Cyberattacks on U.S. Water Systems Expand to Seven States, Prompting Calls for CISA Funding
Cyberattacks targeting water and wastewater treatment systems have expanded to at least seven U.S. states as of August 2026, according to federal officials. The attacks have disrupted operations at several facilities and raised concerns about the vulnerability of critical infrastructure. Lawmakers are calling for increased funding for the Cybersecurity and Infrastructure Security Agency to address the threat.
Cyberattacks on water and wastewater treatment systems have spread to at least seven U.S. states as of August 2026, federal officials confirmed. The attacks have disrupted operations at multiple facilities and prompted urgent calls for increased federal investment in critical infrastructure security.
The Cybersecurity and Infrastructure Security Agency (CISA) said the attacks appear to be carried out by multiple threat actors, including groups with ties to foreign governments. The agency said it has been working with affected utilities to contain the damage and restore normal operations.
Water systems are considered among the most vulnerable segments of U.S. critical infrastructure. Many facilities run on aging industrial control systems that were not designed with cybersecurity in mind and have been slow to adopt modern protections.
In several of the affected states, attackers gained access to operational technology systems that control chemical dosing and water pressure. Officials said no contamination of drinking water supplies has been confirmed, but the potential for harm is significant.
Lawmakers on the House Homeland Security Committee called for an emergency supplemental appropriation to boost CISA's capacity to assist water utilities. A bipartisan group of senators introduced legislation that would require water systems serving more than 10,000 customers to meet minimum cybersecurity standards.
The water sector has historically received less attention and funding for cybersecurity than sectors like energy and finance. Industry groups said many small and mid-sized utilities lack the staff and resources to implement strong defenses on their own.
CISA said it is offering free cybersecurity assessments to water utilities and has published a set of recommended practices for securing industrial control systems. The agency urged utilities to prioritize patching known vulnerabilities and to implement multi-factor authentication for remote access.