America’s drinking-water and wastewater networks have become targets in a widening cyber conflict involving foreign governments, politically motivated hackers, criminals and insiders. The danger is unusually tangible: Attackers who reach the operational technology controlling pumps, valves and chemical treatment could interrupt service or damage equipment. Yet the public record requires careful interpretation. Some incidents have firm government attribution; others are merely claimed by online groups or remain unsolved.
The recent timeline begins with a reminder that the attacker can come from inside. In January 2021, former contractor employee Rambler Gallo remotely accessed California’s Discovery Bay Water Treatment Facility and removed software used to monitor pressure, filtration and chemical levels. Gallo later pleaded guilty, and in May 2024 he was sentenced to home confinement and probation. Another widely reported event occurred in Oldsmar, Florida, on February 5, 2021, when an operator reported that someone remotely increased a sodium-hydroxide setting before the change was reversed. The FBI investigated it as an attempted hacking incident, but no perpetrator was publicly identified.
The threat accelerated dramatically in late 2023. Beginning November 22, hackers using the name CyberAv3ngers entered internet-connected Unitronics programmable logic controllers at American facilities. According to a joint CISA advisory, the devices commonly retained default or nonexistent passwords. The attackers replaced control logic, blocked remote access and displayed an anti-Israel message. Across four waves between November 2023 and January 2024, they compromised at least 75 U.S. devices, including at least 34 in the water and wastewater sector. Some utilities temporarily shifted to manual operation.

This campaign has the clearest attribution. U.S. agencies identify CyberAv3ngers as affiliated with Iran’s Islamic Revolutionary Guard Corps, or IRGC—not simply as unaffiliated activists who happen to support Iran. On February 2, 2024, the Treasury Department sanctioned six IRGC Cyber-Electronic Command officials in response to the attacks. The selection of Israeli-made equipment suggests the campaign was partly political signaling connected to the Israel-Hamas war, but its access to real industrial controls created a genuine public-safety risk.
A different campaign emerged in Texas. On January 18, 2024, a pro-Russia hacktivist accessed control systems at two water facilities, manipulated pumps and alarms, and caused storage tanks to overflow, according to a June 2024 intelligence assessment. The same actor later posted videos purporting to show manipulation of American wastewater controls. The precise attribution matters: U.S. authorities describe the actor as “pro-Russia,” not as a proven Russian-government unit. CISA subsequently issued defensive guidance for operational-technology operators.
China presents a quieter but potentially more strategic threat. U.S. agencies say the state-sponsored group Volt Typhoon infiltrated information-technology networks across multiple critical-infrastructure sectors, including water and wastewater. Officials assess that the group was establishing persistent access that could support disruption during a future crisis rather than conducting attention-seeking vandalism. In December 2023, the FBI used a court order to remove malware from hundreds of compromised routers; the Justice Department announced the operation on January 31, 2024. A February advisory confirmed compromises in U.S. water-sector organizations, sometimes with access maintained for years.
Why is the sector so exposed? The United States has nearly 170,000 water and wastewater systems, many of them small, locally managed and dependent on aging equipment. Default passwords, obsolete software, exposed remote interfaces and limited cybersecurity staffing recur across incidents. An EPA inspector-general scan conducted October 8, 2024, found critical or high-risk vulnerabilities at 97 drinking-water systems, collectively serving about 26.6 million people.
The federal response intensified during 2024. In February, CISA, EPA and the FBI published eight priority security actions, including removing operational controls from the public internet, changing default passwords, inventorying equipment, making backups and rehearsing incident-response plans. In March, the White House and EPA asked governors to produce state cybersecurity plans and supported a Water Sector Cybersecurity Task Force. In May, EPA increased inspections and enforcement, using existing Safe Drinking Water Act requirements for risk assessments and emergency-response planning.
That response still has limits. EPA withdrew a broader 2023 cybersecurity interpretation after legal challenges, and the Government Accountability Office concluded in August 2024 that federal protection remained fragmented and too dependent on voluntary action. EPA subsequently completed a sector risk assessment and risk-management plan in January 2025. In August, it released ten task-force recommendations and offered more than $9 million in resilience grants. By February 2026, EPA reported that it had assessed 277 systems and helped eliminate 350 vulnerabilities during 2025.
The encouraging fact is that publicly documented attacks have generally produced temporary disruption, equipment manipulation or defensive shutdowns—not confirmed mass poisoning. The warning is that adversaries have repeatedly demonstrated access. America is improving its defenses, but uneven funding, voluntary standards and thousands of small operators leave a gap between federal guidance and security at the plant.





