A massive surge in cyberattacks on Americans’ water supply in recent years has exposed a shift in hackers’ focus from financially motivated ransomeware to attacks designed to disrupt one of the most essential pieces of civilian infrastructure, senior Environmental Protection Agency (EPA) officials told Fox News Digital.
“Everyday life completely crumbles” when drinking water and wastewater systems are impacted, warned EPA Assistant Administrator for Water Jess Kramer.
“There is definitely been an increase, several fold on attacks recently,” Kramer added in an interview with Fox News Digital. “You’re seeing everything from failure to change password, leading to cyberattacks all the way to … system specifics being available online.”
Asked why the water sector has become such an attractive target, Kramer said the answer begins with how deeply embedded it is in Americans’ daily lives.
AN AI CYBERATTACK COULD TURN OFF AMERICA’S LIGHTS BEFORE WASHINGTON EVEN UNDERSTANDS WHY
“Our everyday life completely crumbles without access to drinking water and wastewater infrastructure,” she said. “Everything from hospitals to daycares, everything that we care about and need on an everyday basis can be impacted” if one of those cyberattacks succeeds.
EPA Assistant Administrator for Enforcement and Compliance Assurance Jeff Hall said water utilities have also become appealing targets because many continue to operate aging infrastructure while lacking the resources to modernize their cybersecurity.
“We will see water systems left vulnerable to cyberattacks where there have not been significant amounts of investment in cybersecurity protocols,” Hall said, pointing to basic protections such as virtual private networks and firewalls that are still missing at some utilities.
Hall explained how hackers have “moved from ransomware attacks designed to extort payments from critical infrastructure generally to more specific attacks designed to disrupt critical infrastructure and particularly water and wastewater systems.”
Attackers, he said, are increasingly “manipulating the human-machine interface to change critical settings which disrupts the service and also puts people at risk.”
FOREIGN HACKERS BREACH TWO MORE US WATER UTILITIES, THREATEN SAFETY OF COLORADO RESIDENTS
The warning comes as cyber threats targeting U.S. water infrastructure have drawn heightened attention from federal and state officials.
In July, a coordinated cyberattack targeted more than 30 community water systems across Minnesota, disrupting technology used to remotely monitor and control equipment. More recently, Colorado officials disclosed that foreign actors breached two small water utilities and manipulated equipment used to control drinking water systems. Officials said drinking water remained safe in both cases, but the incidents highlighted growing concern over cyber threats to critical infrastructure that millions of Americans rely on every day.
WATER CYBERATTACK HITS AT LEAST 7 STATES
Unlike data breaches that primarily expose personal information or ransomware attacks intended to extract payment, successful cyber intrusions into water systems have the potential to interfere with services that underpin nearly every aspect of daily life — from hospitals and schools to manufacturing, emergency services and businesses — raising concerns among national security officials about the vulnerability of critical civilian infrastructure.
Kramer added that workforce shortages have compounded the challenge, making it harder for many utilities to recruit and retain employees with the expertise needed to defend increasingly complex networks.
The officials said many of the vulnerabilities EPA continues to identify are surprisingly basic.
Since 2025, the agency has identified more than 900 cybersecurity vulnerabilities at water systems across the country. Kramer said the most common include “failure to change passwords, lack of multi-factor authentication” and critical system information that is “easily accessible” online.
Hall said EPA and its law enforcement partners have also issued advisories about vulnerabilities involving programmable logic controllers, or PLCs, and other industrial control systems that operate pumps, valves and other critical equipment inside water facilities.
“There are aging infrastructure that is embedded in these drinking water systems,” Hall said. “It’s often left open to the open internet and not protected by any specific firewalls or virtual private networks that would ensure that cyber attackers cannot easily manipulate those.”
Hall said the agency remains concerned about a range of adversaries, including state-affiliated actors, hacktivist networks and insider threats.
CHINA-LINKED HACKERS INFILTRATED US GOVERNMENT NETWORKS BEFORE FBI TAKEDOWN
“There are certainly state affiliated actors targeting water and wastewater systems,” Hall said, adding that investigators are increasingly concerned about the sophistication and intent behind those attacks.
Despite the growing threat, both officials said utilities are making progress by addressing many of the most common weaknesses.
Kramer acknowledged it is difficult to measure national progress because EPA does not have authority to require every water system to report cyber incidents. Still, she said the agency has observed clear evidence that attackers are becoming more sophisticated as utilities work to improve their defenses.
Hall said EPA inspectors review cybersecurity planning at larger drinking water systems, while the agency’s Office of Water provides technical assistance, training and one-on-one support to help utilities identify and remediate vulnerabilities before they can be exploited.
“We are seeing an increase in the number of systems that are addressing their basic vulnerabilities,” Hall said. “But … there are real concerns that cyber attackers are going up to the next level and that there are still a lot of vulnerabilities out there that we will have to be addressing.”
[#item_full_content]