Skip to Content

Why US water systems are vulnerable to foreign cyberattacks

By Sean Lyngaas, CNN

(CNN) — A cyberattack on water systems in a dozen states is exposing years of under-investment in critical infrastructure and how US adversaries can threaten services that everyday Americans take for granted, according to industry experts and current and former US officials.

The cyber intrusions in some cases led to water pressure drops and flooding at facilities, according to the FBI, but did not compromise the safety of drinking water, according to state and local officials.

US officials are now asking themselves why the hackers, who struck during a scorching heat wave, didn’t go further in causing damage at the water facilities. Manipulating devices that monitor chemical dosing, for example, could have jeopardized the safety of the drinking water.

“Do we have the C team and they couldn’t do worse?” one US official said. “How bad could it be if the A team turned to the US?”

Iran is a suspect in the hacks, but US officials have not yet confirmed Tehran’s involvement.

For years, US officials have warned that sabotage-capable hacking teams from Russia, China and, to a lesser extent, Iran, were developing access to sensitive industrial networks across the US and were lying in wait for a moment of crisis to cause disruptions. The soft underbelly of American infrastructure — local water and power plants that serve military facilities, for example ­— have been targeted.

Now, water system operators in modest-sized towns and counties are at the forefront of investigation into one of the most serious cyberattacks on the sector in years. States from South Dakota to Georgia have been affected.

“It’s no secret that water utilities are under-resourced and vulnerable to cyberattacks, and it’s no secret that our adversaries know it,” said Caitlin Durkovich, a former deputy homeland security adviser in the Biden White House. “By targeting critical infrastructure, they can undermine public confidence in our leaders and impose significant costs with relatively little effort. They’ve spent years positioning themselves for exactly this kind of disruption.”

Erin Thomas, a spokesperson for the Clayton County Water Authority in central Georgia, said her team hasn’t experienced a malicious cyber incident at scale before. The water authority is investigating “unauthorized cyber activity” that may have caused a water pump station to fail, triggering a boil-water notice in the early hours of July 27.

“Our main concern when this happened was to make sure that we got the system up and running,” she told CNN on Thursday. (They accomplished that in a matter of hours on July 27).

In Rapid City, South Dakota, a “cyber incident” hit one of the lift stations that serves the city’s wastewater system, officials announced July 31.

“We’re not surprised by it,” Mike Theis, Rapid City’s public works director, when asked about the possibility of being targeted by a foreign adversary in wartime. He couldn’t recall a time when Rapid City had experienced a similar cyberattack. Theis credited the “quick action from our employees who noticed abnormal behavior” on computer systems and isolated them from the internet.

The hacking incidents have triggered federal and state policy responses. New York Gov. Kathy Hochul, a Democrat, has announced about $9 million in grants to try to strengthen the cyber defenses of water systems across New York.

Democratic Sen. Adam Schiff of California plans to introduce legislation next week that would give the Environmental Protection Agency’s greater authorities to help boost water cyber defenses, Schiff’s spokesperson told CNN.

Coupled with national security concerns is a deep frustration among water-sector specialists and cyber experts that there is still so much infrastructure that is directly accessible from the internet.

“For the past 20 years, experts have been telling utilities to make sure their systems were not directly accessible from the internet,” said Marty Edwards, former head of the Department of Homeland Security’s Industrial Control Systems Cyber Emergency Response Team. “This recent set of intrusions is the result of complacency and a lack of budget prioritization.”

The-CNN-Wire
™ & © 2026 Cable News Network, Inc., a Warner Bros. Discovery Company. All rights reserved.

Article Topic Follows: CNN - Politics

Jump to comments ↓

CNN Newsource

BE PART OF THE CONVERSATION

KION 46 is committed to providing a forum for civil and constructive conversation.

Please keep your comments respectful and relevant. You can review our Community Guidelines by clicking here

If you would like to share a story idea, please submit it here.