August 10, 2026

Daily Pulse

Clear reporting on the stories that matter

Cyberattacks Expose Critical Weaknesses in US Water Systems: Five Urgent Actions for Leaders

Recent cyber intrusions targeting American water infrastructure highlight long-standing vulnerabilities and underscore the urgent need for comprehensive security upgrades to protect essential services.

Opinion·

Cyberattacks Expose Critical Weaknesses in US Water Systems: Five Urgent Actions for Leaders

As geopolitical tensions persist, reports indicate that cyber actors with ties to Iran have penetrated critical infrastructure deep within the United States, specifically targeting the essential systems that manage public water supplies.

Over 30 community water facilities in Minnesota reportedly experienced a coordinated cyber intrusion in late July, with similar digital activity observed in several other states.

This development should be a significant concern for all Americans. However, the most alarming aspect isn't merely the identity of the potential perpetrators, but rather the seemingly low level of technical sophistication required to execute these attacks.

Initial assessments suggest these incidents did not involve an insurmountable cyberweapon. Instead, attackers appear to have exploited common, fundamental security gaps in internet-connected operational technology—weaknesses that cybersecurity experts have cautioned about for many years.

While the specific attacks may have been conducted by Iranian-affiliated groups, reflecting an escalation in the ongoing friction between the U.S. and Iran, the vulnerabilities exposed in Minnesota were not unknown to national leaders.

On the contrary, these events have further highlighted the tangible consequences of systemic weaknesses that the federal government has been documenting for a considerable time.

The Escalating Threat to Water Infrastructure

For example, in 2024, an assessment by the Environmental Protection Agency’s Office of Inspector General reviewed 1,062 drinking water systems, collectively serving more than 193 million citizens. The investigation uncovered critical or high-risk cybersecurity vulnerabilities in 97 of these systems, impacting approximately 26.6 million Americans. Additionally, 211 other systems, serving over 82.7 million people, possessed network portals that were externally visible from the public internet.

In essence, systems serving tens of millions of Americans were discoverable via the public internet. The inspector general warned that exploiting these accessible entry points could enable hackers to disrupt services and potentially cause physical damage to vital water infrastructure.

This situation elevates the stakes far beyond the typical data breaches that have become unfortunately common.

While data breaches, whether affecting retailers or credit bureaus, can compromise personal information and inflict serious harm—a risk that should not be underestimated—an attack on a water system crosses a much more dangerous threshold. It shifts from compromising data to disrupting an essential service upon which human life fundamentally depends. Such an event could halt pump operations, interrupt water supplies, and jeopardize the health and safety of entire communities.

The magnitude of this issue extends far beyond Minnesota. According to the Government Accountability Office, the American water sector comprises nearly 170,000 water and wastewater systems. Many of these systems rely on outdated equipment, grapple with workforce shortages, and possess limited capacity for dedicated cybersecurity personnel.

The advent of artificial intelligence (AI) further complicates this landscape.

AI technology has empowered malicious actors to identify vulnerable systems more efficiently, craft highly convincing phishing messages, and modify malicious software with unprecedented speed. Although there is no public indication that AI played a direct role in the Minnesota incidents, it is undeniably making cyberattacks cheaper, faster, and easier to execute at scale—a threat that demands serious attention.

Fortunately, regardless of AI's increasing power, it does not represent the fundamental weakness itself. Rather, AI simply provides attackers with more efficient tools to exploit existing vulnerabilities.

Safeguarding Essential Services: Five Critical Steps

So, what is the path forward? The solution does not lie in pursuing futuristic technologies while neglecting foundational security practices. Instead, protecting critical infrastructure, such as water treatment plants, must begin with five fundamental actions.

  • Know Your Network: First, utility providers must possess a complete understanding of everything connected to their networks. Every water system requires an accurate inventory of its equipment, software origins, remote access points, and third-party vendors. An organization cannot effectively protect technology it is unaware it possesses.
  • Secure Access Points: Second, every point of access must be rigorously secured. Default passwords must be eliminated, multi-factor authentication should be a mandatory requirement, and critical control systems should never be directly exposed to the public internet.
  • Segregate Systems: Third, operational technology equipment must be isolated from routine business systems. A computer used for email, internet browsing, or administrative tasks should not provide a direct pathway to the pumps and other machinery vital for controlling a community’s water supply.
  • Update Software Promptly: Fourth, software must be updated regularly and promptly. Attackers frequently target known vulnerabilities for which patches have been available for months or even years. A security update that exists but remains uninstalled offers no protection whatsoever.
  • Implement Application Allowlisting: Lastly, critical infrastructure must implement strict controls over what software is permitted to run, by deploying application allowlisting—also known as whitelisting—across all its systems.

Most conventional cybersecurity tools are designed to detect and block programs identified as malicious. However, AI now enables attackers to generate and modify malware with extraordinary speed, producing novel variations that may not resemble previously known threats. This rapid evolution makes a traditional, detection-only security strategy increasingly unsustainable.

Application allowlisting, conversely, reverses this paradigm. Rather than attempting to identify every potential threat, it permits only pre-approved software to operate. All other software is prevented from running by default until a system administrator can conduct a thorough safety review. This proactive approach prevents unknown, potentially malicious software from executing within the vital systems that Americans rely on for necessities like water and electricity.

Collectively, these five measures would significantly enhance the resilience of America’s water systems—and indeed all critical infrastructure—making them substantially more difficult to compromise. They would also shift these systems from a reactive stance, responding to attacks after damage has begun, to a proactive one, preventing damage in the first place.

A Call for Immediate Action and Accountability

The recent attacks in Minnesota must serve as a pivotal moment in how our nation safeguards its critical infrastructure. Addressing this challenge effectively demands more than mere acknowledgment of the risks; it requires decisive action, clear accountability, and a profound sense of urgency.

Every utility operator, municipal leader, and government agency responsible for these essential systems should immediately assess their adherence to these five standards, assign unequivocal responsibility for rectifying any deficiencies, and establish firm deadlines for resolving all identified vulnerabilities. Furthermore, where local communities lack the necessary expertise or resources, state and federal partners must step in to bridge these gaps.

The threat posed by cyberattacks is no longer distant or theoretical.

America’s adversaries are actively searching for known weaknesses. Any action, or indeed inaction, that allows these vulnerabilities to persist constitutes a choice that invites a more severe attack—one with potentially deadly consequences.

America was fortunate in this instance; Minnesota’s water system continued to serve residents despite the cyber intrusion.

However, this favorable outcome should instill a sense of urgency, not complacency. Relying on good fortune is not a viable cybersecurity strategy for America. Leaders must take decisive action today to close known security gaps before the next cyberattack endangers American lives.

Iranian cyberattackswater infrastructure securitycritical infrastructure protectioncybersecurity vulnerabilitiesEPA water systemsapplication allowlistingmulti-factor authenticationoperational technology security

Related Stories