- A new Pew Research report finds cyberattacks targeting U.S. water systems on the rise.
- New web-linked automation systems improve system efficiency but create opportunities for intrusion.
- Researchers say additional federal and state funding is critical to keeping drinking water safe.
A new report from Pew Research finds cyberattacks targeting U.S. water systems are on the rise including incidents this summer tracked by the FBI which threatened operations across seven states.
While federal law enforcement officials did not identify states impacted by a rash of intrusion attempts in July, Utah facilities were among those in the crosshairs of cyber criminals in recent attacks. That includes a series of incidents outlined in an intelligence note reviewed by ABC News that confirmed Utah public safety officials “identified targeted reconnaissance” against the state’s water infrastructure last fall. The report notes the hacking efforts were traced to an internet signature linked to Iran and included nearly 500 attempted intrusions within 46 minutes in November 2025.
According to Utah’s “Drinking Water Cybersecurity” audit released earlier this year, a June 2023 denial-of-service attack on an unidentified municipal water system forced staff to switch to manual operation for about three weeks. While water delivery was never impacted, according to the report, it took the city 18 months to recover from the attack and cost about $360,000 for equipment, software and overtime.
In an analysis released Tuesday, Pew researchers note that while most incidents have not contaminated water or caused sustained outages, “cyber threats are increasing as more utilities adopt internet-connected technologies — often without appropriate safeguards.”
The cost of cyberattacks on water systems
Cyberattacks on water systems can include ransomware incidents, breaches of customer data and intrusions into operational technology that can disrupt service, damage infrastructure or compromise technologies used to operate and monitor water systems, according to the Pew report.
In July 2026, a series of cyberattacks on water and wastewater utilities in more than 30 communities in Minnesota forced some systems to go offline, disconnect equipment or rely on manual operations.
A cyberattack in October 2024 forced American Water, the nation’s largest water utility, to shut down customer systems, including billing, to protect data, which interrupted normal revenue processes, per the report. Similarly, a 2019 ransomware attack on Baltimore’s municipal systems prevented the city from issuing water bills for several months and ultimately cost the city an estimated $18 million for IT system repairs and lost or delayed late payment and penalty revenue.
In Boston, a 2020 ransomware incident disrupted administrative systems for weeks and forced the city’s water and sewer commission to devote time and resources to restoring normal operations.
“Things that even 10 years ago we never thought about are all now adding to the cost of what it takes to run a water supply system,” said Mike Grimm, vice chair of the American Water Works Association’s Water Utility Council, according to the report.
As a result of intrusions into water systems, utilities shoulder much of the burden for cybersecurity, which they often then pass on to already stretched ratepayers, the report says.
In their assessment, Utah auditors gathered information from 500 water system contacts across the state and found opportunities to improve vulnerability management, risk assessments, training and incident response plans. The report also cites similar findings from the Utah Education and Telehealth Network that many Utah water systems “lack foundational protections against growing cyber threats.”
Auditors noted that drinking water systems generally use operational technology to control or monitor physical processes like pumps and valves. But while this technology can provide benefits such as real-time monitoring, automated controls and improved efficiency, it has also increased the cyber risk to water systems.

How government agencies are responding
In July, a bipartisan U.S. Senate committee introduced the Water Resources Development Act, aiming to authorize more than $35 billion in funding for water infrastructure programs over the next four years. In addition to allocations for revolving funds for drinking water systems and clean water efforts, the proposal authorizes two cybersecurity-focused programs sought by the American Water Works Association. Those include the Midsize and Large Drinking Water System Infrastructure Resilience and Sustainability Program and a new program to encourage utility participation in the Water Information Sharing and Analysis Center.
Sen. Sheldon Whitehouse, D-R.I., ranking member of the Senate Environment and Public Works Committee, said the effort represents a significant step forward in improving the safety of municipal water systems across the country.
“Our markup to advance this significant package of legislation demonstrates a bipartisan commitment to maintaining and upgrading the nation’s water infrastructure,” he said in a press statement.
In their January report, Utah auditors said they believed improved governance, including a more strategic approach to cybersecurity, will help elevate cybersecurity at Utah’s water systems and offered a trio of recommendations to achieve those goals:
- The Utah Drinking Water Board should require all community water systems that use operational technology to adopt a plan to implement cybersecurity best practices like those outlined by the U.S. Environmental Protection Agency. Plans should target baseline best practices to provide a solid foundation for cybersecurity.
- The Legislature should consider whether any additional steps should be taken to further address cybersecurity risk to drinking water systems.
- The Legislature should consider modifying statute to require drinking water systems that have governing bodies to provide regular cybersecurity briefings to their governing council or board. Briefings should include information on existing protections, cybersecurity risk and the results of any cybersecurity assessments completed.
Pew researchers underscored that the work to build up cyber attack resilience by water systems operators would be costly and warned that, even with additional state-level fiscal assistance and technical support, limited resources could lead to the necessity of passing on costs to ratepayers already facing household budget challenges.
“Without more consistent or dedicated federal and state funding, the gap between cybersecurity needs and available resources is likely to remain a challenge for the nation’s critical water systems,” the Pew report reads.
