Water Systems cyberattacks in 12 states and growing as “low hanging fruit”!
The WashingtonPost.com reported that “The number of states affected has expanded to at least a dozen, say officials familiar with the matter, with at least 30 systems affected in Minnesota alone.” The August 10, 2026 article entitled " Water systems are ripe for cyberattacks, experts warn after suspected Iranian hacks” (https://www.washingtonpost.com/national-security/2026/08/10/us-water-systems-are-low-hanging-fruit-cyberattacks-experts-warn-after-suspected-iranian-hacks/) included these comments from Reporters By Ellen Nakashima and Amy Wang:
U.S. intelligence agencies are confident that Iran’s Islamic Revolutionary Guard Corps is behind the campaign, but have not made a formal attribution, in part because there is still some debate about which group within the IRGC carried out the attacks, according to two people familiar with the matter. One of the people added that there may be a reluctance to make an attribution that contradicts the president’s public remarks.
The FBI declined to comment.
The state of cybersecurity varies across the nation’s more than 150,000 water systems. Some municipalities, such as Cedar Rapids, Iowa, were largely insulated against the recent hacks because their systems are air-gapped, or not connected to the internet.
“We have had multiple people recommend we tie our system to the outside world,” said Roy Hesemann, utilities director for Cedar Rapids, whose water system serves about 135,000 people and whose state was among those that sued EPA. “I’ve been adamant going back to 9/11, knowing that people were occasionally getting hacked — no, we’re not doing it.’’
At least three states have recent laws requiring cybersecurity risk assessments for water systems: Indiana, Maryland and New York. Authorities are unaware of any water system hacks related to the recent campaign in these three states.
This very bad news, what do you think?