Security1 publisher2 min readPublished
EPA links rising attacks on water utilities to unchanged passwords and exposed controls
EPA water chief Jess Kramer says attacks on US water utilities have risen several fold, citing unchanged passwords and system details left online. EPA keeps finding basic weak points, and officials say many utilities lack the staff and investment to close them.
The Watch · Security desk

What happened
- EPA enforcement chief Jeff Hall says attackers have moved from ransomware built to extort payments toward attacks designed to disrupt water and wastewater systems.
- EPA has identified more than 900 cybersecurity vulnerabilities at water systems across the country since 2025.
- In July, a coordinated cyberattack targeted more than 30 community water systems in Minnesota, disrupting technology used to remotely monitor and control equipment.
- In Colorado, officials said foreign actors got into two small water utilities and tampered with the equipment that controls their drinking water systems.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Hall lists hacktivist networks as well as state-affiliated actors, and either kind of attacker can reach an internet-facing control screen that still uses its original password.
- decision A utility whose incident plan assumes ransomware has to add the case Hall describes, where someone changes a setting on a controller that runs pumps or valves.
- cost Some of the most common fixes on EPA's list, such as changing passwords, cost staff hours. Firewalls and VPNs for aging controllers need the investment Hall says many utilities have not made.
Hall said the problem starts at the network edge. Aging control equipment in drinking water systems is "often left open to the open internet and not protected by any specific firewalls or virtual private networks that would ensure that cyber attackers cannot easily manipulate those," he said [7]. Kramer said the most common findings include "failure to change passwords, lack of multi-factor authentication" and critical system information that is "easily accessible" online [6]. When one system has both an exposed screen and an unchanged password, the intrusion needs no exploit code. The attacker just logs in [6][7].
Hall also described what attackers do once they are in. They are increasingly "manipulating the human-machine interface to change critical settings which disrupts the service and also puts people at risk," he said [4]. Behind those interfaces sit the programmable logic controllers that run pumps and valves. EPA and its law enforcement partners have issued advisories about those controllers [8]. Officials said drinking water stayed safe in both the Minnesota and Colorado incidents [11].
The claim that attacks are rising rests on Kramer's interview. "There is definitely been an increase, several fold on attacks recently," she said [1]. She did not give a baseline year or an attack count. The reporting also does not attribute the Minnesota attack or name the foreign actors in Colorado [9][10]. EPA's vulnerability total is the firmer number. It counts weaknesses the agency found at utilities [5].
In both public incidents, attackers reached the systems that control equipment [9][10]. Hall said attackers have moved from extortion toward disruption, and both incidents fit that description [3]. With no attribution on the record, the evidence supports a sector-wide change in what attackers target. It stops short of showing one actor's campaign maturing.
Hall blamed the gaps on money. "We will see water systems left vulnerable to cyberattacks where there have not been significant amounts of investment in cybersecurity protocols," he said [12]. Kramer said workforce shortages make it harder for utilities to recruit and retain people with the expertise to defend their networks [13].
What to watch
- Attribution of the Minnesota attack, or a name for the foreign actors in Colorado, would show whether this is one actor's sustained campaign or several separate efforts.
- An EPA count of attacks with a baseline year would turn Kramer's several-fold estimate into a number utilities can plan against.
- Whether Hall's enforcement office follows its advisories with enforcement action over the basic findings EPA keeps logging.