The US needs a real plan to defend its water systems
The summer’s cyberattacks by Iranian hackers on water systems in 12 states underscored how vulnerable U.S. water systems are to foreign adversaries. A broad attack on water infrastructure could have consequences comparable to a public health crisis that impacts the country’s entire population.
The threat to water has long been clear. As the 2026 Annual Threat Assessment from the U.S. intelligence community states “Cyber actors from China, Russia, Iran, North Korea, and ransomware groups... pose critical threats to U.S. networks and critical infrastructure.”
Advances in artificial intelligence have heightened those vulnerabilities. Advanced AI models, such as Anthropic’s Claude Mythos, have demonstrated the ability to identify thousands of zero-day vulnerabilities in critical software systems, including major operating systems and browsers. Other systems, including some developed in China, are demonstrating similar capabilities. AI systems can now “plan, test, and execute attacks in rapid cycles,” ranging from minutes down to seconds.
U.S. water systems are vulnerable to cyberattacks for technical, legal and practical reasons.
Technical: About 80% of U.S. water systems lack even basic cyber hygiene, a weakness exploited in the summer attacks. Even systems that serve most of the population ( approximately 450 large and 4500 medium-sized water systems ) have not adopted advanced cybersecurity capabilities used in other sectors where failure can have catastrophic consequences, including aviation, rail, mass transit, medical devices, finance, and nuclear power…