Skip to content
USA DAILY NEWS 24
security

Why US Water Systems Face Cyber Risk

Sixteen thousand wastewater and fifty thousand drinking water systems, most of them tiny utilities with no security staff, are the country's least defended critical infrastructure.

Why US Water Systems Face Cyber Risk
An unstaffed control room at a small-town water treatment facility, where legacy industrial panels sit beside newly networked equipment.

The United States runs roughly 50,000 community drinking water systems and about 16,000 wastewater systems, and federal agencies have documented for years that they are among the country's weakest cyber targets: more than nine in ten serve fewer than 10,000 people, and almost none employ dedicated security staff. The Environmental Protection Agency warned all 50 governors in January 2024 that attacks on water utilities were increasing in frequency and sophistication.

This explainer stays on the documented record — EPA and CISA advisories, congressional testimony, and the regulatory fight over who is responsible — rather than on threat speculation. The pattern that emerges is not sophisticated sabotage but opportunistic intrusion against industrial controls that were never designed for networked threats.

What actually happened to water utilities?

The incidents on the public record share a shape. In February 2021, an intruder remotely accessed a treatment plant in Oldsmar, Florida, and briefly changed chemical dosing settings before an operator caught it; officials later said danger to the public was low, but the case made the exposure famous. In November and December 2023, Iranian-linked actors compromised programmable controllers at multiple US water facilities using default passwords — including the Municipal Water Authority of Aliquippa, Pennsylvania, where a pump station display was defaced. CISA, the EPA, and the FBI responded with a joint advisory, and the director of national intelligence's annual threat assessment has since listed water systems among sectors targeted by state-linked intrusion sets. None of the publicly documented incidents produced contaminated drinking water; the documented harm has been disruption, emergency response costs, and lost public confidence.

Why are water utilities so exposed?

Three structural reasons recur in federal reports. First, fragmentation: water is not one system but tens of thousands of independent utilities — municipal, district, and private — with no national operator and no shared security operations center. Second, legacy equipment: industrial control systems in treatment plants were built for reliability, not security, and often run on networks reachable by remote vendors and, in documented cases, protected only by factory-default credentials. Third, money and staff: a system serving a few thousand customers has an operating budget and workforce that cannot absorb a dedicated cyber program. CISA and EPA communications since 2023 have leaned on free services — vulnerability scanning, incident response help, a 2025 water-sector initiative pairing federal analysts with utilities — precisely because the sector cannot buy its way out.

Who regulates water cybersecurity?

The answer is contested, and the fight is the story. The Clean Water Act and the Safe Drinking Water Act require utilities to conduct risk and resilience assessments under the 2018 America's Water Infrastructure Act — but assessments are self-directed, with no federal cyber standard behind them. In March 2023, the EPA tried to treat cybersecurity as part of sanitary surveys, the existing Clean Water Act inspections. Two lawsuits by a coalition of states — led by Missouri and Arkansas — and industry groups argued the agency had exceeded its authority; the EPA withdrew the approach in October 2023 and the Eighth Circuit later vacated it. Since then, responsibility has stayed distributed: EPA for water quality rules, CISA for threat information and incident help, state drinking water programs for inspections, and Congress for any funding mandate. Legislative proposals to set water cyber standards have circulated since 2024 without enactment.

AuthorityRole on the recordLimit
EPADrinking water and clean water rules; risk assessment requirementsNo binding federal cyber standard
CISAAdvisories, scanning, incident response, 2025 water initiativeAssistance is voluntary
StatesSanitary surveys, utility oversightStandards vary widely
UtilitiesSelf-directed risk and resilience assessments (AWIA 2018)No dedicated staff at small systems

Related stories: Space Force and the Orbital Traffic Jam · How DHS Security Grants Reach Cities.

What can a utility actually do?

Federal advisories converge on the same short list, scaled to what a small utility can execute. Inventory the industrial control network and remove any remote-access path that does not need to exist; change default credentials on every programmable controller — the exact weakness the 2023 advisory exploited; segment operational networks from office and internet connections; back up control logic and water-quality records so operations can be rebuilt manually; and establish a relationship with CISA before an incident, since free vulnerability scanning and incident response are standing offers rather than emergency services. None of this requires new regulation or large budgets, which is why agencies have distributed it in plain-language checklists rather than rules. The structural limits remain: a utility with one operator cannot run a security program the way a city government can, and no checklist addresses the vendor relationships through which documented intrusions have arrived. The practical assessment running through federal guidance is that the sector's improvement path is incremental hygiene applied at scale, not any single technical fix.

What does the documented timeline look like?

Laying the record out in sequence shows the escalation pattern regulators keep reacting to. In February 2021, the Oldsmar, Florida intrusion made remote access to treatment controls a public issue. In March 2023, the EPA proposed treating cybersecurity as part of routine Clean Water Act sanitary surveys. In October 2023, facing lawsuits from a state coalition led by Missouri and Arkansas, the agency withdrew the approach. In late 2023, the Iranian-linked intrusions hit multiple utilities using default credentials, and CISA, EPA, and the FBI issued their joint advisory; the Municipal Water Authority of Aliquippa, Pennsylvania, became the named public case in December. In January 2024, the EPA warned all 50 governors in writing that disinformation and intrusion attempts against water systems were rising. Through 2025, the response shifted to voluntary capacity: expanded CISA vulnerability scanning for water utilities, joint EPA-CISA technical assistance, and congressional proposals to fund sector cybersecurity that had not been enacted as of early 2026. The sequence — incident, attempted rule, litigation, voluntary program — is the cycle this sector has run twice, and the reason its governance question remains open.

What does this change?

The water fight previews how all US critical-infrastructure cyber regulation will be decided: by litigation over agency authority rather than by a single national standard. The markers to watch are whether Congress writes water-specific requirements into the next water-resources bill, whether the 2025 joint CISA-EPA sector initiative measurably reduces documented intrusions, and whether another high-visibility incident forces the regulatory question again. Until one of those moves, the documented baseline stands: tens of thousands of locally run utilities, voluntary federal help, and an open legal question about who can require anything at all.

Frequently Asked Questions

Has a cyberattack ever contaminated US drinking water?
Not in any publicly documented incident. The 2021 Oldsmar, Florida intrusion changed chemical settings briefly before an operator caught it, and officials said the public faced little danger. Documented consequences of water-sector intrusions through recent years have been operational disruption and response costs, not contaminated water — a fact federal advisories state plainly.
Who is responsible for water utility cybersecurity?
No single regulator owns it. The EPA sets water quality rules and requires self-directed risk assessments under the 2018 America's Water Infrastructure Act. CISA provides voluntary threat information, scanning, and incident response. State programs run inspections. A 2023 EPA attempt to make cybersecurity part of routine inspections was withdrawn after state-led lawsuits and vacated by the Eighth Circuit.
Why do small water utilities struggle with cyber defense?
More than 90 percent of US community water systems serve fewer than 10,000 people. They operate on thin budgets with few technical staff, run legacy industrial controls designed before network security existed, and have no national operator to share defenses. Federal agencies offer free scanning and incident help because the sector cannot fund private security operations.
What did the 2023 Iranian-linked water attacks do?
According to the joint CISA-EPA-FBI advisory issued in late 2023, actors linked to Iran's Islamic Revolutionary Guard Corps compromised programmable controllers at multiple US water facilities using default passwords, defacing at least one pump station display in Pennsylvania. The attacks caused operational disruption and required manual operation at some sites, and prompted the EPA's warning letter to governors in January 2024.