Cyber warfare is increasingly coming for U.S. water supplies.
Water providers in at least seven U.S. states have been targeted by cyberattacks over the past two weeks, according to multiple agencies including the FBI, the Environmental Protection Agency (EPA), and the Cybersecurity and Infrastructure Security Agency (CISA). Some officials indicated that as many as a dozen states could have been impacted.
The hackers targeted components known as programmable logic controllers, which allow utility providers to manage the flow and even chemical composition of water supplies to the homes and businesses they serve, according to the agencies. In many cases, they “modified passwords to lock out operators and disconnected the [controllers],” CISA said in a recent advisory.
There are still no indications that the cyberattacks have caused major disruption or lasting damage to water supplies—at least some of the operators were reportedly able to switch to manual operations or use backup systems. However, CISA said that they were serious enough in some cases to have “resulted in boil water notices” to affected people.
The implications of the attacks are more severe, however. Programmable logic controllers help operators regulate the flow, distribution, and even chemical composition of the water supply. There have been a few close calls: In 2021, a hacker reportedly attempted to increase chemical levels at a Florida plant before being discovered in time, and in 2024, an attack caused a tank in Texas to overflow.
While the U.S. government has yet to officially attribute the latest attacks to a particular adversary or group, several reports as well as multiple former officials that Foreign Policy spoke to indicated that they are very likely linked to Iran. “I’m incredibly confident that these attacks are Iran,” said Cynthia Kaiser, who served as deputy assistant director of the FBI’s cyber division under former U.S. President Joe Biden. “The geopolitical motivation, capability, the recent history of targeting that sector … all of that points to Iran, and there’s not a plausible alternative.”
Hackers linked to U.S. adversaries like Iran, China, and Russia have a history of targeting U.S. critical infrastructure, with high-profile attacks such as the 2021 Colonial Pipeline hack (blamed on Russia) disrupting gas supplies to most of the U.S. East Coast. Other major hacks by operators affiliated with those countries have targeted telecommunications networks, medical providers, and food supplies.
This is also not the first time that U.S. water systems have been targeted, with both Iran and Russia linked to previous hacks of local water supplies in states such as Florida and Texas. While there have been no major disruptions linked to this month’s spate of attacks, they serve as an important reminder of how vulnerable the water sector is.
“Of the 16 sectors of critical infrastructure, it’s probably the most brittle,” said retired Gen. Paul Nakasone, who served as director of the National Security Agency and head of U.S. Cyber Command during the Biden and first Trump administrations.
Kaiser, who is now a senior executive at the cybersecurity company Halcyon, agreed. “When policymakers asked me which sectors I was worried about, I would always say water,” she said.
There are a few reasons why water systems are particularly at risk, foremost among which is the sheer number of possible infiltration points. According to the EPA, there are more than 148,000 public water systems across the United States serving homes, schools, hospitals, and other sections of the economy. “It has an incredible attack surface—there’s so many places,” said Nakasone, who now leads Vanderbilt University’s Institute of National Security. “When an adversary looks at it, it’s like: ‘Oh, my goodness, this is low-hanging fruit for us.’”
The water infrastructure in the United States is also far more decentralized than other sectors, with more than 52,000 different local water providers across the country—many of which cater to only a few hundred people each. By comparison, the country has only 3,300 electric utilities.
“The water municipalities generally just don’t have the resources,” said Rob Joyce, who served as the NSA’s cybersecurity director during the Biden administration and as cybersecurity coordinator on the National Security Council during the first Trump administration. “Most of them are small, they’re very decentralized, they’re often running technology installed by a third party, and they don’t understand the cyber implications of the technology they’re running.”
Those third-party technologies—often connected to the internet so that providers can control them remotely—end up broadening the list of targets from a single entry point, because many municipalities use the same software tools. That was the case in 2023, during the early days of the Israel-Hamas war, when an Iranian hacking group known as “CyberAv3ngers” infiltrated the Israeli company Unitronics—many of whose controllers are used in U.S. water systems. It was also the case in the current spate of attacks, with the FBI and EPA pointing to components made by the company Rockwell Automation as the source of vulnerability.
The tools that make life easier for smaller water system administrators can also make it easier for hackers, according to Kaiser. “If you’re the only person at a water utility, you want to be able to have remote access so you can remotely manage it, which makes sense, but that’s why from a convenience perspective a lot of these got connected to the internet,” she said. However, water utilities typically don’t have the kinds of firewalls or protections required to add obstacles in hackers’ path. “What would have stopped this is not being directly connected to the internet,” she added.
