Iranian Hackers Targeted U.S. Water Systems Amid Federal Warnings
Years of unaddressed cybersecurity gaps in water infrastructure have left federal and state agencies responding reactively to a threat that internal reports identified well in advance.
Federal and state officials are responding to a series of cyberattacks on U.S. water supply systems that authorities believe are the work of Iranian state-linked hackers, according to reporting by The New York Times published August 5, 2026. Officials described the incidents as part of an ongoing assault rather than isolated intrusions, and characterized the response as a race to address vulnerabilities that had been documented but not fully remediated.
The attacks follow a documented history of federal warnings about water sector cybersecurity. The Cybersecurity and Infrastructure Security Agency (CISA) and the Environmental Protection Agency (EPA) jointly issued advisories in 2023 and 2024 — both publicly available on CISA.gov — warning that water and wastewater systems represented a critical infrastructure sector with significant unpatched vulnerabilities and limited federal enforcement authority over cybersecurity standards.
Congress has addressed water cybersecurity in limited legislative form. The America's Water Infrastructure Act of 2018 (Public Law 115-270) required community water systems serving more than 3,300 people to conduct risk and resilience assessments, with results submitted to the EPA. However, the law did not mandate specific cybersecurity controls, nor did it establish penalties for non-compliance with cybersecurity provisions, according to the statutory text available via Congress.gov.
Federal spending on water infrastructure cybersecurity has been allocated through the Bipartisan Infrastructure Law (Public Law 117-58, Section 50111), which directed $25 million over five years to the EPA for cybersecurity technical assistance to water systems, per USASpending.gov records. Independent assessments from the Government Accountability Office — including GAO report GAO-24-106200, published January 2024 — found that the EPA had not yet developed a comprehensive cybersecurity strategy for the water sector as of that report's release date.
The identity of specific systems compromised, the volume of affected customers, and the operational impact of the intrusions remain unknown as of this publication. What public records would clarify those questions: EPA incident disclosures under the Safe Drinking Water Act, any CISA Coordinated Vulnerability Disclosure notices, and congressional oversight correspondence from the Senate Environment and Public Works Committee or the House Energy and Commerce Committee, none of which had been publicly released as of August 5, 2026.