‘;
document.currentScript.insertAdjacentHTML(“beforebegin”, banner);
let giftListenerCb = function (e) {
let date = new Date(e.detail.expiration_date);
let formatted = date.toLocaleDateString(“en-US”, {
month: “long”,
day: “numeric”,
year: “numeric”,
});
document.querySelector(“.article__gift-banner-exp”).textContent = formatted;
document.querySelector(“.article__gift-banner”).hidden = false;
window.removeEventListener(“hasValidGiftLink”, giftListenerCb);
};
window.addEventListener(“hasValidGiftLink”, giftListenerCb);
}
On July 30, the FBI, Environmental Protection Agency, and Cybersecurity and Infrastructure Security Agency issued a joint statement confirming that “malicious cyber actors” had successfully infiltrated municipal water facilities in at least seven states, a count that has since grown to a dozen, forcing many of them offline. The attacks were inconsequential in one sense—there were no reports of contaminated water, though some systems suffered pressure drops and issued precautionary boil-water advisories. James Wilson, co-host of the Srsly Risky Bizpodcast, likened the attacks to an “endless amount of cyber mosquitoes,” as opposed to a “cyber Pearl Harbor.”
But the coordinated attacks also underscored the vulnerability of the United States’ water facilities, prompting some obvious questions as to what the federal government has been doing, is presently doing, and perhaps should be doing. Water is critical to life, after all. Shouldn’t its security be a top, if not the top, priority? The United States hasn’t necessarily experienced a water cybersecuritydisaster, but worst-case scenarios are more tangible than hypothetical. We’ve had water treatment failures, chemical imbalances brought on by malfunction, E. coli contamination, and the people of Flint, Michigan, of course, appreciate the criticality of clean water better than anyone in the country.
With respect to this recent attack, experts’ fears nearly played out in Clayton County, Georgia, when a pressure drop was noted but quickly addressed. The water that flows through the pipes to us is made safe in part by physics—a pressure loss can lead to backflow of groundwater, sewage, and soil contaminants.
The attack echoed a previous campaign by CyberAv3ngers, an arm of Iran’s Revolutionary Guard, which has led to a working presumption that Iran was responsible. President Donald Trump, to his continued discredit, blamed Minnesota Gov. Tim Walz. In 2023, the CyberAv3ngers group broke into water utility controllers in Aliquippa, Pennsylvania, with only default factory passwords, leading CISA to issue an advisory with fundamental remedial steps:
• Implement multifactor authentication
• Use strong, unique passwords
• Check [Programmable Logic Controllers] for default or no passwords
If this familiar-looking advice seems like the barest minimum in modern cybersecurity hygiene, that’s because it is. Three years later, the U.S. is at war with Iran, who it appears again simply strolled through dozens of still-unlocked front doors.
CISA, the agency charged with the mandate of leading the nation’s collective defense against cyber threats and coordinating national incident responses, appears unprepared to meet this moment. The sum total of its response to the 2023 threat was to provide some common-sense IT advice, which promptly went unfollowed in many quarters. Underfunded, understaffed state utilities can’t be the first line of defense against coordinated cyberattacks by hostile foreign actors, right?
One could point to CISA’s reduced budget and staffing as a possible weak spot: Congress cut CISA’s budget by $135 million this year (Trump wanted a $495 million cut), and there are 1,000 fewer workers at CISA than there were in early 2025.
I asked Tatyana Bolton, executive director at the Operational Technology Cybersecurity Coalition, what part budget and staffing cuts might have played in the recent attacks, and she downplayed the significance, pointing to an array of other factors, such as an absence of baseline controls and standards in the water infrastructure sector, unlike the energy and finance sectors. Bolton, who was at CISA from 2017–20, noted that CISA is chronically underfunded and spread too thin to meet its mandate, but that acting Director Nick Andersen is focusing on the right things. She maintains that the problems for water security are broader than CISA has the capacity to handle. But she agreed that July’s dozens-fold repeat of the 2023 attack pointed to a failure to implement and audit CISA’s earlier guidance—guidance that, again, merely amounted to “Set better passwords.”
Naturally, water presents particular security challenges that the other infrastructure sectors don’t have to wrestle with, beginning with the fact that there are approximately 148,000 relatively siloed public water systems in the United States, many running different operational technologies. Our water system’s decentralized, fragmented nature, perhaps a bit like our electoral system, is a double-edged sword, inasmuch as its vulnerabilities are atomized—at least a single hacker can’t contaminate all the water in the country. That said, one hacker can wreak no small amount of havoc, as one compromised water system might serve tens of thousands of people. Iran, of course, sent a team.
A huge wrinkle is that larger cities and metro areas benefit from economies of scale that help insulate them: they can afford dedicated OT security staff and redundant control systems. Many communities, though, are served by water facilities staffed by only three people. Roughly 85 percent of water systems serve communities of fewer than 50,000, communities that together comprise less than 10 percent of the entire U.S. population. Still, both Plymouth, Minnesota (population 80,000), and Clayton County, Georgia (serving 300,000), were victims. Although rural communities require a disproportionate amount of attention, they’re not the only communities that are vulnerable.
