Foreign hackers are increasingly targeting the United States' drinking water and wastewater systems, a shift that senior Environmental Protection Agency officials warn could disrupt the daily lives of millions of Americans. The EPA has identified more than 900 cybersecurity vulnerabilities at water systems across the country since 2025, many of them surprisingly basic, including failure to change passwords, lack of multi-factor authentication, and critical system information left easily accessible online.
«Our everyday life completely crumbles without access to drinking water and wastewater infrastructure,» said Jess Kramer, EPA Assistant Administrator for Water. «Everything from hospitals to daycares, everything that we care about and need on an everyday basis can be impacted» if a cyberattack succeeds. Kramer said attacks on the water sector have increased several-fold in recent years, ranging from simple password failures to system specifics being available online.
The threat has already materialized in several incidents. In July, a coordinated cyberattack targeted more than 30 community water systems across Minnesota, disrupting technology used to remotely monitor and control equipment. More recently, Colorado officials disclosed that foreign actors breached two small water utilities and manipulated equipment used to control drinking water systems. Drinking water remained safe in both cases, but the incidents underscored growing concern over the vulnerability of critical infrastructure.
EPA Assistant Administrator for Enforcement and Compliance Assurance Jeff Hall said water utilities have become attractive targets because many operate aging infrastructure while lacking resources to modernize their cybersecurity. «We will see water systems left vulnerable to cyberattacks where there have not been significant amounts of investment in cybersecurity protocols,» Hall said, pointing to missing basic protections such as virtual private networks and firewalls.
Hall explained that hackers have «moved from ransomware attacks designed to extort payments from critical infrastructure generally to more specific attacks designed to disrupt critical infrastructure and particularly water and wastewater systems.» Attackers are increasingly «manipulating the human-machine interface to change critical settings which disrupts the service and also puts people at risk,» he added.
Unlike data breaches that expose personal information or ransomware attacks intended to extract payment, successful intrusions into water systems can interfere with services that underpin nearly every aspect of daily life — from hospitals and schools to manufacturing, emergency services, and businesses. National security officials are concerned about the vulnerability of such critical civilian infrastructure.
Workforce shortages have compounded the challenge, making it harder for many utilities to recruit and retain employees with the expertise needed to defend increasingly complex networks. The EPA and its law enforcement partners have issued advisories about vulnerabilities involving programmable logic controllers, or PLCs, and other industrial control systems that operate pumps, valves, and other critical equipment inside water facilities.
«There are aging infrastructure that is embedded in these drinking water systems,» Hall said. «It's often left open to the open internet and not protected by any specific firewalls or virtual private networks that would ensure that cyber attackers cannot easily manipulate those.» Hall said the agency remains concerned about a range of adversaries, including state-affiliated actors, hacktivist networks, and insider threats.
Despite the growing threat, both officials said utilities are making progress by addressing many of the most common weaknesses. Kramer acknowledged it is difficult to measure national progress because the EPA does not have authority to require every water system to report cyber incidents. Still, she said the agency has observed clear evidence that attackers are becoming more sophisticated as utilities work to improve their defenses.
EPA inspectors review cybersecurity planning at larger drinking water systems, while the agency's Office of Water provides technical assistance, training, and one-on-one support to help utilities identify and remediate vulnerabilities before they can be exploited. The officials stressed that continued investment in basic protections and workforce development is essential to protecting the nation's water supply from an evolving threat landscape.