Underfunded Water Systems Are an Open Door for Cyber Attackers
Small local governments and utilities in the US are becoming prime targets for state-backed hackers, largely because they lack the budget to properly secure their systems. In August, US authorities warned of active attacks against Siemens S7 programmable logic controllers (PLCs), devices widely used to control equipment such as pumps, valves and motors in water systems, hospitals and other critical infrastructure.
This isn't theoretical. In 2024, Russian-linked actors exploited a similar weakness to breach a small Texas town's water system, causing a tank to overflow. That town had no dedicated cybersecurity budget at all. Similar incidents have since occurred in several Minnesota towns, highlighting how attackers are using under-resourced local utilities as low-risk testing grounds for their techniques.
The core problem is money: many local agencies operate with a single IT staffer responsible for everything from asset tracking to incident response, and a large share of these organisations report stagnant or shrinking cybersecurity budgets. While this article focuses on US policy responses, the underlying lesson applies broadly: critical infrastructure operators of any size are attractive targets precisely because they are assumed to be poorly defended.