<p>A significant rise in cyberattacks on the water supply in the United States has shifted hackers' focus from financially motivated ransomware to attacks aimed at disrupting critical civilian infrastructure, according to senior officials from the Environmental Protection Agency (EPA). In an interview, EPA Assistant Administrator for Water Jess Kramer stated that when drinking water and wastewater systems are affected, "everyday life completely crumbles." Kramer noted that there has been a several-fold increase in such attacks recently, with vulnerabilities ranging from simple password failures to specific system information being available online.</p><p>Kramer explained that the water sector has become an attractive target for hackers due to its essential role in daily life. She emphasized that hospitals, daycares, and other critical services depend on access to drinking water and wastewater infrastructure. EPA Assistant Administrator for Enforcement and Compliance Assurance Jeff Hall added that many water utilities operate with aging infrastructure and lack the resources to modernize their cybersecurity measures. He highlighted that some utilities still lack basic protections like virtual private networks and firewalls.</p><p>Hall explained that hackers have transitioned from ransomware attacks to more targeted disruptions of critical infrastructure, particularly water systems. He noted that attackers are increasingly manipulating human-machine interfaces to change critical settings, which disrupts service and poses risks to public safety.</p><p>The warning comes as cyber threats to U.S. water infrastructure have gained increased attention from federal and state officials. In July, a coordinated cyberattack targeted over 30 community water systems in Minnesota, affecting technology used for remote monitoring and control. More recently, officials in Colorado reported that foreign actors breached two small water utilities, manipulating equipment used to control drinking water systems. Although drinking water remained safe in these instances, the incidents raised alarms about the vulnerabilities of critical infrastructure relied upon by millions of Americans.</p><p>Unlike data breaches that primarily expose personal information or ransomware attacks meant to extract payments, successful cyber intrusions into water systems can disrupt services essential to daily life, including hospitals, schools, and emergency services. This has raised concerns among national security officials regarding the vulnerability of critical civilian infrastructure.</p><p>Kramer noted that workforce shortages have further complicated the challenge, making it difficult for utilities to recruit and retain employees with the necessary expertise to defend complex networks. The EPA has identified over 900 cybersecurity vulnerabilities in water systems nationwide since 2025, with common issues including failure to change passwords and lack of multi-factor authentication.</p><p>Hall stated that the EPA and its law enforcement partners have issued advisories about vulnerabilities involving programmable logic controllers and other industrial control systems that manage critical equipment in water facilities. He expressed concern about aging infrastructure that remains exposed to the open internet without adequate protections.</p><p>Hall also mentioned that state-affiliated actors, hacktivist networks, and insider threats are among the adversaries targeting water and wastewater systems. Despite the growing threat, both officials noted that utilities are making progress in addressing common weaknesses. Kramer acknowledged the difficulty in measuring national progress due to the EPA's lack of authority to mandate reporting of cyber incidents by all water systems. However, she indicated that there is clear evidence that attackers are becoming more sophisticated as utilities work to enhance their defenses.</p><p>Hall stated that EPA inspectors review cybersecurity planning at larger drinking water systems, while the agency's Office of Water provides technical assistance, training, and support to help utilities identify and address vulnerabilities before they can be exploited. He concluded that while there is an increase in systems addressing basic vulnerabilities, concerns remain about the evolving sophistication of cyber attackers and the ongoing vulnerabilities that need to be addressed.</p>
Why this rating? · 1 signal
Signals flagged in the original
- headline asserts a conclusion / scare-quotes
Provisional estimate — refines shortly Full breakdown ↓
Increase in Cyberattacks Targeting U.S. Water Infrastructure Raises Concerns
Senior officials from the Environmental Protection Agency (EPA) report a significant increase in cyberattacks targeting U.S. water infrastructure, shifting from financially motivated ransomware to disruptive attacks. The vulnerabilities in water systems, including aging infrastructure and lack of cybersecurity resources, pose risks to essential services relied upon by the public. Despite efforts to address these issues, concerns remain about the sophistication of cyber threats and the ongoing vulnerabilities in the sector.
No note attached
on this article.
Language Analysis
Loaded Language Removed
- ✕ headline asserts a conclusion / scare-quotes
Original vs. Neutral
How foreign hackers could 'crumble' America by targeting one essential utility
Increase in Cyberattacks Targeting U.S. Water Infrastructure Raises Concerns