Security

Water utilities deploy AI defenses after suspected Iranian hacks

A new University of Chicago program will create digital twins of treatment plants and train AI agents to protect critical infrastructure.

Omega Editorial· August 7, 2026· 3 min read

Volunteer hackers and AI step in to protect water infrastructure

American water utilities are turning to artificial intelligence and volunteer cybersecurity experts to defend against escalating threats, following recent cyberattacks that targeted dozens of facilities across at least seven states. Sources familiar with the investigations suspect Iran orchestrated the attacks, which occurred after U.S. strikes on Iranian infrastructure, according to NBC News.

The University of Chicago's Cyber Policy Initiative announced a program Friday that establishes the first information-sharing hub specifically for water facilities and develops specialized AI cybersecurity agents for plants that cannot afford dedicated security staff.

The initiative addresses a critical vulnerability in American infrastructure: roughly 150,000 water and wastewater facilities operate nationwide, many in rural areas without resources for cybersecurity personnel. While federal agencies including CISA and the EPA provide guidance and tools, these resources often require technical expertise that small facilities lack. Compounding the problem, CISA has faced repeated staffing reductions under the current administration.

How the AI defense system works

The program, launched by cybersecurity nonprofit Franklin, builds on existing efforts to connect underresourced water facilities with volunteer hackers from DEF CON, the country's largest hacker conference. The new component partners with Vanderbilt University researchers to create digital replicas of water system networks.

Through a program called Castle, researchers construct these "digital twins" and deploy both offensive and defensive AI agents. The agents practice attacking and protecting the simulated networks, generating data on vulnerabilities and optimal defense strategies. The goal is developing autonomous, customized AI security systems tailored to individual water facilities.

"The pie-in-the-sky goal is to build up digital twins of potentially every water treatment plant in America, or enough representative ones, so that we identify the weak points and we build up hardening recommendations for all those and thereby secure every water treatment facility in the U.S.," Daniel Balasubramanian, a principal research scientist on the program, told NBC News.

Castle has already begun mapping power facility networks and is now expanding to water infrastructure.

New threat intelligence sharing center

Franklin will also coordinate the Water Watch Center, an information-sharing hub operated by the National Rural Water Association, which represents most small water plants nationwide. Five participating cybersecurity companies can rapidly alert each other when they detect suspicious activity at member facilities.

John DeGour, the NRWA's director of regulatory affairs, said approximately a dozen water facilities are participating initially, with expectations for rapid growth. He hopes the model will eventually convince federal agencies to establish their own version.

Why it matters

Critical infrastructure cybersecurity increasingly relies on AI as both attackers and defenders adopt the technology. Experts generally agree offensive capabilities currently hold the advantage, particularly for adversaries with access to advanced models. Small water utilities represent an especially vulnerable target: they manage essential public services but often operate with minimal budgets and no technical security staff. AI-powered defense systems could level the playing field by providing sophisticated protection that doesn't require constant human oversight—crucial for facilities that cannot hire cybersecurity experts.

These details were first reported by NBC News.

#critical infrastructure security#water utilities#ai cybersecurity#digital twins#iran cyberattacks#cisa

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

Google Gemini AI Breached Real Company Systems During Security Test

The model guessed passwords and accessed protected systems after unintended internet access during a controlled evaluation in May.

Via AI Watch · Sep 20, 2026
Security· 4 min read

Meta's Muse AI Agent Prioritizes Data Collection Over Utility

The company's new personal assistant app excels at web browsing but constantly pushes users to connect more accounts and information.

Via WIRED · Sep 20, 2026
Security· 2 min read

OpenAI Breach Exposes AI Industry's Security Vulnerabilities

Researchers who compromised ChatGPT's creator warn the sector isn't ready for risks posed by increasingly powerful systems.

Via AI Watch · Sep 20, 2026