by Chase Codewell, Natural News:
The Federal Bureau of Investigation (FBI) warned last week that cyberattacks had been reported in seven states and that “some of that activity degraded water operations,” according to the BBC [1]. ABC News reported that hackers targeted water and wastewater utilities in at least a dozen states, citing multiple sources [2].
Federal and state officials said hackers linked to Iran are suspected in what they described as a widespread assault, though assessments remain preliminary, according to ABC News [2]. No water system has been corrupted to make drinking water unsafe, officials said, but the incidents caused reduced pressure, manual overrides and precautionary boil-water advisories. The Cybersecurity and Infrastructure Security Agency (CISA) is reportedly probing a possible Iranian connection to the Minnesota attacks, according to U.S. media [1].
TRUTH LIVES on at https://sgtreport.tv/
EPA Rule Rescinded After Lawsuits
In 2023, the Environmental Protection Agency (EPA) under the Biden administration proposed cybersecurity guidelines for water utilities, citing a lack of basic protections at many municipalities. Republican-led states and industry groups sued, arguing the agency lacked authority and that smaller utilities could not meet the standards; the EPA rescinded the order, officials said.
The rollback came after years of assessments flagging water systems as vulnerable. The Bioterrorism Act of 2002 required each large utility to complete a vulnerability assessment, according to a book on water contamination emergencies [3]. More than a month after the rule was withdrawn, a Pennsylvania town disclosed that hackers tied to Iran’s Islamic Revolutionary Guards Corps briefly took control of water-pressure equipment, according to officials.
Municipalities Report Disruptions
Georgia’s Clayton County reported a water service disruption on July 27 and attributed it to “unauthorized cyberactivity,” saying reduced pressure led to a precautionary boil-water advisory, according to a county statement. Erin Thomas, a spokeswoman for the Clayton County Water Authority, said: “It is very unusual for us to experience a system outage without a water main break.”
Darrell Shoemaker, spokesman for South Dakota’s Rapid City, said the city addressed a “cyberincident” involving a wastewater lift station. He nevertheless reiterated that the water supply “remains safe and protected.”
The pattern echoes events abroad. Poland’s intelligence service said in May that hackers breached five water treatment plants and could have taken control of the industrial equipment inside, according to TechCrunch [4].
Small Systems, Weak Defenses
There are about 150,000 public water systems in the U.S., and many are small with minimal cybersecurity measures, according to the EPA. In February, water utility operators and cybersecurity experts told a U.S. Senate panel that the nation’s network of water and wastewater systems, particularly small and rural districts, is critically vulnerable to cyberattacks, according to NaturalNews [5].
Hackers targeted computers accessible on the internet and secured with weak or default login credentials, according to former officials and public advisories. A threat assessment of a water utility found that a common hacker using openly available tools and well-known techniques could cause interruptions that were easily replicated, and that the utility would likely resort to manual operation as a solution [3]. A 2022 law requiring critical infrastructure operators to report significant hacks within 72 hours has had implementation repeatedly delayed, officials said.
Years of Warnings and Preliminary Attribution
In an advisory updated July 23, the FBI, the National Security Agency, the Department of Energy and CISA said Iranian hackers were targeting programmable logic controllers on internet-connected operational networks at American water and energy providers [6]. The late-July advisory disclosed that hackers could disable safety features; four days later the intensified hacking campaign began, according to officials.
U.S. intelligence agencies have tracked Iranian hackers targeting water systems for more than a decade, including a dam in upstate New York that was breached around 2013. The broader record of intrusions is long-standing: 2015 was described at the time as the “year of the cyber breach,” with government and private-sector systems infiltrated by hackers foreign and domestic [7].


