News Feature | August 10, 2026

Water Utilities Seek Resources To Combat Growing Cyberattack Threat

Source: Aerzen
GettyImages-1591787866_450_300

Infrastructure has increasingly become a target in nontraditional warfare, and U.S. water and wastewater utilities are more frequently falling victim to a wave of cyberattacks that seek to disrupt their operations. In the last week of July, more than 30 municipal water systems in Minnesota were targeted and, since July 27, utilities in at least a dozen states have reported the incidents to the FBI. Neither state nor federal officials have publicly attributed the malicious activity to any specific actor.

The Cybersecurity & Infrastructure Security Agency (CISA) states it has seen “significant escalation” of attacks targeting the programmable logic controllers (PLCs) used to automate and monitor pumps and other drinking and wastewater treatment functions. The hackers targeting exposed PLCs have modified passwords to lock out operators and have disconnected the PLCs by changing their IP addresses.

In some instances, utilities have reported system pressure loss or flooding as a result of the attacks. Cyberattacks on community water systems (CWS) also can disrupt the treatment, distribution, and storage of water via damage to pumps and valves, or by altering the levels of treatment chemicals to hazardous amounts. In response, some utilities have had to issue boil-water advisories and conduct sustained manual operations.

In addition to the practical risk, utilities are under threat of enforcement action from the EPA when their cybersecurity measures fail. Section 1433 of the SDWA requires systems serving more than 3,300 people to conduct Risk and Resilience Assessments (RRAs), develop Emergency Response Plans (ERPs) and certify their completion to EPA — as well as review and update both initiatives every five years. Per a 2024 EPA Enforcement Alert, “over 70% of the systems inspected by EPA since September 2023 are in violation of basic SDWA Section 1433 requirements including missing specific sections of the RRA and ERP.”

Both CISA and the FBI have issued advisories detailing measures utilities can take to protect their operations and communities, including removing publicly exposed devices from the internet and restricting network access, as well as using and regularly changing strong, unique passwords. PLC supplier Rockwell Automation also has issued an advisory acknowledging their devices are being targeted and explaining step-by-step how utilities can recover access to their PLCs.

However, the fact remains that the majority of the 50,000+ community water systems in the U.S. are small and under-resourced, combating rising operational costs and a shortage of skilled workers while struggling to update aging infrastructure — making them easy targets. The municipalities and states operating utilities shoulder most of the responsibility and expense in defending against cyberattacks; although federal allocations are available to supplement cybersecurity upgrades, they are difficult to coordinate. Such resources include direction from the EPA on how utilities can perform a cybersecurity assessment. Additionally, the National Rural Water Cybersecurity Center (NRWC) in collaboration with the SANS Institute, provides free cybersecurity training modules to members.

States beefing up cybersecurity efforts in response to the threat include New York, where Gov. Kathy Hochul announced grants of $50,000 for cybersecurity assessments and $100,000 for implementing cybersecurity upgrades at more than 150 water systems across the state. The $2.5 million initially set aside for Strengthening Essential Cybersecurity for Utilities and Resiliency Enhancements (SECURE) recently ballooned to $9 million, though the governor’s office has not directly attributed the increase to the recent attacks. Facility operators applying for the grants must “implement common cybersecurity controls” and complete regular cybersecurity training, adhering to new cybersecurity regulations imposed on New York water utilities in March.

DEF CON Franklin, meanwhile, is a volunteer initiative aimed at helping resolve these challenges. It connects public-spirited cybersecurity experts with small, rural water systems that need help fending off hackers. The volunteers’ help can consist of conference calls or meetings to share best practices and answer utilities’ questions, as well as facility visits to guide staff through specific upgrades. DEF CON Franklin matches volunteers with water utilities based on their respective levels of cybersecurity skill and availability.

To report a cyber incident, contact CISA’s 24/7 Operations Center (contact@cisa.dhs.gov), call 1-844-Say-CISA (1-844-729-2472), or call the local FBI field office. Reports should include the date, time, and location of the incident, the type of activity, how many people were affected, and the type of equipment affected. CISA’s Reporting a Cyber Incident guidance contains additional details.