Iran’s Water Signal: Measuring What a Non-Event Could Become
Programmes

Iran’s Water Signal: Measuring What a Non-Event Could Become

Between July 26 and 31, 2026, hackers took manual control away from water and wastewater utilities across U.S. states, Minnesota, Michigan, New Jersey, Georgia, and South Dakota among them, with more than 30 community systems hit in Minnesota alone. According to news, cyberattacks on U.S. water systems are suspected to be linked to Iran-backed hackers. Operators in Georgia's Clayton County Water Authority, serving 300,000 people near Atlanta, watched pressure drop and had to issue a boil-water advisory before service was restored within hours. In several cases, the hackers gained remote access to pumps, valves, and water pressure, though the cyberattacks have had no impact on drinking water, which has remained safe.   A hacking front calling itself CyberAv3ngers, an Iranian Revolutionary Guard Corps-linked group sanctioned by the US Treasury Department in February 2024, has since claimed the operation on Telegram, framing it as a warning rather than an attack: "our intention in attacking Minnesota was only to warn" of its abilities and its intention to retaliate against any country that poses a threat to Iran. That framing matters as it leaves us questioning whether an “actual” attack can take place.
The Collapse of Trust in the Digital State
Programmes

The Collapse of Trust in the Digital State

For decades, the systems that governments, banks, universities, and public institutions built to verify who someone is rested on a single foundational assumption that personal information, documents, and physical characteristics were difficult to convincingly fake. A Social Security number combined with a date of birth and a driver's license was, for most practical purposes, enough to establish identity.   That assumption has now been broken. The US recorded its highest number of data breaches in 2025 since tracking began, identity theft reports to the Federal Trade Commission rose nearly 20% year over year, and global fraud losses now exceed $534 billion annually. Generative AI, the same technology powering productivity tools and creative applications across the economy, has become a force multiplier for those seeking to deceive digital systems at scale. The speed, sophistication, and accessibility of these tools mean that the problem is no longer confined to the margins of financial crime. It has moved to the centre of a broader question about whether the digital infrastructure modern states depend on to function is as reliable as they have assumed.