Cyberattacks on water facilities test US defenses, reveal gaps
Over two days in late July, water supply managers from Georgia to South Dakota saw their screens go dark and their controls go haywire.
Hackers gained access to dozens of water utilities around the country, according to state and federal officials.
They infiltrated computer systems, seizing control of equipment that prevents flooding and tap water contamination for hundreds of thousands of Americans. The FBI confirmed July 30 that cyber attackers hit water and wastewater utility companies in seven states.
The bureau did not comment on the actors behind the attacks. Early investigations indicate that U.S. officials believe Iran may be responsible, according to media reports.
For those familiar with America’s cybersecurity vulnerabilities, the attacks were not a surprise.
The country’s critical infrastructure, particularly water providers in rural areas, has long been vulnerable to cyberattacks. Foreign adversaries have attacked before, but federal and some state authorities have been slow to equip these utilities with the resources and training they need to protect themselves.
Why We Wrote This
A spate of cyberattacks on water utilities across the United States last month were resolved quickly. Yet the incidents underscore weaknesses, particularly in small or rural towns with fewer resources to protect infrastructure. Some trade groups are calling for minimum cybersecurity requirements.
In one sense, the water utility cyberattacks highlight improvements in America’s cybersecurity defenses. The warnings arrived quickly and no serious damage was done. At the same time, the volume of successful attacks illustrates the vulnerabilities that remain and could be expanding.
“Utilities were able to notice the attack quickly, take action quickly, and there were no dire consequences,” says Cynthia Finley, director of regulatory affairs at the National Association of Clean Water Agencies, a lobbying group.
But, she adds, “we’re concerned about more sophisticated cyberattacks.
… It will be a constant challenge to keep up with the evolving threat.”
Locked out of computer systems
Four days before the attacks began, seven federal agencies updated a cybersecurity advisory raising alarms about “ongoing Iranian-affiliated cyber targeting” of “U.
S. critical infrastructure sectors.” The advisory cautioned that hackers were trying to access internet-connected devices controlling equipment used by that critical infrastructure. According to a separate advisory by the FBI following the late-July attacks, hackers accessed those devices remotely and then changed IP addresses and passwords, effectively locking the utilities out of their own computer systems.
“Operational effects reported to the FBI have included loss of pressure and flooding,” the agency said. “Pressure loss in water systems could potentially allow untreated ground water to seep into pipes.”
The FBI did not respond to questions, referring only to that statement.
According to reports, water utilities in at least 12 states were hacked – a larger number than the FBI has confirmed – including more than 30 in Minnesota.
For Karleen Kos – CEO of the Minnesota Municipal Utilities Association, a trade group – the attacks caused a variety of issues.
Some operators stopped being able to see what was happening in their water systems; some lost automated control over some equipment and had to switch to manual controls; for others, some controls began acting oddly, like a caps lock command getting stuck on a keyboard.
“People started to notice anomalies that didn’t make sense, so they shut the equipment down, rebooted it, and did something to correct what they were seeing,” she says.
Nobody’s drinking water was threatened, she adds. Other utilities in the state took manual control of equipment they could no longer control through computer systems.
The U.S. has had other near misses. In 2024, several small Texas towns had their water utilities targeted by Russia-linked hackers, including one town where hackers caused a water storage tank to overflow for nearly 45 minutes. In 2013, Iranian hackers took control of a small dam 20 miles north of New York City.
While the hackers gained access to the dam’s computer systems, they were unable to move its sluice gates.
Smaller utilities targeted
The cyberattacks last month were broader in their geographical scope than past hacks but still relatively low-tech, according to experts.
The hackers seem to have successfully targeted specific, internet-connected equipment that also had weak password protection.
“These were opportunistic [attacks], which is in keeping with what we’ve seen [from] Iran,” says Tahira Mammen, an AI security expert at the RAND Corporation.
Other recent cyberattacks on U.S. water infrastructure have largely fit the same profile and have targeted smaller utilities that are understaffed and underfunded.
Water infrastructure in general has only recently been computerized, so operators are often inexperienced in basic cybersecurity practices.
Many smaller utilities can’t afford to hire dedicated cybersecurity teams. Federally-funded training and improvements on this front are all voluntary, and many smaller utilities don’t know they exist or don’t have the resources to access them. Nearly 90% of public water utilities in the U.
S. serve fewer than 10,000 people, according to a National Conference of State Legislatures report in 2022.
Some water industry groups are now pushing Congress to enact minimum cybersecurity requirements.
On Aug. 5, the American Water Works Association sent a letter to congressional leaders calling on lawmakers to pass a number of bills related to cybersecurity funding for water utilities.
The same day, the head of the National Association of Water Companies issued a similar statement, adding that “the absence of uniform cybersecurity standards leaves too many systems vulnerable.”
Some organizations oppose such requirements, however, especially given the pace at which cyber threats are evolving.
Congress and the Environmental Protection Agency should prioritize increasing education and funding for programs that already exist, says Ms. Finley at NACWA.
That “is a more practical solution than regulatory requirements, which will take years to develop,” she adds.
Cuts to federal cyber defense department
Amid this changing landscape, America’s leading cyber defense department, which works to protect U.S. infrastructure, has been getting downsized and defunded by the Trump administration.
The Cybersecurity and Infrastructure Security Agency has lost roughly one-third of its workforce, about 1,000 employees, since January 2025 through a combination of layoffs, buyouts, and early retirements.
The administration’s 2027 budget proposes a $707 million cut to the agency. The cuts “eliminat[e] weaponization and waste,” the White House says in the budget. The agency has not had a permanent director since President Donald Trump returned to the White House.
That turmoil didn’t prevent the agency from responding effectively to July’s major cyberattack on U.S. water infrastructure, and cyber experts are optimistic that the half-dozen agencies overseeing the country’s cyber defense are able to protect its critical infrastructure.
“We’re in a moment of strong investment in cybersecurity,” through other federal and private investment, says Ms. Mammen, who previously served as head of the NSA’s Artificial Intelligence Security Center. “We have the technology to be in front of the problem, we just need to apply the technology appropriately.