DNYUZ
No Result
View All Result
DNYUZ
No Result
View All Result
DNYUZ
Home News

Hacks on U.S. Water Supply Follow Years of Warnings and Neglect

August 5, 2026
in News
Hacks on U.S. Water Supply Follow Years of Warnings and Neglect

In 2023, the Environmental Protection Agency under the Biden administration proposed creating stronger cybersecurity guidelines to better safeguard the nation’s water supply from hackers.

The steps were modest, but necessary, officials said at the time: Many municipalities lacked even basic protections, and the computers that monitor and adjust water quality, including chemical-treatment levels, were easy-to-find targets for a would-be intruder.

The E.P.A. rescinded the order, however, after Republican-led states and industry groups sued to block its enforcement. They argued that the E.P.A. lacked authority for the move and that smaller, underfunded utilities would struggle to adopt the new standards.

The episode is just one of several in recent years in which efforts to bolster the cyberdefenses of America’s water systems were blocked despite repeated attacks that highlighted vulnerabilities. Just a little more than a month after the E.P.A. proposal was killed, a small town in western Pennsylvania disclosed that a hacking group tied to Iran’s Islamic Revolutionary Guards Corps briefly took control of equipment used to adjust water pressure.

Now federal and state officials are racing to address an alarming, widespread assault on the nation’s water supply that they believe is also probably the work of Iranian hackers.

Last week, at least seven states, including Minnesota and Michigan, reported incidents to the F.B.I., and in some cases the hacks — or the response to them — degraded water operations. The tally of states reporting possible attacks to the F.B.I. is now at least a dozen, according to people familiar with the investigation. The F.B.I. has not disclosed the states publicly, but some have come forward to confirm activity.

At least 100 municipalities have detected recent malicious hacking efforts related to their water systems, though some of those may be unrelated incidents, the people said. Some security experts said the number of vulnerable systems nationwide could be far higher.

There are no indications so far that any water system has been corrupted in a way that rendered drinking water unsafe. But the attacks have led to disruptions that required manual overrides and boil-water advisories issued out of an abundance of caution.

Clayton County, Ga., experienced a water service disruption on July 27, local officials disclosed this week. The county, which is part of the Atlanta metropolitan area, said that it believed the incident was the result of “unauthorized cyberactivity” and that it witnessed reduced water pressure, issued a precautionary boil-water advisory and restored services within hours.

“It is very unusual for us to experience a system outage without a water main break,” Erin Thomas, a spokeswoman for the Clayton County Water Authority, said in an interview. “We are still investigating what happened, but something happened.”

A spokesman for Rapid City, S.D., said that the city had also recently addressed a “cyberincident” involving a lift station, or a specialized pump, in its wastewater system and was working with federal partners on the investigation. The water supply “remains safe and protected,” said the spokesman, Darrell Shoemaker. He declined to say when the disruption occurred or if it was related to the current wave of attacks.

Officials and experts said the breadth of hacking activity could be far larger than what is currently known. There are about 150,000 public water systems in the country, according to the E.P.A. Many are small and have minimal cybersecurity measures in place.

Some municipalities may not report incidents to state leaders, let alone the federal government. Congress passed a law in 2022 that requires water facilities and other critical infrastructure operators to report significant hacks within 72 hours. But implementation of that law has been repeatedly delayed.

Iran-linked hackers are suspected of being responsible, according to U.S. officials and state and local officials briefed by federal authorities on the investigation, but that assessment is preliminary.

Officials and experts warn that as the U.S. war against Iran stretches on, Tehran could take more sinister actions if it feels it has little to lose. (President Trump on Friday dismissed the notion Iran was responsible for the attacks on water systems and instead blamed Tim Walz, the Democratic governor of Minnesota, for the attacks there.)

“We are facing a reckoning of the consequences of ignoring the importance of investing in our nation’s cybersecurity for our critical infrastructure,” Tatyana Bolton, the executive director of the Operational Technology Cybersecurity Coalition, said in a public letter Friday.

The group, which represents security firms that specialize in securing systems like those in the water attacks, called for a series of swift congressional actions, including more funding for state and local governments to bolster digital protections.

Ms. Bolton, a former U.S. cybersecurity policy official and Navy veteran who also worked at Google, noted years of warnings about Chinese and Iranian hackers burrowing deep inside computer networks of critical infrastructure to be able to unleash disruptive or destructive attacks at a later date.

