Crime & Safety

Iranian hackers attacked our water systems. Here are 5 things our leaders need to do now

Over 30 community water systems in Minnesota were targeted in a coordinated cyberattack in late July, with similar activity identified in several other states.

Share this story
Iranian hackers attacked our water systems. Here are 5 things our leaders need to do now
DETAILS: Trump RESPONDS to water systems cyberattack

Over 30 community water systems in Minnesota were targeted in a coordinated cyberattack in late July, with similar activity identified in several other states.

Investigations suggest that Iranian-affiliated hackers are likely behind the attack. However, experts say that the attackers did not use sophisticated cyberweapons, but rather exploited fundamental security weaknesses that have been known for years.

The Environmental Protection Agency's Office of Inspector General found critical or high-risk cybersecurity vulnerabilities at 97 drinking-water systems serving approximately 26.6 million Americans in 2024. Another 211 systems serving more than 82.7 million people had portals visible from outside their networks, which could be exploited by hackers to disrupt services and cause physical damage to water infrastructure.

This type of attack crosses a dangerous threshold, as it can compromise an essential service that is critical to human life. Pumps can stop operating, water supplies can be interrupted, and entire communities' health and safety can be put at risk.

The scope of the challenge extends beyond Minnesota, with nearly 170,000 water and wastewater systems making up America's water sector. Many rely on aging equipment, face workforce shortages, and operate with limited capacity for dedicated cybersecurity personnel.

To address this issue, experts recommend five essential actions: utilities must know what is connected to their networks, every point of access must be secured, operational equipment must be separated from routine business systems, software must be updated routinely and promptly, and critical infrastructure must control what software is permitted to run by deploying application allowlisting across its systems.

These measures would make America's water systems substantially harder to compromise, moving them away from reacting to attacks after the damage begins and toward preventing the damage in the first place.

Source

NTC Report coverage is based on reporting from the original publisher.

View original reporting →