How Trump Left America Vulnerable to Cyberattacks
Context
During her January 2025 confirmation hearing to be secretary of homeland security, Kristi Noem was asked how she would strengthen the nation’s cyberdefenses. Noem told senators that she would make the department’s Cybersecurity and Infrastructure Security Agency “smaller” and “more nimble.” President Trump had created CISA as a stand-alone agency within the Department of Homeland Security during his first term to give cybersecurity more institutional heft, and it had grown quickly with support from lawmakers of both parties. But after CISA declared the 2020 presidential election to be “the most secure in American history” and the agency’s director, Christopher Krebs, refused to back Trump’s claims that the vote had been stolen, Krebs became a target for the president’s fury and a seething grudge.. During the DOGE fever of the first few months of Trump’s return, CISA’s budget was reduced and its staff cut by one-third. The agency hasn’t had a permanent, Senate-confirmed director since Trump retook office. In April, the White House proposed deeper cuts to CISA’s budget, but Republican lawmakers have raised concerns that critical U.S. infrastructure is already too vulnerable. In June, Noem’s replacement, Markwayne Mullin, reversed course. He told lawmakers during a DHS budget hearing that he wants to add 600 positions at CISA. The agency has scheduled new hiring expos, and Acting Director Nicholas Andersen says that he’s “ruthlessly prioritizing” critical cyberdefense roles. But the United States is now nearly six months into a war with Iran, an aggressive and capable cyber foe—and preparations for the midterm elections are under way, with far less intelligence from CISA about foreign and domestic threats. Hackers with suspected ties to Iran targeted U.S. water and wastewater systems late last month in more than a dozen states. In Braham, Minnesota, the attacks temporarily shut down the water system. The town was one of more than 30 systems that were targeted, state officials said, describing the attacks as the most extensive they’ve seen. The Trump administration has not confirmed Iran’s purported role in the water-system hacks or said how many states or utility systems have been affected—or whether there have been other breaches. Three port facilities in North Carolina reported disruptions to operations from cyberattacks two weeks ago, although authorities haven’t linked the incidents to a specific actor. But CISA, the FBI, and the EPA warned last month that Iran-affiliated hackers are attempting to exploit vulnerabilities in U.S. systems. Cybersecurity experts told us that hacking attempts could spread as the midterms approach and hostilities with Tehran enter what Trump has characterized as a more low-key phase aimed at squeezing the Iranian economy. Iran may respond by going after U.S. infrastructure. DHS did not respond to a request for comment. Despite the elevated threat from Iran, the Trump administration continues to focus its attention on questioning the integrity of U.S. elections. The president and Andersen have each met recently with election deniers who have spent years attacking the officials who carry out the democratic process and calling for votes to be counted by hand. The administration has halted federal intelligence briefings for state officials responsible for overseeing the vote, and it has ended funding for an information-sharing network. Federal employees who worked to combat foreign disinformation within CISA were put on leave, and DHS hired Heather Honey, a conservative activist who’d tried to help overturn Trump’s 2020 defeat, to oversee election integrity. The administration is investigating the 2020 elections in Georgia and Arizona, and demanding access to data about voters—and Mullin has threatened to throw election officials in prison if they don’t comply. [Read: Arizona is now at the center of election investigations] The administration’s stances are deepening distrust and straining relations with state and local election officials, especially those who are Democrats. Although the ability of foreign attackers to change election results remains low, given the decentralization of the system, former CISA officials told us, the broader goal of hackers would be to undermine confidence in democratic institutions and the integrity of U.S. elections. But that’s what the president and his allies are already doing as they continue to make false or unproven claims about rampant voter fraud. State officials worry that if a foreign hack actually happens, the administration will use the incident as a justification to press for more federal control. CISA was meant to provide nonpartisan, technical expertise and function like the Transportation Security Administration or the Secret Service. It has no regulatory authority, so it relies on the trust of state and local officials who want its support and advice. But the hope that it would float above politics was damaged after the 2020 presidential election. Republican lawmakers erupted at the Biden administration’s attempts to enlist CISA against foreign misinformation campaigns, accusing the administration of “weaponizing” the agency to pressure social-media companies and censor conservative speech. Today, it’s mostly Democratic officials who are wary of the agency. Half a dozen Democratic secretaries of state, along with some of their staff members, told us that they no longer look to CISA as a reliable partner to help safeguard their election-related systems. They have tried to replace the role of the agency by sharing information with one another and enlisting the help of private contractors, state and local law enforcement, state homeland-security departments and National Guard, emergency-management agencies, and nonprofit organizations (including one filled with ex-CISA officials). But no other entity can replace the extensive intelligence gathering and threat analysis that the federal government performs by drawing on its web of agencies and cyber units, experts told us. It took years for CISA to earn the trust of state and local election officials, some of whom had been suspicious of the agency during its early days but came to appreciate its help in responding to cyber threats, limiting damage, and even assessing buildings for vulnerabilities in an era shaped by political violence. Krebs, now an independent consultant, was singled out by the White House in an April 2025 presidential memorandum titled “Addressing Risks From Chris Krebs and Government Censorship” that claimed that he’d “falsely and baselessly denied that the 2020 election was rigged and stolen, including by inappropriately and categorically dismissing widespread election