EPA warns foreign hackers could cripple U.S. water systems
EPA officials say a surge in cyberattacks on water utilities is shifting from ransomware to disruptive attacks that could shut down drinking water and wastewater services.
EPA Assistant Administrators Jess Kramer and Jeff Hall told officials that cyber threats to the nation's water supply have risen dramatically, moving from profit-driven ransomware to attacks aimed at disabling essential services. They highlighted that many water utilities operate aging equipment and lack basic protections such as firewalls, VPNs and multi-factor authentication, making them vulnerable to intrusion. Hackers are increasingly exploiting human-machine interfaces and programmable logic controllers to alter critical settings, potentially endangering public health.
Recent coordinated attacks affected over 30 systems in Minnesota and two small utilities in Colorado, though drinking water remained safe in those cases. The agency has logged more than 900 vulnerabilities since 2025, most involving simple password failures and publicly available system information. While EPA inspectors and the Office of Water are providing technical assistance and training, officials warn that attackers—including state-affiliated groups—are becoming more sophisticated and could cause widespread disruption.
Why it matters
Compromised water systems could halt essential services, affecting health, safety and daily life across the United States.
In this story
