More than 150,000 public water systems across the United States now rely on a federal cybersecurity backstop that has lost roughly a third of its staff since January 2025, according to Warner's office, even as a suspected Iran-linked hacking campaign that began in Minnesota in late July has now hit water utilities in at least a dozen states. On Wednesday, standing in front of the drinking-water tanks that serve Park Ridge, New Jersey, Rep. Josh Gottheimer unveiled a bipartisan "Critical Infrastructure Security Plan," warning that hackers had already broken into two Cape May County water systems and forced operators to run pumps and turn valves by hand, according to his office. "This isn't some kid in a basement messing around," Gottheimer said, describing what he called a likely state-backed effort to test whether adversaries could shut off water and power to American families, hospitals and farmers.
The proximate trigger: a two-week hacking spree
The acute event driving Wednesday's announcement is concrete and recent. According to Law Review, hackers hit roughly 30 Minnesota water and wastewater utilities in a single 48-hour window on July 26-27, then spread to Michigan, New Jersey, Georgia, South Dakota and at least six other states within days. The FBI confirmed cyberattacks in at least seven states by July 30 and, alongside CISA and the EPA, issued a joint advisory telling the entire water sector to lock down its systems immediately. By August 4, ABC News reported at least 12 states affected, with some incidents causing loss of pressure and, in one case, flooding — the first documented instance of cyber-caused flooding in U.S. water-infrastructure history, according to the outlet.
In Braham, Minnesota, operators shut down the town's well and treatment plant for several hours. In Cape May County, New Jersey, hackers accessed pumps and treatment equipment plugged directly into the internet, logged in and locked out the legitimate operators, according to Gottheimer's account. Staff had to physically turn valves and run pumps manually until state and federal partners restored control. Service was never interrupted, but Gottheimer was blunt: "let's not kid ourselves and call that luck." Reporting has pointed to Iranian-affiliated actors, though Axios noted that President Trump said he did not "think there was an Iranian cyberattack." It is not a novel tactic: GAO's testimony documents that an Iran-affiliated group hacked a Pennsylvania water system in November 2023 the same way, and that EPA and CISA had warned three months before this campaign that Iran-affiliated groups were targeting the exact industrial-control technologies common at drinking-water plants.
The structural root cause: a fragmented sector Washington cannot legally compel to defend itself
The deeper story is not that hackers found a new vulnerability. It is that the federal government has spent years documenting this exact vulnerability without gaining the authority or resources to close it. GAO's report found that EPA had never conducted a comprehensive, sector-wide cybersecurity risk assessment for water systems and lacked a risk-informed national strategy — a finding that has kept water-sector cybersecurity on GAO's High Risk List since 2003. The report also details how EPA tried to require cybersecurity assessments during routine "sanitary surveys" in March 2023, only to rescind the rule seven months later after Missouri, Arkansas and Iowa sued, arguing EPA had no statutory authority to regulate cybersecurity at all. The Eighth Circuit stayed the rule in July 2023, and by October the agency withdrew it outright, according to Reuters and CyberScoop.
Three years later, that legal gap remains open. GAO's May 2026 testimony confirms EPA's own evaluation of its authority found "significant limitations" and a continuing lack of cybersecurity risk-assessment requirements for wastewater and many drinking-water systems. More than two years after Congress's watchdog flagged the problem, the agency responsible for water safety still cannot compel the roughly 170,000 drinking-water and wastewater systems nationwide to secure themselves, according to the GAO testimony. Gottheimer's figures reinforce the scale: 97 percent of the nation's roughly 150,000 public water systems serve small and mid-sized communities with no dedicated cybersecurity staff, and more than one in ten carries a critical vulnerability — over 80 percent tied to software flaws discovered before 2017.
Underinvestment compounds the authority gap. EPA's own needs survey put the sector's basic 20-year capital shortfall at $625 billion, before even counting cybersecurity. An FDD analysis found cybersecurity spending represents less than 1 percent of state revolving-fund awards to utilities, meaning chronic pipe-and-treatment funding gaps have crowded out digital defense almost entirely. Layered on top is the federal backstop meant to help these underfunded utilities: CISA's workforce has fallen from roughly 3,400 employees in early 2025 to about 2,400, a reduction of nearly a third, according to CSA research, Warner's office and CBS News. CISA's field cybersecurity advisers dropped from about 164 nationwide to roughly 97. The FY2027 budget proposes cutting a further $707 million and roughly 860 positions, according to CSA, while DHS's FY2027 request for infrastructure assessments sits at about 58 percent of the FY2026 level, according to the GAO testimony. DHS also defunded the Multi-State Information Sharing and Analysis Center in 2025, ending free threat-monitoring for roughly 18,000 state and local organizations that the Center for Internet Security now charges up to $1 million a month to replicate.
Quantifying the stakes
The exposure is not abstract. GAO's May 2026 testimony lists the potential consequences of a successful attack on water infrastructure as service disruption, drinking-water contamination, environmental pollution, and cascading harm to hospitals and energy production that depend on functioning water systems. AWWA has separately estimated that restoring and expanding the nation's water systems will cost at least $1 trillion over the next 25 years, an amount into which cybersecurity retrofits must now compete, according to Rockwell Automation. New York estimates that bringing mid-sized systems into compliance with basic cybersecurity mandates can cost up to $150,000 annually, rising to $5 million for larger utilities, according to FDD — a bill thousands of cash-strapped small-town utilities have no line item to cover.
Attribution and accountability: a bipartisan structural failure
This is a rare case where the evidence supports a genuinely non-partisan diagnosis, and both parties involved say so explicitly. The regulatory gap originated under a Democratic administration's EPA, which tried and failed to claim cybersecurity authority it did not clearly have under the Safe Drinking Water Act, and was blocked in court. The subsequent hollowing-out of CISA's workforce and budget has occurred under the current Republican administration's efficiency-driven cuts. The root cause is structural and bipartisan: a decades-old statute that never anticipated networked infrastructure, a fragmented ownership model spanning tens of thousands of independent local utilities with no uniform capacity to defend themselves, and years of both parties treating cybersecurity funding as discretionary rather than core infrastructure spending.
The perfect storm
What is unfolding is the convergence of four independent failures, none of which alone would have produced this moment. First, a legal architecture that courts have ruled does not give EPA clear authority to mandate cybersecurity practices, leaving compliance voluntary across a sector where it costs money utilities do not have. Second, a fragmented sector of roughly 170,000 independently operated systems, 97 percent of them too small for dedicated security staff, connecting decades-old industrial equipment directly to the internet for convenience. Third, a federal support structure at CISA that has lost roughly a third of its staff and faces further cuts precisely as threats accelerate, eliminating the free monitoring smaller utilities depended on. Fourth, a geopolitical trigger — a suspected Iran-linked actor testing these seams during an active window of U.S.-Iran hostilities — arriving to exploit gaps both parties had years of warning to close. Together, they explain why a 48-hour hacking spree in Minnesota cascaded into a dozen-state emergency and a congressional press conference within three weeks.