malfeasance and serious vulnerabilities with voting machines.” The attacks on water systems may be a warm-up. Krebs told us that cyberattackers target utilities that are in some way connected to the internet. Many smaller water systems with fewer employees lack expertise but may have a greater need to perform remote operations that require connectivity. During previous attacks on water utilities, hackers sought out systems with poor password security, which allowed them to disrupt operations until the interference was detected. Krebs said that these weaknesses are a result of a wider, lackluster approach to cyber risks, but he added that it’s unfair for Trump officials to tell local governments that it’s solely their responsibility to fend off the attacks. The U.S. bombing campaign in Iran has hit bridges, desalination plants, and power stations, and Trump has threatened to wipe out the rest of the country’s physical infrastructure. Although Iran can’t retaliate from the air, it can try to hit back online. “If you’re gonna go start a shooting war with someone that we know has capabilities, you have a responsibility to work with state and local partners and give them a hand,” Krebs said. “You can’t have a geopolitical conflict on a global level that’s going to manifest at the local level and not do anything in between.” Jen Easterly, who ran CISA during the Biden administration, told us that water systems and other U.S. utilities were created to maximize efficiency and reliability, not security. “They have a lot of inherent weaknesses, but I don’t think these small towns and municipalities should have to defend themselves from the Iranian government,” she said. AI models are making it easier for hackers to find vulnerabilities and exploit these systems, she said: “The threats are moving faster and the risks are more dangerous than ever.” Most of the voting equipment used in U.S. elections is not connected to the internet and produces paper ballots as a backup against manipulated tallies. It is the other, online elements of the electoral process that remain most vulnerable, including voter-registration systems and state and local election websites that report results. If hackers can inflict outages or make abrupt changes by hacking those sites, they can damage public confidence. [Read: The forever negotiation] Adrian Fontes, a Democrat who serves as secretary of state in Arizona, told us that he remains skeptical of CISA and the administration it reports to. “They cut off all support for us; they’ve threatened to investigate us, they’ve continued to promote falsehoods against election officials across the country,” he said. “And that’s not the posture that an ally would take. That’s what an adversary would do.” One day after the United States struck Iran’s nuclear capabilities last summer, a suspected pro-Iranian intruder gained access to the Arizona secretary of state’s server and websites. The cyberattacker defaced websites displaying election results dating to 2016 and replaced candidate photos with images of a late Iranian ayatollah. State staff scrambled to limit the damage and alerted state-government officials. But given CISA’s new direction and staff, Fontes did not directly tell the agency as he would have previously. Instead, his office asked state homeland-security officials to connect with CISA—but without identifying the office that was affected. “I don’t trust them,” Fontes told us at the time, adding that he had lost confidence that the agency was collaborating in good faith. Some state election officials told us that they fear that any information they share with CISA about cyber intrusions, weaknesses, or threats could be used against them as evidence of malfeasance or wrongdoing. They watched that scenario unfold when Trump blamed Minnesota Governor Tim Walz, a Democrat, for cyberattacks on his state’s water utilities, not Iran, the suspected culprit. “The strange thing is, after this water incident and others, I don’t have to worry about state and nonstate malicious actors,” Walz told us. “I have to worry about this administration.” One election official in a battleground state told us that he had received a threat briefing in April from major technology companies that said that, based on their intelligence, they have a “high degree of confidence that Iran is going to attempt to disrupt the general election this year.” The state official said that he wasn’t surprised by the information but that he was baffled when a CISA official reached out a few weeks ago, after Trump’s prime-time address questioning the legitimacy of the 2020 election, for the first time in many months to let him know that CISA “would like to come back and help.” He remains skeptical. Andersen, CISA’s acting director, faced sharp questioning from Democratic secretaries of state when he appeared on a video call with them on Monday, twirling a pen and sipping an energy drink, according to people on the call. They asked him why they should trust the agency, whether CISA would resume offering them intelligence briefings, and whether it would restart penetration testing of their systems (another service that they said had gone dormant) before the November election. Andersen sidestepped some of the questions, gave noncommittal responses to others, and said that government shutdowns had affected various services. He also told the group that some of the services for election officials might resume in 2027, those on the call said. Minnesota Secretary of State Steve Simon, a Democrat, told us that he got the impression that CISA is “mostly writing off the 2026 election cycle” when it comes to direct services for states. “They kind of seemed resigned to looking forward to the next election cycle and not this one,” Simon said. Several secretaries of state said that although they hope the federal government will restore the services before the November election, it is late in the cycle for CISA to help in any meaningful way.
What it means
Causal chain
No clear market signal
How to read a signal
- Severity
- the event's market impact, 1–5
- Direction
- ↑ / ↓ likely price move for the asset
- Exp. move
- the size of the abnormal move we'd expect if the call plays out — not a claim a move will happen:Most flagged events don't move beyond noise; those count against us (see the track record).Ssmall<1%Mmoderate1–5%Llarge>5%
- Timeframe
- the window we measure over:1dshort5dmedium21dlong
- Conviction
- how well-established the directional call is (textbook → speculative) — not a guaranteed outcome:lowaveragestrong
Get the next signal the moment it breaks.
The full live feed, asset filters, and alerts — free.
Sign up free →Not investment advice · for informational purposes only. Generated 2h ago