Key Takeaways
- In July 2024 a coordinated cyber‑intrusion hit municipal water facilities in at least a dozen U.S. states, causing pressure drops and precautionary boil‑water advisories but no confirmed contamination.
- The attacks echo a 2023 campaign by Iran‑linked CyberAv3ngers that exploited default passwords on programmable logic controllers (PLCs).
- CISA’s response has been limited to basic hygiene advice (multifactor authentication, strong passwords, password audits) that many utilities have not implemented, hampered by recent budget and staffing cuts.
- The water sector’s decentralized structure—roughly 148,000 mostly small, siloed systems—creates both a barrier to widespread catastrophe and a challenge for uniform defense.
- Legislative proposals such as the Water Risk and Resilience Organization Act (H.R. 7922/H.R. 2594) and the Water Cyber Shield Act of 2026 seek to give EPA authority to set and enforce cybersecurity standards, but face political and judicial obstacles.
- Some states (New York, Indiana, Maryland) already mandate cyber‑vulnerability assessments, while others experiment with bans on internet‑connected controls, cyber‑incentive funds, or private‑sector partnerships.
- Philanthropic‑driven initiatives like DEF CON Franklin and the emerging Water Watch Center demonstrate that expert volunteers and managed security service providers can fill gaps, though scaling to national coverage remains uncertain.
- Ultimately, experts agree that higher, enforceable standards are needed, but disagreement persists over who should set them—federal agencies, independent bodies, or market‑driven solutions—leaving the nation’s water infrastructure vulnerable to future attacks.
Recent Cyber Attacks on U.S. Water Facilities
On July 30, 2024 the FBI, the Environmental Protection Agency (EPA), and the Cybersecurity and Infrastructure Security Agency (CISA) issued a joint statement confirming that “malicious cyber actors” had successfully infiltrated municipal water facilities in at least seven states; the tally has since risen to a dozen. The intrusions caused pressure drops in several systems, prompting precautionary boil‑water advisories, but no reports of contaminated water emerged. Analysts described the campaign as a relentless series of low‑level breaches—akin to “cyber mosquitoes”—rather than a catastrophic “cyber Pearl Harbor.” Nonetheless, the events highlighted a glaring weakness in the nation’s water‑sector defenses and raised urgent questions about federal preparedness.
Impact and Immediate Consequences of the Attacks
Although the attacks did not produce toxic water, the physiological risk remains real: a loss of pressure can enable backflow of groundwater, sewage, or soil contaminants into drinking‑water lines. In Clayton County, Georgia, a pressure dip was detected and corrected before any harm occurred, illustrating how quickly a seemingly minor anomaly can escalate. The incidents forced utilities to issue boil‑water notices, erode public trust, and divert operational resources toward emergency response. Even without direct health impacts, the disruption underscores that cyber threats to water infrastructure can impose significant social and economic costs.
Historical Context and Prior Warnings (CyberAv3ngers, 2023 Incident)
The July 2024 campaign bears striking resemblance to a 2023 operation by the Iran‑linked hacking group CyberAv3ngers. That earlier intrusion broke into water‑utility controllers in Aliquippa, Pennsylvania, using nothing more than default factory passwords. In response, CISA issued an advisory urging utilities to implement multifactor authentication, adopt strong, unique passwords, and audit PLCs for default or absent credentials. The guidance was deliberately basic, reflecting the fundamentals of modern cybersecurity hygiene. Yet three years later, the same simplistic exploits succeeded again, indicating that many utilities failed to heed the earlier warnings.
CISA’s Response and Limitations (budget, staffing, guidance)
CISA, tasked with leading the nation’s cyber defense and coordinating incident response, appeared ill‑equipped to stop the repeat attacks. Its 2023 reply consisted largely of the common‑sense password advice mentioned above, which many small utilities did not follow. Compounding the problem, Congress cut CISA’s budget by $135 million for the current fiscal year (the administration had sought a $495 million reduction), and the agency now employs roughly 1,000 fewer staff than it did in early 2025. Tatyana Bolton of the Operational Technology Cybersecurity Coalition acknowledged that while funding shortfalls matter, the deeper issue lies in the absence of baseline controls and standards across the water sector—a gap CISA alone cannot fill given its dispersed mandate.
