Key Takeaways
- Water and wastewater systems are high‑value targets for foreign‑government hackers because they provide essential services yet often run outdated, poorly secured industrial control systems.
- Repeated warnings since 2016—including EPA advisories, the Cyberspace Solarium Commission report, and joint alerts from EPA, FBI, CISA, and NSA—have highlighted the sector’s weak cybersecurity posture.
- Recent attacks on Minnesota utilities and similar incidents in other states followed a pattern linked to Iranian‑affiliated groups (e.g., CyberAV3ngers), exploiting default passwords and internet‑exposed programmable logic controllers (PLCs).
- President Trump publicly dismissed the Iranian connection, attributing the breaches to state incompetence, despite consensus among intelligence and cybersecurity agencies.
- Mitigating the threat requires concrete, low‑cost actions: isolating PLCs from the internet, enforcing strong passwords and multifactor authentication, continuous vulnerability scanning, updating equipment, training staff, and providing federal funding to small utilities.
History of Warnings
Concerns about cyber threats to water infrastructure are not new. As early as 2016, experts warned that adversaries could disrupt drinking‑water and wastewater services. The issue resurfaced in 2022, and in 2020 Congress’ Cyberspace Solarium Commission concluded that “water utilities remain largely ill‑prepared to defend their networks from cyber‑enabled disruption.” The EPA responded by issuing cybersecurity best practices in 2023, updating them in 2024, but these guidelines remained voluntary. A 2023 EPA attempt to mandate cybersecurity evaluations during state inspections was blocked by Missouri, Arkansas, and Iowa, who argued the agency lacked authority under the Safe Drinking Water Act, prompting the EPA to withdraw the proposal. In March 2024, then‑EPA Administrator Michael Regan and White House National Security Advisor Jake Sullivan wrote to all 50‑state governors urging them to adopt preventive plans, emphasizing that water systems are lifeline infrastructure often lacking resources for rigorous cybersecurity. By 2024 the EPA reported that 70 % of federally inspected utilities failed to meet necessary cybersecurity standards, underscoring the persistent gap between warning and action.
How the Attacks Occurred
The confirmed Minnesota cyberattacks primarily targeted the technology used to remotely monitor and control water system equipment, especially programmable logic controllers (PLCs). PLCs are small computers that manage pumps, valves, and treatment processes; when exposed to the internet they become convenient entry points for attackers. Many of these intrusions appear to be supply‑chain compromises: hackers infiltrate a third‑party vendor—such as a remote‑monitoring service or PLC manufacturer—and then use that trusted connection to reach multiple utilities. In 2023‑2024 the Iranian hacker group CyberAV3ngers demonstrated this technique by attacking PLCs across several U.S. water systems. A troubling common factor was the failure to change default passwords that shipped with the equipment; those passwords are publicly known and easily exploitable. Although the July 2024 Minnesota incidents have not been definitively attributed to Iranian actors, researchers note that the tactics, techniques, and procedures match earlier Iranian‑linked campaigns, suggesting a continuation of the same threat pattern.
President Trump Weighs In
Despite the weight of technical evidence and intelligence assessments pointing to Iranian‑backed hackers, former President Donald Trump offered a contradictory explanation. He asserted that “Minnesota is behind it… the governor’s behind it” and claimed the state’s alleged incompetence, not a foreign cyberattack, caused the disruptions. This statement contradicts findings from the FBI, CISA, NSA, and EPA, which identified indicators consistent with Iranian state‑affiliated activity. Trump’s remarks illustrate how political narratives can diverge from expert consensus, potentially complicating public understanding and delaying unified responses to critical‑infrastructure threats.
How to Fix the Problem
Addressing the vulnerability of water systems requires a combination of technical, procedural, and resource‑based measures. First, utilities should remove direct internet exposure of industrial control systems, placing PLCs behind firewalls or using air‑gapped networks where feasible. Second, strong, unique passwords must replace default credentials; password policies should enforce complexity and regular rotation. Third, multifactor authentication (MFA) should be mandatory for any remote access to control networks. Fourth, continuous vulnerability scanning and real‑time monitoring can detect anomalous activity before it escalates. Fifth, aging equipment should be retired or upgraded, and software must be kept current with security patches supplied by vendors. Sixth, regular cybersecurity training for operators and IT staff builds a culture of vigilance and ensures personnel know how to respond to incidents. Finally, Congress and federal agencies should increase funding streams—such as grants from the EPA’s Water Infrastructure Finance and Innovation Act (WIFIA) or the Cybersecurity and Infrastructure Security Agency’s (CISA) State and Local Cybersecurity Grant Program—to help small and rural utilities afford these improvements. Implementing these steps, many of which are low‑cost and straightforward, would significantly reduce the likelihood of successful cyberattacks on the nation’s water supply.
Conclusion
The recurring cyber intrusions against water utilities underscore a sobering reality: critical infrastructure remains an attractive, yet insufficiently protected, target for nation‑state actors. Historical warnings have consistently highlighted the sector’s lack of preparedness, while recent attacks reveal concrete exploitation pathways such as internet‑exposed PLCs and default passwords. Political rhetoric that dismisses these threats can undermine coordinated defenses, but the technical community agrees on actionable remedies. By isolating control systems, enforcing robust authentication, maintaining up‑to‑date defenses, training staff, and securing adequate financial support, the United States can close the gaps that adversaries have long exploited and safeguard the essential service of clean water for all citizens.

