Hackers targeted municipal water systems across at least seven U.S. states this week, affecting more than 30 facilities in Minnesota and other locations. In some instances, attackers altered passwords and network settings, effectively locking operators out of the computerized systems that control critical infrastructure such as pumps and valves. Although some operations were disrupted, there is no evidence that drinking water safety was compromised.
The cyberattacks have been tentatively linked to groups affiliated with Iran, highlighting a significant challenge in American cybersecurity: geopolitical threats often exploit vulnerabilities in smaller municipal systems. Many of these local communities have limited resources and minimal cybersecurity staff, leaving essential infrastructure exposed to foreign-backed cyber intrusions.
Warnings about this type of threat have been issued repeatedly by federal agencies. In April, the FBI, Cybersecurity and Infrastructure Security Agency (CISA), and the Environmental Protection Agency (EPA) released advisories cautioning about hackers targeting internet-connected industrial control devices nationwide. A July update stressed the continuation of such campaigns against critical infrastructures, including water systems, and associated the activity with Iran’s Islamic Revolutionary Guards Corps Cyber Electronic Command.
Political reactions to the attacks have included efforts by former President Donald Trump to assign blame to Minnesota and its Democratic governor, Tim Walz. However, experts emphasize that cyber threats transcend federal, state, and local boundaries, targeting the weakest defenses irrespective of jurisdiction.
The United States operates approximately 51,000 community water systems, over 90 percent of which serve fewer than 10,000 people. Many rely on outdated equipment not designed with cybersecurity risks in mind, creating an ongoing vulnerability as these systems have been connected to the internet.
During the Biden administration, CISA and the EPA worked to improve cybersecurity support for small water utilities by issuing practical guidance, offering free security assessments, and deploying regional advisers to assist local officials. Congress also established the four-year, $1 billion State and Local Cybersecurity Grant Program to help municipalities implement basic cyber defenses such as multifactor authentication and incident-response planning.
While these measures did not prevent recent breaches, officials credit them with helping to limit disruptions. Operators were able to detect anomalies, switch to manual operations, and coordinate responses alongside state and federal agencies, ensuring continued access to safe drinking water.
Despite these gains, federal support for cybersecurity efforts has weakened recently. Personnel reductions and budget cuts at CISA have occurred, and the agency remains without a Senate-confirmed director. Funding for the Multi-State Information Sharing and Analysis Center, a key provider of threat intelligence to local governments, ended last year, compelling it to charge fees for assistance. Additionally, the State and Local Cybersecurity Grant Program is approaching the end of its funding cycle, and the Cybersecurity Information Sharing Act of 2015, which facilitates voluntary threat information exchange between private companies and government, is set to expire on September 30.
Experts warn that these developments undermine the nation's defense posture against cyber threats targeting critical infrastructure. They call on the federal government to restore and increase funding for cybersecurity programs, reinstate support for information-sharing centers, and extend legislative frameworks that promote cooperation. Recommendations also include investing in the modernization of water system controls, reinforcing manual operational capabilities, and ensuring manufacturers design industrial control equipment with built-in security features.
As cyberattacks from nation-states persist, officials stress the importance of resilience: ensuring that even if attackers penetrate systems, public health is not endangered and safe drinking water continues uninterrupted.
