1
US formally names Iran as the attacker
Possible
Resolves by Feb 1, 2027
Discussed by: The Washington Post, CBS News, Recorded Future News
A US agency moves from anonymous sourcing to a named public attribution. Triggered by forensic evidence tying the intrusions to IRGC-linked infrastructure, CISA, the FBI, or the Treasury publishes a statement or sanctions naming Iran as responsible for the water-system campaign.
2
Attack disrupts water service or safety
Unlikely
Resolves by End of 2026
Discussed by: The Record, ABC News, FBI advisories
The campaign crosses from probing to real harm. Triggered by hackers manipulating pumps, valves, or chemical dosing, a US utility reports a confirmed service outage, a boil-water notice, or a public-health incident tied to the intrusions rather than to routine equipment failure.
3
Campaign fades as espionage-grade probing
Possible
Resolves by Nov 30, 2026
Discussed by: Tenable, security researchers cited by NBC News
The intrusions stay reconnaissance, not sabotage. Triggered by the conflict cooling and hardening of exposed controllers, new state reports taper off and officials characterize the campaign as pressure and probing that never caused physical damage.
4
US retaliates and cites the water attacks
Uncertain
Resolves by May 1, 2027
Discussed by: National-security analysts quoted by Al Jazeera and CBS News
Washington answers the intrusions. Triggered by attribution and political pressure, the US announces sanctions, indictments, or offensive cyber action that explicitly names the water-system campaign as a reason.
5
Water Cyber Shield Act becomes law
Uncertain
Resolves by End of 2026
Discussed by: Sens. Adam Schiff and Amy Klobuchar, E&E News by POLITICO
The bill would give the EPA power to order utilities to fix flagged security gaps and add $300 million a year in cybersecurity funding. A similar EPA push failed in 2023 after Republican states and industry groups sued to block it, so passage is not assured even with the water intrusions as fresh evidence.