In 2023, the Environmental Protection Agency (EPA) under the Biden administration proposed enhanced cybersecurity guidelines aimed at protecting the United States’ water supply from cyberattacks. The initiative sought to address the widespread lack of basic cyber defenses in municipal water systems, where computerized controls manage critical operations such as chemical treatment and water pressure. However, the EPA withdrew the proposal after facing legal challenges from Republican-led states and industry groups. Opponents argued that the EPA lacked the authority to enforce such measures and expressed concerns that smaller, underfunded utilities would face significant hurdles in implementing the new standards.

The repeal of these guidelines came just weeks before a small municipality in western Pennsylvania revealed that a hacking group linked to Iran’s Islamic Revolutionary Guards Corps had taken control of equipment controlling water pressure. This incident was among several that have raised alarms about vulnerabilities in the nation’s water infrastructure. In recent weeks, at least seven states—including Minnesota and Michigan—reported cyber incidents involving water systems to the FBI. Some of these incidents caused operational disruptions or prompted precautionary water quality advisories.

According to officials familiar with the ongoing investigation, at least a dozen states have reported incidents to federal authorities, with the total number of affected municipalities possibly exceeding 100. While the FBI has not publicly named the states involved, some jurisdictions have acknowledged the activity. Security experts warn that the actual number of compromised or vulnerable water systems nationwide could be significantly higher.

No evidence currently indicates that any water systems’ environments have been maliciously altered to make drinking water unsafe. Nonetheless, the incidents have caused disruptions necessitating manual overrides and led some communities to issue boil-water advisories as a safety precaution. One recent example occurred in Clayton County, Georgia—a suburb of the Atlanta metropolitan area—where officials disclosed a water service disruption on July 27 that they attributed to what they described as an “unauthorized” access event.

Federal and state authorities are actively working to strengthen defenses in response to the wave of cyber intrusions, which they believe are likely linked to Iranian-backed hacking groups. These developments follow years of concerns about the resilience of the nation’s water infrastructure amid rising cyber threats and underscore ongoing debates over federal authority and regulatory actions to protect critical public utilities.