Federal officials are sounding the alarm that cyber attacks on America’s drinking water and wastewater systems are on the rise, posing a direct risk to hospitals, daycares and everyday households. EPA Assistant Administrator for Water Jess Kramer told Fox News Digital that the surge in attacks reflects a shift from ransom‑driven malware to deliberate attempts to disrupt essential services.
Recent incidents highlight the danger
In July, more than 30 community water systems in Minnesota were hit by a coordinated cyber intrusion that temporarily disabled remote monitoring equipment. A few weeks later, Colorado authorities disclosed that foreign actors breached two small utilities, manipulating the controls that regulate drinking water flow. Both incidents left water supplies safe, but they underscored how vulnerable aging infrastructure can be when basic cyber defenses are missing.
Why water utilities are attractive targets
Kramer explained that water systems are deeply woven into daily life, making them a high‑value target for adversaries. “Our everyday life completely crumbles without access to drinking water and wastewater infrastructure,” she said. EPA Assistant Administrator for Enforcement and Compliance Assurance Jeff Hall added that many utilities operate with outdated equipment and lack the resources to modernize cybersecurity.
Hall noted that simple safeguards such as virtual private networks, firewalls and multi‑factor authentication are still absent at numerous facilities. “There are aging infrastructures that are often left open to the open internet,” he said, emphasizing the need for basic protective layers.
EPA’s response and progress
The agency says it has identified more than 900 cybersecurity vulnerabilities at water systems since 2025, the most common being unchanged passwords, lack of multi‑factor authentication and publicly available system details. In response, EPA inspectors are reviewing cybersecurity plans at larger drinking water utilities, while the Office of Water provides technical assistance, training and one‑on‑one support to help smaller systems remediate weaknesses.
Both Kramer and Hall reported that utilities are beginning to address these basic gaps. Hall said, “We are seeing an increase in the number of systems that are addressing their basic vulnerabilities,” though he warned that attackers are becoming more sophisticated and that many risks remain.
Broader threat landscape
The EPA cautions that state‑affiliated actors, hacktivist groups and insider threats all pose ongoing risks. While the agency cannot compel every water system to report cyber incidents, it continues to issue advisories on protecting programmable logic controllers and other industrial control systems that manage pumps, valves and critical equipment.
Officials stress that protecting water infrastructure is a shared responsibility. Communities, state regulators and the federal government must work together to ensure that essential services remain resilient against increasingly sophisticated cyber threats.
Original reporting: Fox News (HLL/CB) — read the source article.