upper waypoint

How Prepared Are We for Cyberattacks on Cities, Water Systems?

How vulnerable are American cities and critical infrastructure like electrical grids, sewage treatment plants, and communications to cyber warfare?
A cyberattack on Suisun City over the weekend forced the city to shut down its network infrastructure and declare a state of emergency. City hall services remain closed. (boonchai wedmakawand/Getty Images)

Airdate: Wednesday, August 12, 2026 at 9 AM

A cyberattack on Suisun City over the weekend forced the city to shut down its network infrastructure and declare a state of emergency. City hall services remain closed. In March, Foster City also declared a state of emergency after a similar attack. And two weeks ago, seven states across the country reported tampering with local water systems, a cyberattack attributed to Iran. How vulnerable are American cities and critical infrastructure like electrical grids, sewage treatment plants, and communications to cyber warfare?

Guests:

  • Lauryn Williams, deputy director and senior fellow, Strategic Technologies Program, Center for Strategic & International Studies
  • Ann Cleaveland, executive director, Center for Long-Term Cybersecurity, UC Berkeley
  • Alma Hernandez, mayor, Suisun City
  • James Rundle, reporter covering cybersecurity, national cyber policy and privacy, Wall Street Journal

Episode Transcript

This is a computer-generated transcript. While our team has reviewed it, there may be errors.

Lesley McClurg: Welcome to Forum. I’m Lesley McClurg. I’m in today for Alexis Madrigal.

The lights, the water, the phones, the internet — they all usually work, and we don’t really think twice about it. But behind all of these systems are computer networks, many of them only accessible remotely or primarily accessible remotely. And those networks are increasingly becoming cyber targets. When they’re attacked, the impact can bring an entire city to a standstill.

So just how vulnerable is our critical infrastructure, and what’s being done to protect the systems we all rely on every day?

Joining us first is Alma Hernandez. She’s mayor of Suisun City, which was hit over the weekend by a cyberattack. Welcome, Mayor Hernandez. Let’s start with where things stand this morning. What is working in Suisun City today? What is not working?

Alma Hernandez: Well, first and foremost, thank you for having me this morning. And the primary item that’s important for us to communicate to the public is that our public safety services have not been disrupted, and so that has always been a priority.

Other than that, things like our Parks and Rec Department or our public works out in the field are running okay. It’s coming into City Hall to pay water bills or being able to pull a business license or a building permit. All of that is delayed and will continue to be delayed. City Hall will remain closed this week.

Lesley McClurg: And do we know who was behind this attack? Has the FBI given you any sense of who that might be? A private hacker, a government entity? Do we know?

Alma Hernandez: We do not know that at this time. The investigation team will continue to provide us updates as they become available. We are definitely going through that process, and we’re all waiting to see more reports.

Lesley McClurg: Has the city received a ransom demand?

Alma Hernandez: We do not have that information available at this time, but we are definitely working through that with the FBI, Homeland Security, the California Office of Emergency Services and our team here at City Hall.

Lesley McClurg: And how did you know initially that your network was under attack?

Alma Hernandez: We received a report — the city council received a report from our city manager on Friday letting us know that they had identified an irregularity in the network. But the network, as soon as it identified the irregularity, froze itself to protect the rest of the system.

That’s what their initial report was to the council, and then we started reporting out to the public as well.

Lesley McClurg: There’s been some conflicting reports about what happened to 9-1-1. Was the system ever actually offline because of the cyberattack?

Alma Hernandez: The system was not offline. It was transferred over to our Solano County Dispatch Center, so they were trafficking all the calls to be able to respond to 9-1-1.

What we did do is we had to relocate our dispatchers from their physical location in Suisun City over to the county dispatch center, where they continue to remain at this time.

Lesley McClurg: Did the city have some kind of contingency plan in place in case this happened, in case of a cyberattack?

Alma Hernandez: The city had been doing some training all last year regarding how to navigate any type of emergency response, which we’ve then deployed this week. But primarily, it is about communicating to the public by working with experts to navigate the incident.

Our team went straight into emergency response mode on Friday and continued throughout the weekend. We held two emergency council meetings since then to be able to navigate this incident.

Lesley McClurg: And Foster City, just down the road, experienced a cyberattack earlier this year. Have you talked with them or any other cities about lessons learned? Are you all communicating about these attacks?

Alma Hernandez: Yes. We are so grateful to the cities and communities surrounding us that have experienced some type of incident themselves. They’ve made themselves accessible to our team, specifically our city manager, and I know that they’ve been communicating about lessons learned or best practices or how they navigated through it.

Lesley McClurg: Well, good luck, Mayor Alma Hernandez. I hope things get back to normal soon for you all. Good luck going forward, and have a good day. Thanks for being with us.

Alma Hernandez: Thank you so much.

Lesley McClurg: Let’s turn now to James Rundle. He’s a reporter for The Wall Street Journal covering cybersecurity and national cyber policy. James, can you put Suisun City in the kind of bigger picture for us? How often are cities getting hit by cyberattacks like this? How common is it?

James Rundle: There’s a depressing regularity to it. Cities, towns, villages all over the United States are really being besieged in multiple ways by cybercriminals, by more nefarious actors as well. It’s a real issue that spreads across state lines and across county lines and anything you can think of.

