- Utah's water infrastructure faced cyberattacks, linked to Iran, with 500 intrusion attempts.
- Federal agencies warn of rising cyber threats to critical water infrastructure in the U.S.
- Utah's water systems lack foundational cybersecurity protections, increasing vulnerability to future attacks.
SALT LAKE CITY — At least a dozen states have recently reported incidents of "malicious" cybersecurity attacks on water and wastewater infrastructure, and Utah is one of them.
The FBI and EPA issued a public announcement concerning malicious cyber actors "remotely tamper(ing) with device configurations," resulting in "a loss of monitoring and control functionality."
An intelligence note reviewed by ABC News said public safety officials in Utah "identified targeted reconnaissance" against the state's water infrastructure using an internet signature linked to Iran, including nearly 500 attempted intrusions within 46 minutes in November 2025.
The Utah Cybersecurity Commission, Utah Cyber Center and Utah Department of Public Safety did not respond to multiple requests for comment on reports of the attack.
Growing risk of cyberattacks
Federal agencies have been warning of cyberattacks on critical water infrastructure for years, and the repeated attacks in recent weeks illustrate a growing threat.
"Cybersecurity threats are a serious concern for our nation's drinking water and wastewater systems, and these threats pose a legitimate risk to the communities, businesses, hospitals, schools, and other critical sectors that rely on these lifeline services," said EPA Assistant Administrator for Water Jess Kramer in a press release.
This is not the first time U.S. critical water systems have been targeted by cybersecurity threats, and the compromise of critical water systems could have serious consequences.
At the same time cybersecurity attacks are becoming an increasing threat, data shows that Utah water systems are "vulnerable" to attack.
Water systems 'lack foundational protections' against cyber threats, audit says

A 2026 performance audit of drinking water cybersecurity in Utah found that many drinking water systems "lack foundational protections against growing cyber threats" and "can do more" to prioritize cybersecurity.
"Utah's drinking water systems are not fully implementing basic cybersecurity practices established by the U.S. Environmental Protection Agency, leaving water systems vulnerable to cyberattack," the report said.
Sage Energy Partners/Sage Water Resources, a Native American-owned water infrastructure company in northeastern Utah, was the victim of a cyberattack earlier this year.
The attack "was a malicious logic manipulation carried out by an advanced nation-state threat actor" and "consistent with a broader, sophisticated campaign targeting critical infrastructure operators across the United States energy and water sectors," the company said in a press release.
Sage Energy Partners said the "unauthorized logic changes" were detected and resolved before causing serious environmental or physical damage to the water resources, and the company is now "fully hardened" against future threats.
"This incident underscores the reality that independent energy operators of critical infrastructure are on the front lines of global geopolitical threats," said Steve Crower, Sage Energy Partners CFO.
Many believe Iran to be responsible

No federal agencies have formally released information on who is responsible for these attacks, but theories that foreign powers, specifically Iran, are behind the attacks have spread.
The EPA, FBI, NSA, and Cybersecurity and Infrastructure Security Agency issued a joint warning in July to advise against "an urgent and ongoing Iranian-affiliated cybersecurity threat."
"CISA has consistently warned critical infrastructure stakeholders that Iranian-affiliated threat actors are conducting a range of targeted cyber activity to include compromise unsecure internet-connected accounts and devices," said CISA acting executive assistant director for cybersecurity Chris Butera in the release.
Lauryn Williams, deputy director at the Center for Strategic and International Studies' Strategic Technologies Program, said water may not be the only critical infrastructure Iran chooses to target.
"The most recent attacks on the water sector that we're seeing across the country are indicative of the vulnerable state of U.S. cybersecurity across all 16 critical infrastructure sectors, water just being one of them," Williams said in a video posted on X.
Williams said there is a need for "all of U.S. society to be taking a cold hard look at our current cyber defenses and working together to collectively improve them."
State leaders address the rise in cyber threats
State representatives across the country are calling for increased security measures to combat the increase in attacks to critical infrastructure.
U.S. Sen. Elissa Slotkin in Michigan, a state that was subject to recent cyber attacks, said the event "reinforces how important it is to harden the defenses of our critical infrastructure, especially in a heightened threat environment."
Rep. Rich McCormic, of Georgia, another affected state, also addressed the issue online, saying the attacks are "an attack on public health, plain and simple."
Two municipal water systems in New Jersey were subject to attacks that, while resolved quickly and without serious consequences, were still "too close for comfort," Rep. Frank Pallone said.
"I'm determined to get to the bottom of this and make sure we're prepared to protect our drinking water," Pallone said in a post on X.
U.S. Sen. Tina Smith, from Minnesota, said the attack on Minnesota's water infrastructure "must be taken as a serious threat of national security." Minnesota was hit the hardest, with more than 30 water systems attacked.
Even in states that did not experience major attacks, leaders are calling for increased security.
Rep. Raja Krishnamoorthi in Illinois said, "We need stronger cyber defenses before the next attack does far greater damage."
Federal agencies warn infrastructure operators
The FBI, EPA and CISA have all recommended precautionary measures to prevent cybersecurity attacks, with the main protocol being disconnecting systems from the internet.
"OT (operational technology) assets exposed to the internet have an increased risk of defacement, configuration changes, operational disruptions, and, in severe cases, physical damage," CISA warned.
Other security measures include creating complex passwords, securing network access through firewalls, and strictly controlling access to devices that operate the systems.









