Emily is a general assignment intern with the Deseret News Utah, Politics and the West team and will soon receive her degree in journalism from Brigham Young University.
Your browser does not support the audio element.
00:00
00:00
1.0x
00:00/00:00
–
+
At least a dozen states have recently reported incidents of “malicious” cybersecurity attacks on water and wastewater infrastructure, and Utah is one of them
The FBI and EPA issued a public announcement concerning malicious cyber actors “remotely tamper(ing) with device configurations,” resulting in “a loss of monitoring and control functionality.”
An intelligence note reviewed by ABC News said public safety officials in Utah “identified targeted reconnaissance” against the state’s water infrastructure using an internet signature linked to Iran, including nearly 500 attempted intrusions within 46 minutes in November 2025
The Utah Cybersecurity Commission, Utah Cyber Center and Utah Department of Public Safety did not respond to multiple requests for comment on reports of the attack
Growing risk of cyberattacks
Federal agencies have been warning of cyberattacks on critical water infrastructure for years, and the repeated attacks in recent weeks illustrate a growing threat
Protecting our water means protecting against cyber threats too. EPA provided expertise for new Water Cybersecurity Recommendations give utilities tools & training to guard drinking water systems from hackers & hazards—so communities stay safe. Learn more➡️…
— U.S. EPA (@EPA) August 15, 2025
“Cybersecurity threats are a serious concern for our nation’s drinking water and wastewater systems, and these threats pose a legitimate risk to the communities, businesses, hospitals, schools, and other critical sectors that rely on these lifeline services,” said EPA Assistant Administrator for Water Jess Kramer in a press release
This is not the first time U.S. critical water systems have been targeted by cybersecurity threats, and the compromise of critical water systems could have serious consequences
At the same time cybersecurity attacks are becoming an increasing threat, data shows that Utah water systems are “vulnerable” to attack
Audit reveals Utah drinking water systems ‘lack foundational protections’ against cyber threats

A 2026 performance audit of drinking water cybersecurity in Utah found that many drinking water systems “lack foundational protections against growing cyber threats” and “can do more” to prioritize cybersecurity
“Utah’s drinking water systems are not fully implementing basic cybersecurity practices established by the U.S. Environmental Protection Agency, leaving water systems vulnerable to cyberattack,” the report said
Sage Energy Partners/Sage Water Reortheastern Utah, was the victim of a cyberattack earlier this year
The attack “was a malicious logic manipulation carried out by an advanced nation-state threat actor” and “consistent with a broader, sophisticated campaign targeting critical infrastructure operators across the United States energy and water sectors,” the company said in a press release
Sage Energy Partners said the “unauthorized logic changes” were detected and resolved before causing serious environmental or physical damage to the water rereats
“This incident underscores the reality that independent energy operators of critical infrastructure are on the front lines of global geopolitical threats,” said Steve Crower, Sage Energy Partners CFO
Many believe Iran to be responsible for the increase in cyber threats

No federal agencies have formally released information on who is responsible for these attacks, but theories that foreign powers, specifically Iran, are behind the attacks have spread
The EPA, FBI, NSA, and Cybersecurity and Infrastructure Security Agency issued a joint warning in July to advise against “an urgent and ongoing Iranian-affiliated cybersecurity threat.”
“CISA has consistently warned critical infrastructure stakeholders that Iranian-affiliated threat actors are conducting a range of targeted cyber activity to include compromise unsecure internet-connected accounts and devices,” said CISA Acting Executive Assistant Director for Cybersecurity Chris Butera in the release
Lauryn Williams, deputy director at the Center for Strategic and International Studies’ Strategic Technologies Program, said water may not be the only critical infrastructure Iran chooses to target
“The most recent attacks on the water sector that we’re seeing across the country are indicative of the vulnerable state of U.S. cybersecurity across all 16 critical infrastructure sectors, water just being one of them,” Williams said in a video posted on X
Cyber threat actors have recently targeted water systems across at least seven U.S. states, in an attempt to cause physical disruption to critical infrastructure. @CSIS_Tech‘s @lauryndsw explains how these attacks expose the vulnerable state of U.S. cybersecurity and the further… pic.twitter.com/BG3lniaUFj
— CSIS (@CSIS) August 4, 2026
Williams said there is a need for “all of U.S. society to be taking a cold hard look at our current cyber defenses and working together to collectively improve them.”
State leaders address the rise in cyber threats
State representatives across the country are calling for increased security measures to combat the increase in attacks to critical infrastructure
U.S. Sen. Elissa Slotkin in Michigan, a state that was subject to recent cyber attacks, said the event “reinforces how important it is to harden the defenses of our critical infrastructure, especially in a heightened threat environment.”
Iranian cyberattacks have increased over 200 percent since the start of the war. This week, cyberattacks hit local water systems in 12 states, including in Michigan. This cyberattack reinforces how important it is to harden the defenses of our critical infrastructure, especially…
— Sen. Elissa Slotkin (@SenatorSlotkin) August 5, 2026
Rep. Rich McCormick of Georgia, another affected state, also addressed the issue online, saying the attacks are “an attack on public health, plain and simple.”
Two municipal water systems in New Jersey were subject to attacks that, while resolved quickly and without serious consequences, were still “too close for comfort,” Rep. Frank Pallone said
Our critical infrastructure is facing increasingly sophisticated cyber threats. And while I’m glad NJ acted quickly and there’s been no reported impact on our water systems, this was too close for comfort.I’m determined to get to the bottom of this and make sure we’re prepared…
— Rep. Frank Pallone (@FrankPallone) August 5, 2026
“I’m determined to get to the bottom of this and make sure we’re prepared to protect our drinking water,” Pallone said in a post on X
Georgia families should not have to boil their water because hackers targeted our pump stations.This is an attack on public health, plain and simple, and we must make sure Georgia’s water infrastructure has the cybersecurity protection it deserves.https://t.co/7jVgXToE7V
— Congressman Rich McCormick, MBA MD (@RepMcCormick) August 5, 2026
U.S. Sen. Tina Smith from Minnesota said the attack on Minnesota’s water infrastructure “must be taken as a serious threat of national security.” Minnesota was hit the hardest, with more than 30 water systems attacked
Even in states that did not experience major attacks, leaders are calling for increased security
Rep. Raja Krishnamoorthi in Illinois said, “We need stronger cyber defenses before the next attack does far greater damage.”
Months ago, I warned the Jaguar Land Rover cyberattack could foreshadow attacks here at home. Now, investigators believe Iranian hackers likely targeted dozens of Minnesota water systems.We need stronger cyber defenses before the next attack does far greater damage.…
— Congressman Raja Krishnamoorthi (@CongressmanRaja) July 31, 2026
Federal agencies warn infrastructure operators to protect themselves from cyber threats
The FBI, EPA and CISA have all recommended precautionary measures to prevent cybersecurity attacks, with the main protocol being disconnecting systems from the internet
“OT (operational technology) assets exposed to the internet have an increased risk of defacement, configuration changes, operational disruptions, and, in severe cases, physical damage,” CISA warned
🚨 FBI PSA: Malicious Cyber Actors Targeting Water and Wastewater Sector PLCsThe FBI warns that malicious cyber actors are conducting cyber attacks targeting operational technology devices. These threat actors are remotely accessing internet-facing PLCs, changing IPs and… pic.twitter.com/v4L7SmAQIO
— FBI Salt Lake City (@FBISaltLakeCity) July 31, 2026
Other security measures include creating complex passwords, securing network access through firewalls, and strictly controlling access to devices that operate the systems

