‘Frightening’ cyberattacks on water utilities renew calls for regulations

By Miranda Willson | 08/10/2026 01:36 PM EDT

Two Senate Democrats introduced a bill Monday to set cybersecurity standards for water utilities — something Republicans and industry have long fought.

Clouds are reflected off the City of Jackson's O.B. Curtis Water Treatment Facility's sedimentation basins in Ridgeland, Mississippi.

Hackers have been targeting drinking water and wastewater systems across the country in a coordinated series of attacks that security officials say remain ongoing. Rogelio V. Solis/AP

The coordinated series of cyberattacks launched on U.S. drinking water and wastewater utilities across the country in recent weeks has alarmed lawmakers on Capitol Hill — but it remains to be seen whether the threat will be enough to break the impasse over mandating basic security standards for the sector.

The vulnerabilities that hackers have been exploiting to attack water systems in at least 30 systems across 12 states were well known and could have been easily identified and addressed with simple fixes, cybersecurity experts say.

But for the better part of two decades, efforts to require the nation’s drinking water and wastewater systems to meet minimum cybersafety standards have been stymied by lawmakers’ reluctance to force new requirements onto the country’s smallest water systems.

Advertisement

Now, that reluctance is being tested as pressure mounts to address the alarming vulnerabilities laid bare in Minnesota, Michigan and other states in attacks that a water sector security group said Thursday are “ongoing and expanding.”

Two Democratic senators introduced legislation Monday that would give EPA clear authority to assess cybersecurity threats across the water and wastewater sector. The bill from Sens. Adam Schiff (D-Calif.) and Amy Klobuchar (D-Minn.) is effectively a second attempt at an approach the Biden administration tried three years ago but was foiled by opposition from Republican states and industry groups.

The Water Cyber Shield Act of 2026 would allow EPA to require utilities to address vulnerabilities it identifies and mandate cybersecurity evaluations for large utilities. A spokesperson for Schiff said he might try to include the bill in a larger package before years’ end but has not singled out a specific vehicle.

But it’s unclear whether the current crisis has shifted the politics around regulation, especially among Republicans.

Senate Environment and Public Works Chair Shelley Moore Capito (R-W.Va.) called the spate of attacks on water systems “frightening.” But in an interview last week, she argued that the solution was more resources. Her office didn’t respond to a request for comment Monday on Schiff’s bill.

“[Utilities] don’t have the capacity, and they haven’t updated their systems to meet the challenge of cyber,” Capito said. “They don’t know what to ask for because they’ve never had to meet that challenge before.”

‘An ongoing challenge’ as hackers breach controls

Small utilities, which make up the majority of the 150,000 drinking water and wastewater providers nationwide, are already struggling to get by with shoestring staffs, tiny budgets and price-sensitive ratepayers. But they are also proving to be the most vulnerable to cyberattacks, rarely having the technical expertise to maintain even basic cybersecurity precautions.

Many of the systems that have been implicated in the ongoing attacks, which began in late July, serve small and midsize communities.

In Braham, Minnesota — a city of fewer than 2,000 people about 50 miles north of Minneapolis — hackers shut down the control system for the water treatment plant and well, prompting officials to issue a call to conserve water before they were able to bring the system back online hours later.

In Michigan, state officials have fielded a handful of reports from water utilities describing attempts to tamper with operational technologies — exactly the type of attacks the Cybersecurity and Infrastructure Security Agency and FBI have warned about — according to a spokesperson for the state’s environment department.

The vulnerabilities the hackers exploited to gain control of the systems’ internet-connected devices were gaping ones, said Michael Garcia, the former associate chief of policy for CISA.

“The sad thing is, these aren’t unique vulnerabilities. They’re actually just basic cybersecurity controls we’ve known about for, honestly, decades,” said Garcia, who now works as vice president of government relations at Monument Advocacy, a lobbying group whose focus includes cybersecurity.

No major drinking water safety issues have been reported in connection to the recent attacks, which some experts have linked with Iranian actors. But some utilities issued boil water notices as precautionary measures before regaining control of their system, Garcia said.

