404 Media also reported this week that a former Flock government affairs manager, Jonathan Paz, said he quit in July 2025 and turned down equity and severance after learning the company had given ICE and Customs and Border Protection direct camera access through a pilot program while telling staff internally it did not work with ICE. Separately, 404 obtained a coaching guide the company gives police on how to speak to city councils, which tells officers to brief council members and city managers privately before public meetings, to come with a scripted presentation, and to shift the argument from cost to “the cost of unresolved crime.”
Cyberattacks on US water systems have hit utilities in at least 12 states, according to CBS News, up from the seven the FBI acknowledged a week earlier. Sources named Michigan, Minnesota, Georgia, New Jersey, and South Dakota. Federal investigators still suspect Iran-backed hackers but have made no formal attribution.
The Clayton County Water Authority in suburban Atlanta, which serves 300,000 people, said an intrusion last month dropped water pressure and forced a boil-water advisory, though service came back within hours. Some utilities lost remote control of their systems entirely and had operators running equipment by hand. In several cases the hackers reached pumps, valves, and pressure controls directly. Officials say drinking water has remained safe.
The July 30 alert from the FBI, EPA, and CISA told utilities to disconnect their industrial controllers from the internet and tighten passwords and firewalls. Those controllers—small computers that run physical equipment like pumps and valves—are the same equipment the CyberAv3ngers hit in 2023, a group tied to Iran’s Revolutionary Guard that got in through devices left on factory-default passwords.
IEH Corporation, a Brooklyn manufacturer that supplies electrical connectors to defense and aerospace programs, told securities regulators on Thursday that an intruder broke into a company email account, according to The Register. The disclosure came in an 8-K—the form public companies file with the Securities and Exchange Commission to report significant events.
An employee received a message from someone posing as a prospective business contact with what looked like a legitimate Microsoft file-sharing link. The page behind it was fake and captured the employee’s login, handing the attacker access to the company’s Microsoft 365 environment. IEH said the intruder could reach email, attachments, customer correspondence, purchase orders, engineering documentation, and possibly technical information covered by US export controls—material that cannot be legally shared with foreign nationals without a license.
IEH said it found the intrusion on August 4 and has not said how long the attacker was inside. It reported no evidence that data was copied out, though Microsoft 365 logging does not reliably capture theft, and nobody has attributed the attack. IEH connectors are used in the Patriot air-defense system, AMRAAM and THAAD missiles, and the Mark 48 torpedo.
Maksim Silnikau, a 40-year-old Belarusian national who built and ran the Ransom Cartel ransomware operation, was sentenced to 16 years in prison, Cyberscoop reports. Prosecutors say the group attacked at least 18 companies between 2021 and 2023.
Silnikau had been active on Russian-speaking cybercrime forums since 2005 and started recruiting for Ransom Cartel in 2021, according to the US Justice Department. He allegedly supplied the people who carried out the attacks with stolen passwords and the software to lock victims’ computers, and built a control panel for tracking break-ins, talking to victims, and haggling over payments. Targets included law firms, schools, a small medical technology startup, and multinational corporations in California, New York, and Nebraska. Some of the targets were knocked offline for months. According to DOJ, the group tried to extract at least $5.2 million.


