The summer-thriller version goes like this: a cyberattack quietly adjusts the chemical levels at one drinking-water utility. A dozen people get sick. Negligence is assumed. Two days later, three more utilities are hit; children are hospitalized. Two days after that, five more, including one in a midsize city. The president addresses the nation. Bottled water disappears from shelves. Riots break out.
That scenario is not a screenplay pitch. It is the analytical framework laid out by Seth M. Siegel — author of Troubled Water: What's Wrong with What We Drink — writing about what a suspected Iranian operation against American water systems should be forcing us to confront.
The facts on the record are sobering enough without the hypothetical. America operates 16 categories of critical infrastructure, all carrying some exposure to cyberattack. According to Siegel, none are as widely exposed as drinking-water facilities. The adversaries he names — Iran, North Korea, criminal enterprises — are not hypothetical either. They are the actors American intelligence agencies have publicly identified as active in the infrastructure-targeting space.
What makes the water sector distinctly vulnerable is the combination of scale and fragmentation. The United States does not have one water system. It has thousands of them — municipal utilities, rural co-ops, small-town treatment plants — each operating with its own software, its own staffing levels, its own cybersecurity posture, which in many cases means no meaningful cybersecurity posture at all. An adversary does not need to crack a hardened federal target. It needs to find the weakest link in a very long chain.
The automation point is critical. Modern water treatment relies on computerized controls to manage the precise dosing of purifying chemicals. Those same controls, if accessed remotely by a hostile actor, can be turned against the population they are meant to protect — either by spiking chemical levels or by cutting them entirely. The change can happen faster than a human operator catches it.
The panic scenario Siegel describes is not irrational. It follows logically from a simple fact: people cannot see, smell, or taste many of the things that make water dangerous. Once trust in the tap is broken, no presidential address restores it quickly. The run on bottled water, the empty shelves, the social disorder — these are the second-order consequences of a first-order infrastructure failure, and they may prove more damaging than the attack itself.
The Environmental Protection Agency and the FBI are named as the agencies that would respond. Neither has demonstrated, on the public record, that it has closed the exposure Siegel documents.
Say it plainly: the federal administrative apparatus has had years of warnings about water-system cyber vulnerabilities and has not produced a durable fix. The cost of that inaction will be borne not by regulators but by the communities downstream — literally. What is at stake is not an abstraction about critical infrastructure. It is the most basic promise a government makes to its citizens: that the water coming out of the tap will not hurt them. That promise is currently being kept by luck as much as by design, and luck is not a security strategy.