If a holistic solution isn’t coming from CISA, where then? House bill H.R. 7922, introduced in 2024 by Reps. Rick Crawford, an Arkansas Republican, and John Duarte, a California Republican, called the Water Risk and Resilience Organization Establishment Act, would create an independent organization, certified by the EPA, to develop and enforce minimum cybersecurity standards for large and midsize utilities, essentially deputizing the experts to come up with solutions. One obvious blind spot is that it would exclude water facilities that serve fewer than 3,300 people, the communities least prepared, that indeed wereamong those likely targeted this time around. A slightly revised version (H.R. 2594) has been stalled in committee since April 2025.
In response to the attacks, Democratic Sens. Adam Schiff and Amy Klobuchar recently proposed the Water Cyber Shield Act of 2026, which would amend the Safe Drinking Water Act and Clean Water Act to give the EPA explicit authority to perform cybersecurity assessments, enforce corrective measures, and establish security standards alongside CISA. The bill would authorize $300 million annually to help utilities pay for much-needed upgrades. In a call, a spokesperson from Schiff’s office characterized the bill to me as giving the EPA the tools to impose a “floor” in terms of standards all water utilities serving more than 3,300 people would need to follow. “I’m also continuing to push for strong federal, state, and local coordination to immediately investigate and stop these cyberattacks, as well as for updated technology to secure our critical infrastructure,” Klobuchar said in a statement to Slate. The Democratic bill seems unlikely to pass for the obvious reason that the Democrats are out of power, though Schiff’s camp suggested it could be passed through appropriations. Klobuchar’s co-sponsorship of the bill makes sense given that Minnesota was the primary target of the recent attacks, perhaps giving her an opportunity to implement something similar there if she’s elected governor in November. “As Governor, I’ll work to ensure that our public infrastructure and services are protected from cyber threats,” her statement read.
It’s worth noting that the bill would empower the EPA to enforce safety standards only three years after the 8th Circuit blocked the agency from doing exactly that. Attorneys general from Iowa, Arkansas, and Missouri had sought an injunction against the EPA to stop them from ordering states to evaluate their water utilities’ cybersecurity operational technology when they conducted inspections. The court agreed, finding that this modest, common-sense measure failed to complete the notice-and-comment dance, and the EPA, already reeling from a pair of Supreme Courtlosses limiting its authority, quietly withdrew the regulation.
Despite the anti-regulatory headwinds in D.C., states like New York, Indiana, and Maryland all mandate cybersecurity vulnerability assessments for their water systems. New York’s regime is considered the national benchmark by the people I spoke with, and is relatively similar to what Schiff and Klobuchar are proposing nationally. It’s a small sample size, but none of these states were issuing boil-water notices last month.
Other states have been active as well, with wildly different approaches. From Leigh Ramsey at Bluefield Research I learned about Texas outright prohibiting utilities from connecting to the internet, and establishing a “Cyber Command” to identify weaknesses and coordinate responses. Idaho has no dedicated water cybersecurity mandate, but created a fund that rewards projects that build in “cyber-informed design principles” from the start.
Braun’s brainchild ran into frustrating scalability problems, which led him to an even more ambitious idea: outsourcing the problem, as a small business might, to managed security service providers, which detect and respond to threats on behalf of water utilities serving fewer than 10,000 people. Only a week ago Braun unveiled the Water Watch Center, a joint effort between DEF CON Franklin and the National Rural Water Association, along with five cybersecurity firms already familiar with the water sector. Braun told me that managed security service providers offer a two-way benefit: it helps his project get over the scalability hump by pooling resources, while the small utilities benefit from a shared information environment.
Braun is already thinking bigger with plans to graduate from managed security service providers in five Federal Emergency Management Agency sectors to 10, which would cover the entire country, and service utilities for communities as large as 150,000. He’s well aware that philanthropy wouldn’t cover such a step up, which is why he believes the project could one day be funded by the federal government. His idea sounds less wild when you recall that we’re really talking about small communities being targeted by hostile foreign actors, leading Braun to reason that the Department of Defense could possibly fund his effort. Braun’s team is already working on an ambitious Defense Advanced Research Projects Agency–funded project to test how A.I. solutions might be deployed in defense of water systems.
One can’t help but admire Braun’s effort, but his project’s existence is also a damning commentary on the federal government’s ability and willingness to protect its citizens from foreign threats. The energy and desire to address what everyone agrees is a gaping hole in our security infrastructure is there, but energy and desire are often no match for inertia and stagnation, which is the unfortunate reality when a particular threat falls short of a disaster measured in lives.
Here, the goals are the same but the methods are scattershot: There’s the top-down regulatory approach relying on the EPA, there’s the independent committee approach favored by an acronym soup of trade groups whom the EPA certifies to figure it out, and finally Jake Braun’s small-business approach of attempting to fix the problem from outside the government and then asking the government to foot the bill if it wants to scale fully up. The different approaches don’t feel that far apart, or mutually exclusive even. Everyone agrees there should be higher standards—they merely differ on who gets to set them. Until someone or something wins out, though, states, utilities, and elected officials remain unprepared for the worst.