Complicating the matter further is the fact that enforcement authority for cybersecurity in the water sector remains unclear. In 2023, the EPA put forward a memorandum seeking to mandate cybersecurity evaluations as part of regular audits of water systems, but it withdrew that memorandum after multiple states filed lawsuits alleging that the required cybersecurity improvements would be too costly for water utilities to bear.
The recent attacks have reignited those conversations. “We’re going to need some explicit cybersecurity authority given to some regulator, whether that’s EPA or somebody who can direct the minimum cybersecurity standards,” Joyce said.
The scale and scope of the latest attacks has sparked widespread alarm and prompted a raft of moves to help shield U.S. water infrastructure from future attacks. This month, New York announced more than $9 million in cybersecurity grants to help safeguard more than 150 water systems across the state. And just this week, Democratic Sens. Adam Schiff and Amy Klobuchar introduced legislation, called the Water Shield Cyber Act, aimed at fortifying cybersecurity protections for water infrastructure across the United States.
“These threats are not hypothetical—they are happening right now,” Schiff said in a statement. “This legislation gives EPA the tools it needs to protect this critical infrastructure while providing the resources that local water and wastewater systems need to strengthen their cybersecurity without passing the cost on to ratepayers.”
The attacks have also cast a fresh spotlight on previously proposed legislation, sponsored by Republican Rep. Rick Crawford, that would authorize an independent organization to spearhead the development of cybersecurity requirements in the sector. It has won the support of the American Water Works Association, which represents around 4,300 utilities across the country and which recently sent a letter to congressional leaders to urge stronger cybersecurity measures and advocate for the bill’s passage.
Private sector volunteers are also jumping into the fray. Last week at DEF CON—a massive annual hacker conference in Las Vegas—saw the launch of a new initiative called the Water Watch Center, which will bring together cybersecurity companies and volunteer hackers to work with the National Rural Water Association to help defend smaller water utilities against foreign adversarial cyberattacks.
These attacks are coming at a time when water resources are increasingly weaponized in global conflict, with profound implications for governments around the world. Access to water isn’t just essential for clean drinking water or sanitation; these systems are also vital for health care, agricultural production, and energy infrastructure, meaning that potential disruptions to water supplies could unleash far-reaching consequences.
“Water security is really a national security problem,” said Liz Saccoccia, an expert in water security at the World Resources Institute.
Yet around the world, water-related violence has only skyrocketed in recent years, according to the Pacific Institute, a U.S.-based think tank that tracks global cases. The institute recorded 420 instances of water violence in 2024—a nearly 20 percent jump from the number of cases logged in 2023, and a 78 percent increase from cases in 2022. The majority of the 2024 cases involved attacks on water infrastructure, according to the institute.
“These cyberattacks on our utilities are part of this broader trend where civilian water infrastructure is increasingly being targeted or a casualty of conflict,” Saccoccia said. “Globally, we’re seeing dams, desalination plants, treatment facilities, pipelines being damaged or deliberately targeted during warfare.”
Even before the water cyberattacks were reported in the United States, physical attacks on water systems were a feature of the Iran war, with Tehran reportedly carrying out strikes on desalination plants in Kuwait and Bahrain, and Iran accusing the United States of hitting one of its desalination plants (the United States denied responsibility).
“You’re seeing in this war almost the normalization of targeting water infrastructure, in a way that we have not seen in recent wars,” said Caitlin Welsh, the director of the Global Food and Water Security Program at the Center for Strategic and International Studies, a Washington-based think tank. That has a “real psychological impact,” she added.
“For the most part, we just take it for granted—water is just something we turn the faucet on and it comes,” Nakasone said. And while the kind of widespread disruption from an attack like the one on Colonial Pipeline is harder to pull off because of the decentralized nature of the water system, just sowing doubt can do plenty of damage.
“What if you just have one attack that’s successful?” Nakasone said. “Even if it’s against a very small town and you have reporting that there are a number of different people that are being poisoned by the water, this is going to have a tremendous impact,” he added. “People are going to start boiling water, it’s going to get covered by everyone, there’s going to be a run on water in the stores—these are really the kind of terror attacks that [Iran] would love their cyberattackers to be able to help [with].”