Sen. Mark Kelly (D-Ariz.), who also serves on the EPW Committee, said the recent attacks show that hackers are getting more sophisticated in their methods — but utilities are still using “old software” and out-of-date systems, he said.

“In this case, we saw that they were able to cause problems,” Kelly said. “They’re not catastrophic problems, but this is going to be an ongoing challenge for us because these tools they’re using to hack are getting stronger.”

Capito and her Democratic counterpart, Sen. Sheldon Whitehouse of Rhode Island, argued that a bipartisan water resources measure passed out of the EPW Committee last month would aid with the problem. The Senate version of the bill would allow EPA to use its existing drinking water funding programs for cybersecurity work, such as training utility workers on best practices and providing grants for rural utilities to reduce vulnerabilities.

A softer, industry-backed approach

As calls are rising to address water systems’ vulnerabilities, some industry groups are backing a bill that would take what they describe as a collaborative approach to developing cybersecurity requirements rather than a top-down regulatory one.

Sponsored by Rep. Rick Crawford (R-Ark.), the Water Risk and Resilience Organization Establishment Act would create an independent organization to develop and enforce minimum cybersecurity standards for large and midsize water and wastewater utilities. It’s a modest attempt to address a problem recognized by lawmakers on both sides of the aisle without giving the federal government a hammer.

“Our preferred approach is one that engages the sector in the conversation,” said Nate Norris, director of legislative affairs at the American Water Works Association. “We’ve been harping on the fact that the water sector is large and diverse. … We want to avoid a minimum, one-size-fits-all approach.”

The American Water Works Association sent a letter to House and Senate leaders last week reiterating support for the bill, which has been referred to the House Transportation and Infrastructure Committee and Energy and Commerce Committee.

“The Committee is aware of these efforts to reform programs under the Clean Water Act and is actively working with Members on this legislation,” a Transportation and Infrastructure Committee spokesperson said by email Monday.

Norris said the water risk organization that would be established by the bill would be similar to the North American Electric Reliability Corp., which oversees security of the power grid. But by excluding the smallest systems — those serving less than 3,300 people — from cybersecurity requirements, the legislation could leave out the very communities experts say are the least prepared to address the problem.

And while the bill would require EPA to approve cybersecurity risk and resilience requirements set by the designated risk organization, it would have EPA defer to the organization’s “technical expertise.”

William Akoto, an assistant professor of foreign policy and global security at Georgetown University, said the “basic idea” behind the bill makes sense. Water system operators likely have technical expertise that EPA lacks, he said.

But there is a risk that whatever standards would be developed under the system could be inadequate, Akoto said.

“[The] risk is that the resulting standards could reflect what utilities consider affordable or convenient rather than what the evolving threat environment actually requires,” Akoto said in an email.

The approach isn’t a political shoe-in, since it doesn’t have the full support of the water sector. The National Association of Clean Water Agencies, the largest trade group for the wastewater sector, doesn’t support the bill. It argues that increased education and funding for cybersecurity investments — not regulatory requirements — should be the priority.

“Creating some sort of new entity right now is challenging in Congress,” said Matthew McKenna, director of government affairs at the National Association of Clean Water Agencies. “Our focus is making sure appropriators know that existing programs are critical and that we have to get more utilities access to them.”

Some of those existing programs — including to help states and localities address cybersecurity risks to government systems — have seen funding sharply curtailed under the Trump administration. CISA has also seen large-scale layoffs.

For now, the water sector has a dedicated organization for sharing updates on cyberattacks and best practices for reducing risks, but participation is limited, voluntary and comes at a cost to utilities.

Of the roughly 620 organizations that are members of the group, known as the Water Information Sharing and Analysis Center, around 400 are water and wastewater utilities — representing less than 1 percent of the sector.

Jennifer Lyn Walker, director of infrastructure cyber defense at the nonprofit, said the group has seen a slight uptick in membership requests over the past few weeks. It is seeking to further increase membership through a partnership with the National Rural Water Association that currently provides no-cost access for utilities serving fewer than 10,000 people, she said.