Senior Environmental Protection Agency officials warned that cyberattacks on American water systems have surged several-fold in recent years, with foreign hackers shifting from financial ransomware to deliberate infrastructure disruption designed to cripple essential services that millions of Americans depend on daily.
Attacks Designed to Disrupt Daily Life
EPA Assistant Administrator for Water Jess Kramer told reporters that everyday life completely crumbles when drinking water and wastewater systems face successful attacks. The agency has identified more than 900 cybersecurity vulnerabilities at water systems nationwide since 2025, with hackers increasingly manipulating equipment controls to change critical settings that disrupt service and endanger public safety. Unlike data breaches or ransom demands, these intrusions threaten infrastructure supporting hospitals, schools, manufacturing, emergency services and businesses across the country.
EPA Assistant Administrator for Enforcement and Compliance Jeff Hall explained that attackers have moved beyond ransomware designed to extort payments toward specific attacks aimed at disrupting critical infrastructure. Hackers now manipulate human-machine interfaces to alter vital system settings, creating risks far beyond financial loss. The shift represents a fundamental change in cyber warfare targeting civilian populations through essential utilities.
Recent Breaches Expose System Weaknesses
A coordinated July cyberattack targeted more than 30 community water systems across Minnesota, disrupting technology used to remotely monitor and control equipment. Colorado officials recently disclosed that foreign actors breached two small water utilities and manipulated equipment controlling drinking water systems. Authorities confirmed drinking water remained safe in both incidents, but the attacks highlighted growing vulnerability in critical infrastructure. Many utilities continue operating aging infrastructure while lacking resources to modernize cybersecurity defenses including basic protections like virtual private networks and firewalls.
Basic Security Failures Leave Systems Exposed
The most common vulnerabilities EPA officials identified remain surprisingly elementary. Systems across America suffer from failure to change default passwords and lack of multi-factor authentication, creating entry points for sophisticated foreign hackers. Workforce shortages compound these challenges, making it harder for utilities to recruit and retain employees with expertise needed to defend increasingly complex networks. Hall warned that water systems lacking significant investment in cybersecurity protocols remain vulnerable to attacks targeting one of the most deeply embedded pieces of American civilian infrastructure.
