The threat to America’s water infrastructure has escalated sharply, with senior Environmental Protection Agency officials confirming that cyberattacks on drinking water and wastewater systems have increased several-fold in recent years. More concerning still is the fundamental shift in the nature of these attacks, as hostile actors move away from financially motivated ransomware schemes toward deliberate attempts to disrupt critical civilian infrastructure.

“Our everyday life completely crumbles without access to drinking water and wastewater infrastructure,” warned Jess Kramer, EPA Assistant Administrator for Water. The assessment underscores a vulnerability that reaches into every American home, hospital, and business.

The scope of recent incidents illustrates the gravity of the situation. In July, more than thirty community water systems across Minnesota fell victim to a coordinated cyberattack that disrupted technology used to remotely monitor and control equipment. Some utilities were forced to revert to manual operations and backup procedures, a stopgap measure that highlights both the vulnerability of modern systems and the thin margin of safety protecting American communities.

According to Kramer, the water sector has become an attractive target precisely because of its central role in daily life. “Everything from hospitals to daycares, everything that we care about and need on an everyday basis can be impacted” should one of these cyberattacks succeed in its objectives.

The vulnerabilities extend beyond the sophistication of the attacks themselves. Jeff Hall, EPA Assistant Administrator for Enforcement and Compliance Assurance, pointed to a troubling reality facing many water utilities: aging infrastructure combined with insufficient resources to modernize cybersecurity defenses. Basic protections such as virtual private networks and firewalls remain absent at some facilities, leaving them exposed to increasingly determined adversaries.

“We will see water systems left vulnerable to cyberattacks where there have not been significant amounts of investment in cybersecurity protocols,” Hall explained. In some documented cases, failures as elementary as unchanged default passwords have provided entry points for hostile actors.

The evolution in attack methodology represents a strategic shift that demands attention from policymakers and security officials alike. “Hackers have moved from ransomware attacks designed to extort payments from critical infrastructure generally to more specific attacks designed to disrupt critical infrastructure and particularly water and wastewater systems,” Hall noted.

These newer attacks go beyond simple system lockouts. Attackers are now manipulating the human-machine interface to alter critical operational settings, actions that not only disrupt service but potentially endanger public health. The implications of such interference with water treatment processes or distribution controls could extend far beyond temporary inconvenience.

The warnings from EPA officials arrive at a moment when federal and state authorities are reassessing vulnerabilities across the nation’s critical infrastructure. The water sector, with thousands of independent utilities operating under varying levels of technological sophistication and financial constraint, presents a particularly challenging landscape for comprehensive security improvements.

What remains clear is that the threat will not diminish on its own. As adversaries demonstrate increasing capability and intent to target essential civilian infrastructure, the question facing communities nationwide is not whether their water systems could become targets, but whether adequate defenses are in place before the next wave of attacks arrives.

Related: Violence Erupts Across France as Students Protest School Conditions