Lesley McClurg: And is there any kind of pattern that we can discern about who’s going to get hit, or does it seem pretty random at this point?

James Rundle: It varies. A lot of the time, the motivation is financial when you’re talking about criminal gangs. So they often go after the target’s opportunity, and those are the towns or the cities who have holes in their defenses, whether that’s unpatched vulnerabilities or kits that are still using default passwords or people who aren’t really doing the basics.

And, you know, these guys aren’t always very sophisticated. They go for what they can get into easiest.

Lesley McClurg: Let’s also now bring in Ann Cleaveland. She’s executive director for the Center for Long-Term Cybersecurity at UC Berkeley. Ann, why are cities — cities specifically — particularly vulnerable to these kinds of attacks?

Ann Cleaveland: Hi, good morning. Thank you, Lesley. And first, just thank you to Forum for taking up this topic. It’s so important to get the message out that we all need to be taking cybersecurity more seriously, whether that’s in our personal lives or in our local infrastructure. So thank you for the conversation.

And there are a few reasons that cities and other local infrastructure are particularly vulnerable. Sometimes these smaller entities are referred to in the industry as “target rich, resource poor” or below the cyber poverty line.

So it’s a two-part problem. Small cities or small operators sometimes think, “We’re too small to be a target. We don’t have anything of value.” And then there’s also a last-mile problem.

There are a lot of resources out there in cybersecurity for small entities. There are alerts, there are risk assessments, there’s free cybersecurity software. But all of the tools and frameworks in the world can’t help you if you don’t have anyone there who can do anything with it.

In many small towns across the country, the person in charge of IT is also in charge of maintaining the playground, for example. And there’s nobody there who can maintain, configure and act on the kinds of alerts that they’re getting.

Lesley McClurg: James, these attackers don’t seem to be going after money most of the time. So what do they want? Or is that correct? And what do they really want?

James Rundle: I would say, actually, they do go after money most of the time. You see that reflected in how targets like hospitals are often hit by ransomware because they know that they will pay, because any interruption is potentially a threat to life.

And the same with municipalities. If you shut down public services, if you shut City Hall, as Mayor Hernandez was just saying, that creates an impetus to resolve the problem quickly.

So often the motivation is financial in many cases. To start getting into different motivations, that gets into a more strategic level, but I would say the vast majority of these cases do end up being financially motivated.

Lesley McClurg: I want to bring in another voice to the conversation. Lauryn Williams is the deputy director and senior fellow at the Center for Strategic & International Studies. She served in the Biden administration as director for strategy in the White House Office of the National Cyber Director.

Welcome to Forum, Lauryn. We’ve seen a wave of cyberattacks on water systems across the country. What is happening? And why water systems? Why are they being targeted more frequently?

Lauryn Williams: Well, thanks so much, Lesley, for having me. To echo all who’ve spoken so far, this is an incredibly important issue, and it’s not least important in the context of the attacks that we’re seeing kind of ripple across the country.

Various motivations, as James mentioned, but specifically looking at the nationwide attacks across maybe up to 12 states, if not more, that we’ve heard about in the last couple of weeks, water systems, as you noted, are the core target.

So this is where we are talking about likely a nation-state threat actor at play, and we’re talking about broader strategic interests at play here. So water systems are, of course, critical, vulnerable infrastructure across the United States.

As Ann just noted, they’re often operated by small utilities — small utilities in localities that are under-resourced, or they may even not have access to the information that’s coming from the federal level just because of how few people might be focused on cybersecurity in these utilities.

Lesley McClurg: And is there any indication that these attacks are actually affecting the water itself? Is the water safe to drink generally, or is it actually getting into the water? Or is it just the systems that go down?

Lauryn Williams: It’s an important question. So fortunately, what we have not seen is any indication that safe drinking water has been impacted or contaminated across the United States. So that’s the good news story here.

These utilities have been able to revert to manual operations or pull specific remote-access systems from the internet, which, of course, was the point of entry for these nation-state actors, which all signs point to Iran.

But what we haven’t seen is any impact on the safety of American drinking water. But what we have alarmingly seen is likely Iran’s ability and intent to target that infrastructure and to impact the operations of water utilities.

Lesley McClurg: Was that the goal? Do you think the goal has ever been to contaminate the water, or is it just to kind of take down the system?

Lauryn Williams: So we do need to think about and look at the broader context of the conflict that the United States is in with Iran right now. So we can’t separate — once federal agencies formally attribute this attack — we can’t separate it from the broader aims in the conflict here.

So there are multiple aims likely that Iran would have in this particular circumstance. The first one, which is unfortunately maybe a successful aim already, is causing confusion, sowing concern across the United States because these hackers have demonstrated the ability to penetrate our systems and potentially disrupt them.

And in addition, there is, of course, the possibility that Iran, again, is looking to disrupt these systems.

This is not the first time that we’ve seen Iran-affiliated hackers target dams, target water systems here in the United States. That’s already happened in 2013 and 2023.

So this is unfortunately a problem that we’ve long been aware of and that federal agencies, even throughout this current conflict, have been warning about, even prior to the most recent attacks.

Lesley McClurg: We’ll talk all about that. We are talking about cyberattacks that are hitting local cities and really critical infrastructure. We’ll be right back after this break.

I’m Lesley McClurg. Stay with us.

lower waypoint
next waypoint
Player sponsored by