New York Pours $9M into Water Utility Cybersecurity After Multi-State Attacks
New York Governor Kathy Hochul announced more than $9 million in funding on Monday to help 153 drinking water and wastewater systems harden their defenses against cyberattacks. Distributed through the state's Strengthening Essential Cybersecurity for Utilities and Resiliency Enhancements (SECURE) grant program, the awards will cover cybersecurity assessments (up to $50,000 per utility) and the implementation of security upgrades (up to $100,000). Recipients also gain no-cost technical assistance from the New York State Environmental Facilities Corporation (EFC). The funding is designed to bring utilities into compliance with minimum cybersecurity standards introduced in March, which include mandatory training for certified operators, incident reporting requirements, risk-based protections for critical operations and sensitive information, and the designation of a cybersecurity lead at larger drinking water systems.
The grant program was launched in direct response to a coordinated cyber campaign that struck operational technology at water and wastewater facilities across the United States. On July 26 and 27, more than 30 community water systems in Minnesota were targeted, with the city of Braham briefly taking its water plant offline after attackers disabled operating controls, shutting down both the well and the treatment facility. Michigan confirmed malicious activity affecting a small number of communities, Rapid City, South Dakota reported an incident at a wastewater lift station, and Georgia was also among the states impacted. While no New York utility has been publicly linked to the campaign, federal investigators have yet to formally attribute it, though Iran has emerged as the leading suspect given the activity's resemblance to previous campaigns by Iranian threat actors known to target industrial control systems and water utilities.
In response, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) urged water and wastewater operators to immediately remove publicly exposed programmable logic controllers and other operational technology from the internet — a step operators can validate using a port scanner to identify exposed services. CISA also recommended changing default credentials on all OT devices, a baseline check that can be supported through a password checker, and routing any necessary remote access through secure gateways or VPNs rather than direct internet exposure. "These threats are real and escalating," Hochul said, underscoring the urgency as municipal utilities nationwide race to close gaps before the next campaign lands.