Water systems are ripe for cyberattacks, experts warn after suspected Iranian hacks
The number of states affected has expanded to at least a dozen, say officials familiar with the matter, with at least 30 systems affected in Minnesota alone.

In late 2022, Microsoft detected the hack of a water system in Guam that U.S. intelligence agencies in the following months determined was orchestrated by China. The idea wasn’t new. The spy agencies had long watched as Iran targeted Israeli water systems.
“That another nation state was doing it to us — that was unsettling,” recalled one former U.S. official, who, like several others interviewed for this story, spoke on the condition of anonymity because of the matter’s sensitivity.
Senior U.S. officials were concerned that such intrusions could affect military bases on Guam, but also civilian water supplies, many of which were poorly protected against hacks.
The Biden administration, alarmed by the spring 2021 ransomware attack on Colonial Pipeline, had already moved to regulate pipelines and then railroads.
Now they wanted to move on water.
In March 2023, the Environmental Protection Agency issued a memo to require that states work with local officials to spot weaknesses in water systems that hackers could exploit, and then develop plans to remediate them. Municipalities could apply for federal grants to help defray costs.
But attorneys general in three Republican-led states — Arkansas, Iowa and Missouri — sued, arguing that the memo exceeded the EPA’s authority, failed to provide for public comment and was a financial burden on small towns. The federal appeals court for that region, seen as among the most conservative, halted the rule change. The EPA withdrew it.
Late last month, a water utility in the western part of Arkansas, one of the states that sued, was hit with a cyberattack, part of a spate of intrusions into municipal water systems that U.S. spy agencies believe is the work of Iranian regime hackers. The campaign comes as a U.S.-launched war with Iran moves into its sixth month, with Tehran showing no sign of backing down.
Had the EPA rule been in place, some experts say, the Arkansas utility or others like it might have been spared.
“Shooting it down set us back,” said Gus Serino, president of I&C Secure Inc., a cybersecurity consultant on control systems, and a former engineer at the Massachusetts Water Resources Authority. “The level of effort and expense to fix these systems is not that much. It wouldn’t remove all the risk, but would certainly remove most of the low-hanging fruit.”
The number of states affected has expanded to at least a dozen, say officials familiar with the matter, with at least 30 systems affected in Minnesota alone.
Iran’s targeting of water systems, a trend that federal authorities first warned of months ago, and a history of failed efforts to boost water utility cybersecurity has lit a fire under some members of Congress.
Sen. Adam Schiff (D-California), the top Democrat on the water panel of the Environmental and Public Works Committee, unveiled a bill Monday explicitly authorizing the EPA to regulate water sector cybersecurity. The measure would enshrine in law what the agency tried to do by executive action three years ago: require water utilities to conduct cybersecurity assessments and require corrective actions when significant vulnerabilities are identified.
Days before Iran began its recent campaign of hacks into water utilities, the Senate EPW committee unanimously passed a bipartisan measure that would help rural water systems mitigate cybersecurity risk.
Industry representatives are now saying that voluntary efforts are not enough.
The largest group representing water utilities is urging passage of a bill, sponsored by Rep. Rick Crawford (R-Arkansas), that would establish an independent nongovernmental body to develop minimum cybersecurity requirements for the water sector overseen by the EPA.
“We need minimum requirements,” said Kevin Morley, federal relations manager at the American Water Works Association (AWWA). “It’s time to step up the game.”
The flurry of activity comes as the administration has slashed cyber specialists at the Department of Homeland Security and has not sought to renew funding for cybersecurity grants to states.
President Donald Trump has blamed the states for the hacks, criticizing Minnesota Gov. Tim Walz (D) for a rash of attacks there, adding that he didn’t think Iran was the culprit.
U.S. intelligence agencies are confident that Iran’s Islamic Revolutionary Guard Corps is behind the campaign, but have not made a formal attribution, in part because there is still some debate about which group within the IRGC carried out the attacks, according to two people familiar with the matter. One of the people added that there may be a reluctance to make an attribution that contradicts the president’s public remarks.
