Volt Typhoon campaign sought persistent access inside American communications, energy, transportation and water networks to position Beijing for disruption during a future crisis.
What is new is AI.
Artificial intelligence is radically changing cyber operations in scope, speed and capability. It can scan the internet for exposed industrial controllers, identify their manufacturers and help hackers modify attack scripts. It can craft phishing messages, test stolen credentials and adapt one method across dozens of similar systems.
In other words, AI industrializes cyberattacks.
A hostile government once needed teams of specialists to attack many targets. AI now allows fewer operators to accelerate reconnaissance, vulnerability analysis, coding and target selection. OpenAI has documented Iranian, Chinese, Russian and North Korean state-linked actors using its models for research, scripting and malware assistance. Western agencies warn AI is shortening the gap between discovering a vulnerability and exploiting it.
This is the danger I warned about in my three recent books, “AI for Mankind’s Future,” “The New AI Cold War,” and “The Final Algorithm.” AI is not merely another commercial technology; in hostile hands it can multiply the reach of governments, terrorist proxies, and criminal organizations.
The threat is national, but many of the softest targets are local.
America has nearly 170,000 drinking-water and wastewater systems. Many smaller utilities run aging equipment, struggle to hire cybersecurity specialists and devote scarce funds first to meeting water-quality requirements. Many controllers designed decades ago for reliability, not for combat against foreign intelligence services, are now connected to business networks, cellular links and the public internet for remote monitoring.
The FBI says the recent attackers reached internet-facing programmable logic controllers, changed addresses and passwords, and caused operators to lose monitoring or control. The FBI warned that similar configurations installed by common contractors can allow attackers to repeat the same intrusion across multiple locations. That is precisely the kind of weakness AI is well suited to exploit: find one vulnerable design, locate every other system using it and attack at scale.
Water is only one sector. The same pattern applies to hospitals, pipelines, electrical distribution, ports, factories, local governments, and emergency communications. The bulk power system and major financial institutions operate under more mature cybersecurity standards and regulatory supervision, but thousands of smaller operators lack comparable money, personnel, and expertise.
AI-assisted cyberattacks should now be treated as an expected instrument of coercive diplomacy and future war.
During a confrontation with either Iran or China, AI-assisted cyberattacks could become an instrument of coercion. Tehran might disrupt several utilities and deliver a simple warning: We have access. We can do more. Change your policy. During a Taiwan crisis, Beijing could interfere with American ports, railroads, fuel distribution or communications to delay U.S. mobilization, complicate military intervention and weaken public support for defending Taiwan.
An adversary may not need to shut down the entire country. A series of local outages, magnified by AI-generated claims that water has been poisoned or hospitals have collapsed, could create fear far beyond the actual damage. The lie might travel faster than the physical disruption.
Such attacks offer hostile governments real advantages. They can be launched from a distance, scaled up or down, routed through proxies and conducted beneath the threshold of war. Attribution may take days or weeks, giving the aggressor time to deny responsibility while exploiting the confusion.
But cyber coercion is also dangerous and unpredictable. An operation intended as a limited warning could kill civilians, contaminate water, shut down a hospital or trigger a larger American response. Once unleashed against interconnected infrastructure, consequences may be hard even for the attacker to control.
The Trump administration recognizes this danger. Its new Gold Eagle Initiative is intended to use frontier AI to identify vulnerabilities, coordinate scanning and deliver prioritized fixes across government and critical infrastructure. AI can indeed help defenders detect suspicious activity, analyze logs and patch weaknesses faster.
But frontier AI cannot compensate for factory-default passwords, unsupported machinery or controllers left directly exposed to the internet.
America needs enforceable minimum cybersecurity standards for systems essential to life: strong authentication, network separation, secure vendor access, tested offline backups and rapid incident reporting. Small utilities need regional or state-supported cyber-defense centers rather than facing foreign intelligence services alone. Every critical facility also needs tested fallback procedures, including manual operation where feasible.
Will we be prepared in time? Not if cybersecurity remains voluntary, fragmented and treated as an information technology expense rather than a national defense obligation. Government must set standards, infrastructure owners must exercise responsible stewardship, and manufacturers must stop selling equipment that leaves security as someone else’s problem.
Scripture teaches that governing authority bears responsibility to restrain evil and protect the innocent (Romans 13:1-4). That duty does not end at the physical border. It extends to the digital gateways controlling the water our children drink, the power sustaining hospitals, and the communications connecting First Responders.
Just-war principles apply as well. Deliberately attacking civilian water or medical systems to frighten a population violates the duty to distinguish between combatants and innocents. Christians must also resist panic and deception; in an AI-enabled attack, protecting truth may be as important as restoring the machinery.
The next war may not announce itself with air-raid sirens. It may begin when a town employee discovers that someone half a world away has changed the password controlling the community’s pumps.
Artificial intelligence did not create America’s vulnerabilities. It is making them easier to find, exploit and multiply. The new front line may be a water tower, hospital server, or electrical substation in a community that never imagined war would reach its street.