Structural Challenges of Water Sector (decentralization, small utilities)
The United States operates about 148,000 public water systems, the vast majority of which are small, independently run entities. Roughly 85 percent serve communities of fewer than 50,000 people, yet those systems collectively supply less than 10 percent of the national population. This fragmentation creates a double‑edged sword: a single hacker cannot easily contaminate the entire national supply, but a compromised system serving tens of thousands can still cause widespread disruption. Larger metros benefit from economies of scale, affording dedicated OT security teams and redundant controls, whereas many rural utilities operate with only three‑person staffs, leaving them especially exposed to sophisticated foreign campaigns like the one attributed to Iran.
Legislative Proposals: Water Risk and Resilience Organization Act and Water Cyber Shield Act
In response to the vulnerability, lawmakers have introduced competing bills. The Water Risk and Resilience Organization Establishment Act (H.R. 7922, later revised as H.R. 2594) would create an EPA‑certified independent body to devise and enforce minimum cybersecurity standards for midsize and large utilities, explicitly excluding systems serving fewer than 3,300 users—the very entities most often hit. Meanwhile, the Water Cyber Shield Act of 2026, sponsored by Senators Adam Schiff and Amy Klobuchar, aims to amend the Safe Drinking Water Act and Clean Water Act to grant the EPA explicit authority to conduct cybersecurity assessments, enforce corrective actions, and set standards alongside CISA. The bill would authorize $300 million annually for utility upgrades. Although Democratic sponsorship makes passage unlikely in the current Congress, supporters argue the measure could advance through appropriations or gain traction if Klobuchar wins the Minnesota gubernatorial race.
Judicial and Regulatory Obstacles (EPA authority blocked, state-level actions)
Efforts to empower the EPA have previously encountered judicial roadblocks. In 2023 the Eighth Circuit blocked an EPA rule that would have required states to evaluate water utilities’ cybersecurity operational technology during routine inspections; the court found the agency had skipped the required notice‑and‑comment process. Faced with a pair of Supreme Court decisions curbing its authority, the EPA withdrew the regulation. Despite this federal impasse, several states have moved ahead: New York, Indiana, and Maryland mandate cyber‑vulnerability assessments for water systems, with New York’s regime viewed as a national benchmark. Notably, none of those states issued boil‑water notices during the July 2024 attacks, suggesting that state‑level rigor can mitigate risk.
Alternative Approaches: State Initiatives, Philanthropic Efforts (DEF CON Franklin, Water Watch Center)
Beyond legislation, innovative experiments are underway. Texas, for example, prohibits utilities from connecting control systems to the internet and has created a “Cyber Command” to hunt weaknesses and coordinate responses. Idaho relies on a grant program that rewards projects incorporating “cyber‑informed design” from inception. Perhaps the most conspicuous private‑sector initiative is DEF CON Franklin, spearheaded by former acting Principal Deputy National Cyber Director Jake Braun. The program pairs volunteer white‑hat hackers with small water utilities to patch vulnerabilities and teach basic hygiene. Recognizing scalability limits, Braun recently unveiled the Water Watch Center—a collaboration between DEF CON Franklin, the National Rural Water Association, and five cybersecurity firms—to deliver managed security‑service‑provider (MSSP) support to utilities serving under 10,000 people. He envisions expanding the model to cover FEMA regions and eventually the entire country, potentially funded by federal sources or even the Department of Defense, given the national‑security implications of foreign cyber‑threats to water.
Conclusion: Need for Coordinated Action and Ongoing Gaps
The July 2024 cyber incursions reveal that the United States’ water infrastructure remains inadequately defended against determined foreign actors. While experts converge on the need for higher, enforceable cybersecurity standards, disagreement persists over who should author and police those rules—federal agencies like EPA and CISA, independent expert bodies, or market‑driven solutions. Legislative proposals languish amid partisan stalemates and judicial constraints, state‑level efforts show promise but are uneven, and philanthropic pilots demonstrate both the ingenuity and the scaling challenges of private‑sector involvement. Until a cohesive, resourced strategy emerges—combining clear federal authority, adequate funding, standardized baseline controls, and support for the myriad small utilities that dot the national landscape—the nation’s water supply will remain vulnerable to the next wave of cyber mosquitoes, whose cumulative sting could one day swell into a far more dangerous threat.

