The Trump White House is launching a new cybersecurity program to protect U.S. water systems after suspected Iranian hackers struck facilities across at least a dozen states — and once again, private contractors are positioned to profit from the government's failure to secure critical infrastructure on its watch.
The initiative, led by the Office of the National Cyber Director, will start as a "proof of concept" in Texas before expanding to other states, offering water utilities free access to vulnerability-scanning tools and other cybersecurity services provided by private companies, according to POLITICO. The program could be announced as early as next week.
The stakes are real. In recent weeks, water systems in Minnesota, Michigan, Georgia, and New Jersey have been hit by attacks targeting both IT and operational systems. In at least one Georgia county, a cyberattack caused a pump station to fail, forcing officials to issue a boil water notice, POLITICO reported. Hackers changed passwords on IT systems, forcing operators to run facilities on manual controls.
Federal and state officials believe Iran is behind the campaign, citing similarities to past Iranian cyber operations. The FBI and the Cybersecurity and Infrastructure Security Agency warned July 30 that hackers were targeting programmable logic controllers — the industrial computers that run machinery inside water facilities — made by Rockwell Automation, Schneider Electric, and Siemens. CISA said August 19 that attackers are now using AI to ease their attacks on Siemens equipment, according to the New York Post.
Meanwhile, the FBI is investigating a separate breach at Micro-Comm, a small Kansas-based maker of PLCs used in wastewater facilities. A ransomware group called Barracuda claimed responsibility, posting nearly 850,000 company files. Micro-Comm co-owner Jim Cote said the FBI told the company the attack was opportunistic, not targeted. Roughly 200 of the company's SCADAview CSX systems currently in use across U.S. states are accessible from the internet, according to internet-monitoring firm Censys.
The White House program's reliance on private companies to fill government gaps drew sharp criticism even from within the discussions. One person with knowledge of the program told POLITICO it amounts to "basically a shakedown of the companies, asking them to step in." National Cyber Director Sean Cairncross announced the pilot concept at a March event, and a White House source said the program has been in the works since last year.
Which companies are providing the free services — and what they stand to gain once the pilot becomes a permanent, taxpayer-funded program — remains undisclosed. The White House would not say which firms are involved.
The pattern is familiar: the federal government fails to secure critical infrastructure, then expands its own authority and funnels money to private contractors to fix what it couldn't prevent. Water utilities have long been soft targets precisely because they lack the funding and staffing to prioritize cyber defense — a problem decades of federal oversight never addressed. Now the same bureaucracy that missed the threat wants more power and a bigger budget to manage the solution.
The open question is whether this program actually secures the water supply or simply opens a new spigot for the cybersecurity contracting class — with taxpayers left holding the bill either way.







