Skip to main content
Threat IntelligenceEmerging Threats

US Water Systems Face Growing Cyber Threats

Municipal water treatment plant with industrial controls and operator at panel.

"Cyber actors from China, Russia, Iran, North Korea, and ransomware groups . . .  pose critical threats to U.S. networks and critical infrastructure," the 2026 Annual Threat Assessment warns — a line that frames this summer's attacks on water systems and the policy debate that followed.

Iranian hackers' summer attacks on water systems in 12 states

The summer’s cyberattacks by Iranian hackers on water systems in 12 states made visible what experts have long said was a latent risk: water infrastructure can be targeted by foreign adversaries with effects comparable to a nationwide public‑health crisis. Federal agencies including the EPA, the FBI, and CISA issued immediate guidance after the intrusions, recommending steps such as disconnecting operational technology from the internet where feasible and adopting stronger password practices.

About 80% of U.S. water systems lack basic cyber hygiene

Technical weaknesses are stark. The piece reports that roughly 80% of U.S. water systems lack even basic cyber hygiene — a shortfall the summer attackers exploited. Even among systems that serve most Americans — approximately 450 large and 4,500 medium-sized water systems — advanced cybersecurity practices widely used in aviation, rail, medical devices, finance and nuclear power have not been broadly adopted. The software base that controls many utilities remains vulnerable, and advances in artificial intelligence have accelerated the pace at which vulnerabilities can be found and exploited: the authors cite AI models, including Anthropic’s Claude Mythos, that have demonstrated the ability to identify thousands of zero‑day vulnerabilities and to "plan, test, and execute attacks in rapid cycles," in timeframes ranging from minutes down to seconds.

EPA's limited authority and the withdrawn 2023 memo

Legal constraints complicate a federal response. The Environmental Protection Agency does not possess clear statutory authority to impose broad cybersecurity requirements on water systems. In 2023 the EPA issued a memo interpreting existing regulations to strengthen cybersecurity but faced widespread opposition and formal legal challenges and ultimately withdrew the memo. The agency retains limited authorities: it can require water systems to complete risk and resilience assessments, maintain emergency response plans, and, in emergencies, address critical cybersecurity flaws.

A five-part federal program: zero‑trust, formal methods, and targeted funding

The authors propose a five‑part federal program aimed at closing the gap. Central technical recommendations include mandatory adoption of zero‑trust architecture — network segmentation and strict authentication that would limit lateral movement after an intrusion — and wider use of formal methods to reduce exploitable software flaws, including memory‑safe languages, mathematical proofs for critical software, and secure microkernels. The piece notes that many industrial control vendors that supply water utilities — including Siemens, Schneider, and Rockwell Automation — have the capacity to develop more secure code, and that commercial AI tools from firms such as Google and CrowdStrike can assist with "code mending" to identify and repair vulnerabilities.

On the policy side, Congress is urged to require large water systems to adopt zero‑trust and formal methods, phased in over time, and to provide tax credits to offset costs. A separate federal program would provide technical and financial assistance to midsize systems through federally funded cohorts and regional teams. For the smallest utilities — about 45,000 systems that serve 3,300 people or fewer — the authors recommend creating a voluntary, state‑led cybersecurity corps, modeled after the National Guard, to supply training, secure remote‑access services, or on‑site staffing; the Texas pilot program, pairing the federal government, the state, and private companies, is cited as a possible model.

What this means for large water systems, midsize utilities, and small systems

  • Large water systems: Would face mandatory standards under the authors' proposal — zero‑trust, code‑mending, and formal methods — with a phased compliance window and proposed tax credits to defray implementation.
  • Midsize municipal utilities: Could rely on a federal program that supplies technical expertise and regional teams to adopt zero‑trust and code‑repair tools, with longer phase‑in periods than for large utilities.
  • Small systems serving 3,300 people or fewer: Would largely remain outside current regulatory reach and need either staffed in‑person operations or secure remote‑access managed by trained personnel; the voluntary cybersecurity corps (state‑led, federally funded) is the recommended path to bridge resource gaps.

The authors underscore two hard realities that have slowed change: the cost and complexity of stronger defenses, and the fragmented structure of the water sector — roughly 49,000 systems serve about half the population through a relatively small number of large systems, while the remaining roughly 49,000 systems serve the rest, with the smallest systems serving about 7% of the population. Lawmakers have begun to respond: Sens. Amy Klobuchar and Adam Schiff introduced the Water Safety Shield Act, which would require tiered cybersecurity standards and dedicate a proposed $600 million annually to water cybersecurity. The administration has launched a pilot with Texas and private firms to scan and remediate vulnerabilities at no cost to utilities.

The record laid out in this analysis is blunt: well‑known technical fixes exist and commercial vendors and AI tools can help deploy them, but legal limits and a fractured sector complicate implementation. The authors — Franklin D. Kramer, Robert J. Butler, and Melanie J. Teplinsky — conclude that the administration, Congress, states and the private sector "should work together urgently" so that every American can rely on safe, clean water. Whether that cooperation produces mandatory standards, sustained funding, and scalable operational support for the smallest utilities will be the decisive test.

Read the original CyberScoop op‑ed