Cyberattacks targeting local water systems were reported in at least seven states last week, sending federal officials on a scramble to warn utilities of the threat. The episode is a frightening reminder of the urgent need to harden critical infrastructure.
The FBI reported that hackers changed the passwords and network settings of multiple systems, preventing water operators from controlling their own equipment and resulting in pressure loss and flooding at some facilities, which can cause untreated water to enter distributional pipes.
The Cybersecurity and Infrastructure Security Agency reported that some utilities sent out boil water notices and were forced to operate their systems manually.
Federal officials have not said where the attacks occurred or who is behind them, though they have all the hallmarks of an Iranian operation. Minnesota and Michigan both publicly reported that several of their utilities were hit, and CISA recently warned that Iran has been targeting internet-connected technology that is used to operate utilities.
The intrusions prompted some unhelpful political sniping. President Donald Trump dismissed claims that Iran was behind the attacks, placing the blame on Minnesota’s government, which he called “grossly incompetent.” Minnesota Gov. Tim Walz (D) used that as an opening to attack Trump on the Iran war.
That’s a needless distraction from a serious problem: The U.S. has around 170,000 water and wastewater systems, which are increasingly automated and vulnerable to attack. Such dispersed infrastructure is a strength, in that no single attack can bring down the country’s water sector. But it’s also a weakness, as smaller utilities with aging operational and IT systems often have limited resources or technical capacity to protect themselves.
In 2024, the Government Accountability Office issued a report with recommendations for the Environmental Protection Agency, which oversees water utilities, to confront this challenge. That included a call for a national cybersecurity strategy, and the EPA responded by completing a risk assessment plan early last year. But those efforts are voluntary, and previous efforts by the federal government to force local systems to improve cybersecurity resulted in legal challenges.
Hopefully, the recent attacks jolt utilities into taking their defenses more seriously. Even a little can go a long way: The GAO found that many systems lack basic cyber hygiene, such as changing default passwords or updating operating systems. The federal government can also help streamline the overlapping government regulations that hinder utilities’ defenses.
As artificial intelligence supercharges the cyber capabilities of nefarious actors, Americans cannot afford operators to be asleep at the pump.
The post Another wake-up call on cyberthreats appeared first on Washington Post.




