U.S. water agencies have been advised to disconnect control networks from the internet and strengthen passwords following a wave of cyberattacks [1, 2].

These security measures are critical because unauthorized access to water-system controls could jeopardize water quality and compromise essential infrastructure for millions of citizens.

Reports indicate that cyberattacks have affected water systems in at least 12 states [3, 4]. Other reports place the number of affected states at seven or more [5]. The scale of the risk is significant given that the United States maintains roughly 152,000 public water systems [6].

Federal officials suspect the intrusions may be linked to hackers backed by Iran [1, 2, 4]. However, the Cybersecurity and Infrastructure Security Agency (CISA) has not attributed the attacks to any specific group [7].

Local authorities are responding to the threat by increasing vigilance. In Baltimore, public works officials have begun monitoring their water systems more closely to detect and prevent potential breaches [8].

The current advisories emphasize the need for immediate action to close security gaps. Agencies are being told to move away from internet-facing control systems, a common vulnerability in older infrastructure, and to implement more rigorous authentication protocols to prevent remote access by foreign actors [1, 2].

U.S. water agencies have been advised to disconnect control networks from the internet

The targeting of water infrastructure highlights a shift in cyber warfare toward 'soft' targets that provide essential services. Because many of the 152,000 water systems in the U.S. are managed by small local municipalities with limited budgets, they often lack the sophisticated cybersecurity defenses used by larger federal agencies, making them attractive entry points for state-sponsored actors.