American Water Facilities Targeted by Hackers, Advanced Weapons Useless
Water is not merely a basic necessity but has also become one of the most vulnerable points in modern conflict. The United States is now experiencing that bitter reality. Since the Roman era, water infrastructure has been used as a target to cripple adversaries. In the conflict between the United States and Iran, the threat to water facilities has resurfaced. President Donald Trump once threatened to destroy Iran’s desalination facilities, which are a lifeline for the country’s southern region. That threat has now turned back against the United States.
According to The Economist, this summer a number of water and wastewater treatment facilities in at least seven US states were infiltrated by hackers. In Minnesota, 30 community water systems were reported affected, while authorities in Georgia asked 300,000 customers to boil their water after a disruption caused water pressure to drop. Initial assessments by US officials point to a group affiliated with Iran as the perpetrator of the attacks.
Around 90% of water utilities in the US are owned by local governments and most serve fewer than 10,000 people. Their small scale means not all facilities have the same resources to update systems or strengthen cybersecurity. Many of the computer systems in use are also old. Operational systems that connect digital networks to physical facilities are still connected to the internet, including via cellular networks, while some use weak credentials.
The situation differs from the electricity sector. Electricity infrastructure has cybersecurity standards overseen by the Federal Energy Regulatory Commission (FERC), whereas the water sector has no similar requirements. This means the vulnerability is not always in overly sophisticated technology. Basic systems connecting computers to physical facilities can serve as entry points.
The threat to US water facilities is not new. In 2013, hackers linked to Iran gained access to the control system of a small dam in New York. A decade later, in 2023, a hacker took over a pump at a water facility in Pennsylvania. Another case occurred in Oldsmar, Florida, in 2021, when a hacker attempted to raise the level of sodium hydroxide in the water. The attempt failed, but the facility’s system was breached because the operator’s computer used TeamViewer. There was also a case in Kansas in 2019 when a former employee of a water facility used his old credentials to re-enter the system.
The US government has tried several times to tighten cybersecurity in the water sector. During Joe Biden’s administration, the Environmental Protection Agency (EPA) sought to require states to review and report cyber threats to water systems. However, the policy was challenged by several Republican state attorneys general along with the American Water Works Association (AWWA) and the National Rural Water Association (NRWA). After a federal court issued a stay, the EPA ultimately withdrew its effort.
Congress has also passed rules requiring the reporting of cyberattacks on critical infrastructure. However, the implementing regulations for the Cyber Incident Reporting for Critical Infrastructure Act, passed in 2022, are only scheduled to be completed in September.
Pressure on the government and water operators has prompted new initiatives. Senators Amy Klobuchar and Adam Schiff introduced the Water Cyber Shield Act. Meanwhile, DEF CON Franklin, together with the National Rural Water Association, launched the Water Watch Centre to help small water utilities. The American Water Works Association also supports the Water Risk and Resilience Organisation Establishment Act sponsored by Rick Crawford. Tom Cotton proposed to Treasury Secretary Scott Bessent that cybersecurity investment be encouraged through changes to tax policy and regulation.
Amid these needs, the direction of the US government budget has drawn particular attention. President Donald Trump proposed a 44% increase in the Department of War budget to US$1.5 trillion, which includes funding for the war with Iran and the Golden Dome missile defence system. At the same time, the government proposed cutting nearly 90% of the EPA’s largest funding source for water system cybersecurity.
This contrast is one of the main problems. Water infrastructure may not look like a defence system or strategic technology, but disruption to it can directly affect the basic needs of society. For the US, the challenge now is not only confronting who is trying to hack water systems. The more difficult problem is ensuring that thousands of facilities of varying size, budget, and technology have adequate digital defences.