A recent wave of cyberattacks targeting public water systems has renewed concerns about the security of one of America’s most essential forms of critical infrastructure. While officials say drinking water remained safe and operators restored affected systems quickly, the incidents highlighted how vulnerable many utilities remain to digital threats and underscored the importance of strengthening cybersecurity before a more damaging attack occurs.
Visit your state page to pray.
According to CBS News, public water systems in at least a dozen states were targeted in recent weeks, including communities in Georgia, Michigan, Minnesota, New Jersey, and South Dakota. Investigators suspect the attacks may be linked to Iranian-backed hackers, although federal officials have not publicly confirmed who was responsible. Utilities responded by taking affected systems offline and switching to manual operations, preventing any known impacts to drinking water quality.
The attacks primarily targeted programmable logic controllers (PLCs), the industrial computers that operate pumps, valves, and treatment processes at water facilities. CBS News reports that many of these devices remain connected directly to the internet with little or no cybersecurity protection, making them attractive targets for foreign adversaries and cybercriminals. In some cases, hackers temporarily locked operators out of systems, altered device settings, and caused pressure disruptions before utilities regained control.
Security experts warn that the consequences could have been much worse. According to CBS News, a successful attack that significantly disrupts water pressure could affect hospitals, emergency services, and other critical facilities that rely on a constant water supply. While recent attacks caused only limited service interruptions, they demonstrate how even relatively simple intrusions could have cascading effects if left unchecked.
The broader challenge extends well beyond these recent incidents. Axios reports that the United States has more than 144,000 public water systems, including roughly 50,000 community drinking water systems. Because these utilities are independently owned and operated, maintaining consistent cybersecurity standards across the country is extraordinarily difficult. Many systems are also grappling with decades-old infrastructure, limited budgets, and staffing shortages while simultaneously preparing for cyber threats, extreme weather, and other emergencies.
Industry leaders say cybersecurity has become another critical responsibility layered on top of long-standing infrastructure needs. Axios notes that many digital control systems were originally designed for efficiency and reliability—not protection against cyberattacks. Smaller utilities often have only a handful of employees, making it difficult to dedicate personnel or funding to cybersecurity improvements while also replacing aging pipes, pumps, and treatment equipment.
Federal and state officials have been working to address these vulnerabilities. According to Axios, the Environmental Protection Agency identified cybersecurity weaknesses at 277 water systems last year and worked with utilities to resolve them. The American Water Works Association has also urged Congress to establish nationwide minimum cybersecurity requirements and provide additional support to local utilities responsible for protecting critical infrastructure.
Meanwhile, new partnerships are beginning to emerge. According to the Detroit Free Press, OpenAI recently offered Michigan up to $1 million in technology credits and technical support to help strengthen cybersecurity following the coordinated attacks that affected communities in Michigan and other states. The company said it has also reached out to other impacted states while emphasizing its commitment to helping organizations defend critical infrastructure. Michigan officials have not announced whether they will participate in the program.
Although investigators continue to examine who carried out the attacks, the incidents serve as a reminder that America’s infrastructure remains a target for hostile actors. Whether the motivation is disruption, intimidation, or intelligence gathering, adversaries continue probing systems that millions of Americans depend on every day.
Water is one of the most basic necessities of life. Every home, hospital, school, business, and emergency service depends on reliable access to clean water. As these attacks demonstrate, protecting that infrastructure requires not only continued investment in modern technology and cybersecurity but also wisdom for those responsible for defending it.
As intercessors, we can pray for those on the front lines of protecting our nation’s critical infrastructure—from local utility operators and cybersecurity professionals to state and federal officials making decisions that affect the security and resilience of essential services. May God grant them discernment, expose malicious schemes before they can cause harm, and protect the systems that millions of Americans rely on every day.
Share your prayers for America’s critical infrastructure and for those working to protect our nation’s water systems below.
(Photo Credit: PriyankaBerry5 – Own work, CC BY-SA 4.0, https://commons.wikimedia.org/w/index.php?curid=82993237)