“To date, we have been lucky that a more catastrophic incident hasn’t occurred,” Ms. Bolton said. “We can no longer rely on luck.”

The Trump administration released a national cybersecurity strategy in March that identified protecting critical infrastructure networks as a priority, but said little about the precise mechanics for how to do so beyond securing supply chains from foreign-built technology that could pose risks.

“We will deny our adversaries initial access, and in the event of an incident, we must be able to recover quickly,” the strategy said about securing water utilities, the energy grid and other key infrastructure.

For all the fears about artificial intelligence models posing a grave risk to global cybersecurity, the efforts to compromise America’s water supply have been relatively rudimentary, according to former officials, experts and the government’s public advisories. The hackers are targeting computers that are readily accessible on the internet and insecure because of weak or default login credentials.

U.S. intelligence and cybersecurity agencies have been worried about Iranian hackers targeting water systems and other critical infrastructure in the United States for years. More than a decade ago, Iranian hackers targeted a small dam in upstate New York, but by happenstance the dam’s sluice-gate controls had been taken offline for maintenance, much to the relief of U.S. authorities at the time. The Justice Department later indicted Iranian nationals it said were behind the breach.

Concerns have grown since the war against Iran began in late February. In April, the Cybersecurity and Infrastructure Security Agency and other federal agencies issued a public alert “urgently warning” that Iranian-affiliated hackers were targeting computers in critical infrastructure networks, including water, energy and government services.

The cybersecurity agency, which has endured steep staffing cuts and a pared-back mission during the second Trump administration, updated that advisory in late July with additional technical guidance about the attack. Among other steps, the agency urged water systems operators to take their remote controllers off the internet.

Of particular note was a disclosure that the hackers had figured out a way to disable safety features that sound alarms or force a shutdown in the event of a serious problem. Operators could be looking at computer screens that say everything is fine when, in reality, something is very wrong.

Just four days later, the intensified hacking campaign against water utilities began. Some cybersecurity experts believe the hackers saw the alert and began racing to compromise as many systems as possible before new safety measures were in place.

“If nothing else, it’s one hell of a coincidence,” said Joe Slowik, the director of threat research at Dataminr, a risk-intelligence cybersecurity company. “There was a shift, like, ‘Oh, we have been spotted,’ or something that prompted rapid change.”

China and Russia, which have generally had more sophisticated cyberoperations, have for years carried out large-scale espionage campaigns against the United States and penetrated some of America’s most sensitive infrastructure. But Iran’s hackers are widely seen as less predictable.

Whether the goal of the water attacks is to try to harm Americans or merely scare them remains unclear.

“The campaign felt a lot like pre-attack staging, not the attack itself,” said Joshua Corman, a critical infrastructure resilience and public safety expert at the Institute for Security and Technology, a California-based think tank. “The level of access is sufficient for significantly more harm than has been seen.”

Ernesto Londoño contributed reporting from St. Paul, Minn.

The post Hacks on U.S. Water Supply Follow Years of Warnings and Neglect appeared first on New York Times.

Nominations for Business Insider’s Rising Stars of Wall Street list are now open
News

Nominations for Business Insider’s Rising Stars of Wall Street list are now open

by Business Insider
August 5, 2026

Business Insider is seeking nominations for its Rising Stars of Wall Street list. Ricardo Santos for BIBusiness Insider is putting ...

Read more
News

New Mexico Sues Trump Administration to Get Unredacted Epstein Documents

August 5, 2026
News

LIV Golf players to become majority owners after mystery investor steps in to keep league afloat

August 5, 2026
News

AI Influencers Are Heading Into Uncharted Territory

August 5, 2026
News

Trump-endorsed candidate loses to Michigan man who dropped out of race

August 5, 2026
Jeanine Pirro doles out $25K bonuses as prosecutors try to quit and Trump rages: report

Jeanine Pirro doles out $25K bonuses as prosecutors try to quit and Trump rages: report

August 5, 2026
The Quest to Extend Human Life

The Quest to Extend Human Life

August 5, 2026
Wait—The Theme for Your Party Is What, Exactly?

Wait—The Theme for Your Party Is What, Exactly?

August 5, 2026

DNYUZ © 2026

No Result
View All Result

DNYUZ © 2026