Jurisprudence
Aug 19, 20262:58 PM
Samuel Corum/Getty Images
On July 30, the FBI, Environmental Protection Agency, and Cybersecurity and Infrastructure Security Agency issued a joint statement confirming that “malicious cyber actors” had successfully infiltrated municipal water facilities in at least seven states, a count that has since grown to a dozen, forcing many of them offline. The attacks were inconsequential in one sense—there were no reports of contaminated water, though some systems suffered pressure drops and issued precautionary boil-water advisories. James Wilson, co-host of the Srsly Risky Biz podcast, likened the attacks to an “endless amount of cyber mosquitoes,” as opposed to a “cyber Pearl Harbor.”
But the coordinated attacks also underscored the vulnerability of the United States’ water facilities, prompting some obvious questions as to what the federal government has been doing, is presently doing, and perhaps should be doing. Water is critical to life, after all. Shouldn’t its security be a top, if not the top, priority? The United States hasn’t necessarily experienced a water cybersecurity disaster, but worst-case scenarios are more tangible than hypothetical. We’ve had water treatment failures, chemical imbalances brought on by malfunction, E. coli contamination, and the people of Flint, Michigan, of course, appreciate the criticality of clean water better than anyone in the country.