The FBI declined to comment.
The state of cybersecurity varies across the nation’s more than 150,000 water systems. Some municipalities, such as Cedar Rapids, Iowa, were largely insulated against the recent hacks because their systems are air-gapped, or not connected to the internet.
“We have had multiple people recommend we tie our system to the outside world,” said Roy Hesemann, utilities director for Cedar Rapids, whose water system serves about 135,000 people and whose state was among those that sued EPA. “I’ve been adamant going back to 9/11, knowing that people were occasionally getting hacked — no, we’re not doing it.’’
At least three states have recent laws requiring cybersecurity risk assessments for water systems: Indiana, Maryland and New York. Authorities are unaware of any water system hacks related to the recent campaign in these three states.
A political third rail
The prospect of cybersecurity regulation has been a political third rail in Congress for over a decade. A major bipartisan push to enact mandatory standards for critical infrastructure in 2010 and again in 2012 blew up in the face of fierce opposition from the industry.
Instead, voluntary frameworks and sector-specific initiatives were established, all by executive action.
Then, in May 2021, a Russian-speaking ransomware group attacked Colonial Pipeline, forcing a multiday shutdown of one the nation’s largest fuel pipelines, causing shortages on the East Coast and panic-buying of gasoline. Ransomware cyberattacks — once considered a criminal nuisance — became a matter of national security, leading then-President Joe Biden to raise the issue with Russian President Vladimir Putin at a summit in Geneva.
The pipeline scare spurred regulations on key sectors of critical infrastructure. Working with the Transportation Security Administration and the Coast Guard, the Biden administration added cyber requirements to existing authorities that mandate physical security of infrastructure.
Anne Neuberger, Biden’s deputy national security adviser, convened meetings in the White House with industry executives to share threat intelligence and drive home the need for cybersecurity not just in pipelines, but airports, ports and railroads.
“It was a pretty sobering assessment of the bad actors and their aim to potentially disrupt critical infrastructure,” said Todd Hauptli, CEO of the American Association of Airport Executives, who attended a September 2022 meeting. “It softened the ground up for those who would react instinctively against increased regulatory efforts.”
The approach, recalled then-TSA Administrator David Pekoske, was “providing a framework and then saying to the critical sector, ‘you come back to us with a plan,’” which was reviewed annually.
The pipelines balked at their initial proposed rule as overly prescriptive. But a revised rule, crafted with industry feedback, allowed more flexibility to synchronize requirements across multiple agencies.
A sign the rules are working, some experts say, is that Trump, who issued an order to slash regulations in his first month back in office, has retained the existing rules put in place by his predecessor.
Signs of a softening
But the U.S. water sector remained impervious to Biden’s rule push. In March 2023, the three states and industry representatives balked when the EPA issued the memo calling for cyber assessments to be added to periodic surveys of the physical security of water systems.
“The 2023 approach was a little bit of a one-size-fits-all, top-down, no real substantive involvement from the community as to what made sense,” said Morley, of AWWA, one of the groups that sued the EPA.
Today, there are signs of a softening.
Iran’s recent attacks, despite the relatively low level of damage inflicted, have raised the level of urgency.
On Wednesday, AWWA sent a letter urging lawmakers to create training programs, provide funding for cybersecurity, and support Crawford’s bill. It also wants the federal government to expand a program that dispatches technicians free to rural towns to help set up water systems and manage cybersecurity.
Chris Harris, CEO of the nonprofit Arkansas Rural Water Association, said his group has been trying for years to educate operators on best cybersecurity practices. After news of the breaches broke last month, his group urged members to take any internet-exposed control-switch devices offline, but he is unsure how many did so.
“A lot of people don’t take it serious until it happens to them,” Harris said. “Most people think that ‘[we’re] this little bitty 300-population town — why would Iran be concerned with us?’ They don’t realize that they’re attacking whatever they can.’’
Pranshu Verma, Aaron Schaffer and Jake Spring contributed to this report.