A cybersecurity nonprofit and Vanderbilt University announced a new initiative Friday to help protect U.S. water systems from cyber threats using AI and volunteer expertise. The move follows a wave of cyberattacks on water facilities across at least seven states, with some incidents linked to suspected Iranian hackers.
New AI hub targets water system vulnerabilities
The Franklin cybersecurity nonprofit—born from DEF CON, the country’s largest hacker conference—unveiled a first-of-its-kind hub to assist water facilities in sharing cyberthreat intelligence and deploying specialized AI agents. The program will clone computer networks of select water systems and train AI models to both attack and defend those networks, with the goal of creating autonomous, customized cybersecurity tools for facilities lacking human experts.
Water systems face escalating cyber risks
The initiative responds to a surge in cyberattacks on U.S. water and wastewater facilities, many of which lack dedicated cybersecurity staff or funding. Last week, facilities in at least seven states were targeted, according to sources familiar with investigations. While the U.S. Cybersecurity and Infrastructure Agency (CISA) and Environmental Protection Agency (EPA) provide guidance and tools, these resources often require technical expertise that rural and underfunded facilities cannot support.
AI and volunteer networks fill security gaps
Franklin already pairs underresourced water facilities with volunteer hackers to identify vulnerabilities. The new AI component, developed in collaboration with Vanderbilt University researchers, will simulate cyberattacks on cloned systems to train defensive AI agents. The goal is to provide automated, plant-specific cybersecurity solutions for facilities that cannot afford human experts.
Potential consequences of successful attacks
Experts warn that undetected cyber breaches could disrupt pumps, valves, and treatment systems, leading to unsafe water, broken pipes, or boil-water notices. While no confirmed contamination has occurred in recent incidents, the FBI issued a public service announcement in late July urging water companies to bolster cybersecurity measures.
Government response and political tensions
Federal agencies like CISA and EPA offer cybersecurity tools and advice, but critics argue these resources are insufficient for facilities with limited staff. Political disputes have also emerged: President Donald Trump recently blamed Minnesota Gov. Tim Walz for cyberattacks on facilities in his state, highlighting partisan divisions over infrastructure security.
Broader context: Aging systems and limited resources
Many water systems rely on older equipment and internet-connected devices, making them attractive targets for hackers scanning for vulnerabilities. Dan Hartnett, interim CEO of the Association of Metropolitan Water Agencies, noted that attackers may not always target water systems specifically but exploit any weak link in connected infrastructure. Ahmad Taha, a Vanderbilt University associate professor, emphasized the catastrophic potential of such attacks, stating that they require minimal effort to cause severe disruption.