NOW THAT WATER SUPPLY IS UNDER ATTACK.
A follow-up to our piece on Trump baselessly blaming Governor Walz for a suspected Iranian cyberattack on Minnesota’s water systems.
Walz’s response to Trump’s accusation included a specific, checkable claim: “DOGE took an axe to CISA and left the U.S. exposed to cyber attacks.” That’s not political spin. It’s a documented, 18-month paper trail, and it’s worse in the details than a single sentence can capture.
THE DISMANTLING, STEP BY STEP
It started in earnest in late February 2025: DOGE terminated the CISA contract supporting the agency’s “red team” — the specialists whose entire job is simulating cyberattacks against government networks to find vulnerabilities before real hackers do. Former CISA penetration tester Christopher Chenoweth described it happening in real time on LinkedIn: “DOGE cut our entire red team and all support roles — over 100 people impacted. The following Wednesday, DOGE cut a second CISA red team also doing mission-critical work.” TechCrunch independently confirmed employees were cut immediately, their network access revoked with no warning — and that this was already the third known round of CISA cuts since Trump’s inauguration, following earlier cuts in January that specifically hit staff working on election security.
It didn’t stop there. The Elections Infrastructure Information Sharing and Analysis Center — which fed cyber threat intelligence directly to state and local election officials — announced its own closure after DHS pulled its funding.
THE SCALE, IN NUMBERS
By this June, Sen. Mark Warner (D-VA) confirmed CISA “has lost one-third of its workforce since the start of the Trump administration, including many seasoned career federal employees with extensive experience protecting our cyberspace and critical infrastructure.” The New York Times independently tracked the collapse: roughly 3,400 employees at the start of fiscal year 2025, down to about 2,400 by December — a 29% cut. And the administration isn’t done: the FY2027 budget proposes an additional $707 million cut, eliminating another 867 positions and gutting the National Risk Management Center’s analytical budget by more than half.
Grant Guyer, chief strategy officer at cybersecurity firm Claroty, put the practical consequence plainly: “The recent layoffs at CISA have made the cybersecurity workforce less stable, further complicating efforts to secure critical infrastructure… leaves the country more vulnerable to cyber threats.”
THIS WAS PREDICTED — IN THOSE EXACT WORDS — BEFORE IT HAPPENED
Back in May 2025, Rep. Eric Swalwell, ranking member of the House Homeland Security Subcommittee on Cybersecurity, wrote a direct warning about exactly this scenario: “If we fail to stop Musk’s rampage through the federal government, we are inviting an attack… We are going to get attacked, and Trump will be responsible.” That’s not hindsight commentary written after the Minnesota attack. That’s a documented, on-record prediction from over a year before it happened, describing this precise outcome with unsettling accuracy.
THE PART THAT MAKES TRUMP’S “INCOMPETENT MINNESOTA” LINE INDEFENSIBLE
Walz didn’t just criticize the federal cuts — he pointed out that Minnesota’s own state cybersecurity team caught and contained the suspected Iranian intrusion despite the degraded federal support structure DOGE left behind: “Thankfully, our experts in Minnesota were able to identify the vulnerability quickly and work with local communities to stop it.” Read against the documented CISA collapse — a third of its workforce gone, its red teams dismantled, its election-security staff cut before anyone else, warnings from sitting members of Congress predicting this exact scenario — the actual incompetence story here isn’t Minnesota’s. It’s the federal government’s, and it was avoidable, and multiple people said so loudly and specifically, in writing, well before an Iranian-linked attack on American water infrastructure proved them right.