Hackers have broken into water systems in at least a dozen states in recent weeks, what cybersecurity experts say should be an urgent wake up call to immense vulnerabilities in American infrastructure.

“Malicious cyber actors” have infiltrated internet-connected water systems that routinely monitor and adjust safe drinking water across the country, according to federal law enforcement agencies.

Officials have not reported any widespread disruptions to America’s drinking water supplies, but analysts who have sounded alarms to governments and utilities for years about national security threats to critical infrastructure say the attacks should spark a nationwide reckoning.

“I’ve spent my 15-year career really trying to avoid being the person that runs around and tries to scare the s* out of everybody,” Craig Jackson, deputy director of the Center for Long-Term Cybersecurity at the University of California, Berkeley, told The Independent. “That said, I think it’s really, really, really bad, dude.”

President Donald Trump’s own intelligence agencies have suspected Iranian-linked actors were responsible for the latest wave of attacks, but the president has dismissed breaches in Minnesota as the fault of the state’s own government. If the regime is unable to target the U.S. with its own rockets and drones, experts fear the attacks could open a new, asymmetrical front in the administration’s war with Iran.

“I blame it on Minnesota because they’re grossly incompetent,” the president told reporters at Camp David on July 31 without providing any evidence.

“I would blame it on Minnesota and the governor, the corrupt governor of Minnesota,” he added. “Iran’s got bigger problems than worrying about Minnesota.”

In a statement on social media, the state’s Governor Tim Walz said that “Trump knows exactly who is responsible for this attack, and knows that other states were hit too.”

“This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran,” Walz said.

“The reason that we’re not seeing successful attacks at scale against other critical infrastructure in the way that we’re seeing it right now with water — it’s not because all these other sectors are super secure and water is especially vulnerable,” Jackson told The Independent. “It’s because some of our adversaries have decided to screw with our water, because it’s scary.”

The U.S. is made up of roughly 16,000 wastewater treatment plants and 152,000 public drinking water systems.

That process is controlled by programmable logic controllers, which measure water pressure and chemicals and operate pumps, among other tasks. Hackers appear to have remotely accessed programmable logic controllers that are connected to the internet.

The FBI and Cybersecurity & Infrastructure Agency have urged utilities to disable internet access, set up strong passwords and revert to manual control, among other changes.

The Operational Technology Cybersecurity Coalition said the attacks deserve more than a handful of alerts from federal agencies. “We must view this through a clear lens: an adversary has directly impacted a core American necessity,” the organization's executive director Tatyana Bolton wrote in an urgent appeal to members of Congress.

Michael Garcia, policy director for the Operational Technology Cybersecurity Coalition, told The Independent that the results of the attacks are the same, regardless of the culprit.

“You have Americans questioning whether or not they could drink their water,” he said. “Hopefully this raises a larger question that our critical infrastructure is vulnerable, and actors will exploit it, and it’s only a matter of time. .. What it comes down to is just actually now taking the action, ensuring that at the local level, these entities are taking the mitigation steps that the government and the manufacturers are suggesting and recommending.”

Experts are very much aware of the obstacles involved in convincing the administration and members of Congress — let alone cash-strapped state and local governments — to invest in sorely needed security updates.

“We’re super, super vulnerable, because the technology — all of our technology — is, generally speaking, built in relatively unsecure ways,” Garcia told The Independent. “And it’s very, very hard in a free market sense to get organizations to invest a lot in reducing this risk.”

Decades of deferred maintenance against growing costs and deteriorating infrastructure have made investments in cybersecurity and operational security measures “a really tough sell,” Jackson said.

The Trump administration has also gutted the agency tasked with responding to cybersecurity threats.

The Cybersecurity & Infrastructure Agency has been villainized by the president and his allies over the agency’s past efforts to disrupt election disinformation and after former director Christopher Krebs publicly assured that the 2020 presidential elections were the “most secure in American history.”

Since taking office, Trump has purged nearly one-third of the agency’s workforce, leaving the agency unprepared to respond to emerging threats from artificial intelligence and a new era of cyberwarfare while the administration is embroiled in a monthslong war with Iran, critics have warned.

Compounding the frustration among national security and cybersecurity experts is that nothing about the latest threats is new.

The attacks are merely the most recent in a string of incidents targeting government agencies, from ongoing phishing and ransomware threats to a malware attack in 2021 that paralyzed the largest fuel pipeline in the U.S.

The long-running Volt Typhoon operation, which the U.S. believes is the work of China’s People's Liberation Army Cyberspace Force, has been accused of hijacking Americans’ internet routers.

The latest attacks are also not the first targeting water systems that have been attributed to Iranian actors. A hacktivist group known as Cyber Av3ngers took credit for a 2023 attack on a Pennsylvania water system that the U.S. has officially attributed to Iran’s Islamic Revolutionary Guard Corps.

“I think we have to remember that cyber is just one tool in the tool belt when it comes to geopolitics,” Garcia told The Independent. “Maybe they were trying just to send a shot across the bow, and just do one locality, or just to show the capabilities, but this is a pretty far-reaching campaign that is pretty escalatory and very dangerous.”

A “worst-case scenario” outlook could have led to massive, life-threatening disruptions to the nation’s water system, from cutting off access to water at hospitals and military bases to pumping chemicals into drinking water supplies.

“At the end of the day, I think we were quite lucky that it’s not worse,” Garcia told The Independent. “A worst-case scenario could have been that we didn't catch it.”